For several years, Canadian businesses braced for a new federal law to replace our aging privacy legislation, PIPEDA. That law was Bill C-27, and it promised sweeping reform — massive fines, new consumer rights, and dedicated AI regulation. In early 2025, it died on the order paper when Parliament prorogued and a federal election followed.
The story isn’t finished. On June 15, 2026, the federal government introduced Bill C-36, the Protecting Privacy and Consumer Data Act (PPCDA) — the third attempt in six years to overhaul federal private-sector privacy law, following Bill C-11 in 2020 and the now-dead Bill C-27 in 2022. It is not law yet, and it may not become law — but it signals that federal reform is genuinely back on the table, even as Quebec’s Law 25 continues to set the practical standard businesses are already being held to today.
For a small business owner, none of this uncertainty is a reprieve. It is the opposite. Whether or not Bill C-36 eventually passes, you are operating in a complex, fragmented privacy landscape where customer expectations are high and the cost of a single breach — in fines and reputation — can be serious.
If you collect any customer data — names, emails, phone numbers, purchase history — this guide explains the real state of privacy and cybersecurity compliance in Canada right now.
While federal reform has repeatedly stalled, Quebec did not wait. Quebec’s Law 25 (formerly Bill 64) is fully in force and remains the toughest privacy law in Canada.
“But I’m not in Quebec,” you might say. “My business is in Brampton.”
Does your website receive traffic from Quebec? Do you have customers, clients, or even just email newsletter subscribers who live in Quebec? If the answer is yes, you are very likely subject to Law 25 and its significant penalties.
Because it remains the strictest standard in the country, Law 25 has become the practical benchmark that most Canadian businesses should aim for, regardless of where they’re headquartered. Notably, the core principles proposed in the now-dead Bill C-27, and largely carried forward into the new Bill C-36, closely mirror Law 25’s approach — reinforcing that this is the clear direction Canadian privacy law is heading, federally or not.
Bill C-36 proposes replacing PIPEDA’s privacy provisions with the Protecting Privacy and Consumer Data Act (PPCDA), overseen by a newly created regulator, the Digital Safety and Data Protection Commission of Canada. If enacted, it would introduce a more prescriptive, documentation-heavy compliance model — mandatory privacy management programs, formal legitimate-interest assessments, and substantially larger enforcement powers than PIPEDA currently provides.
The practical reality for your business today: PIPEDA remains the operative federal law, unchanged, while Bill C-36 works through Parliament. Given that its two predecessors both died before passage, there is genuine uncertainty about whether C-36 will become law, and if so, in what final form. The sensible approach is not to wait and see — it’s to build your privacy practices toward the Law 25 standard now, since that standard already applies to any business with Quebec customers and closely resembles where federal law appears headed regardless of which specific bill eventually passes.
Privacy law and cybersecurity are two sides of the same coin. Your privacy policy is the promise you make to customers. Your cybersecurity is how you actually keep that promise.
All Canadian privacy laws — PIPEDA, which remains fully in force, and Quebec’s Law 25 alike — contain a core safeguarding principle: you are legally required to protect the personal information you hold with security measures “appropriate to the sensitivity of the information.”
In 2026, cyber threats targeting small businesses continue to grow more sophisticated, and small businesses remain a primary target precisely because attackers assume — often correctly — that their defences are weaker than a large enterprise’s. This means your safeguarding obligation carries a genuinely higher practical bar than it did even a few years ago. “Appropriate” cybersecurity in 2026 is no longer simply having antivirus software installed. It generally means:
A data breach exposing customer emails and purchase history, later traced to a failure to enable MFA, is a straightforward violation of your legal duty to safeguard that data — under PIPEDA today, and under Law 25 if any Quebec residents are affected.
Federal law may still be in transition, but your responsibility is not waiting for it to resolve. Here is a practical plan to protect your business and your customers in 2026.
You cannot protect what you don’t know you have. Document, in a simple spreadsheet:
This is the single most important lesson carried forward from both Law 25 and the now-dead Bill C-27 — and it’s the model Bill C-36 would likely make mandatory federally if enacted. A genuine program includes:
Stop hiding consent inside dense fine print. Move to an active, opt-in model:
Begin with the fundamentals rather than waiting for a comprehensive overhaul:
Don’t let the ongoing uncertainty around federal legislation lull your business into a false sense of security. Customer expectations, the enforcement power of provincial regulators like Quebec’s CAI, and the persistent risk from cybercriminals have already created a higher practical standard than PIPEDA alone requires — and Bill C-36 signals that federal law is trying to catch up to that reality, even if it takes another attempt or two to get there.
By treating customer data with the seriousness it deserves now, you’re not just positioning your business for whatever law eventually passes — you’re building your single greatest asset: genuine customer trust. A Brampton small business that can demonstrably show it takes privacy seriously holds a real competitive advantage over those still waiting for a law to force their hand.
If you need help building a privacy program that meets today’s Law 25 standard, or want your practices reviewed against where federal law appears to be heading, contact GS Arora Law to speak with our business law team.
Disclaimer: The information provided in this blog is for general informational purposes only and should not be considered legal, tax, financial, or professional advice. Bill C-36 was introduced in Parliament on June 15, 2026, and had not received Royal Assent as of publication; it may be amended or may not become law. Regulations and procedures may change over time and vary by jurisdiction. For guidance tailored to your specific situation, please consult a qualified professional.