Canada's New Privacy Law: What Bill C-36 Means for Lenders and Affiliates

Bill C-36 would replace PIPEDA with the Protecting Privacy and Consumer Data Act. What changes for lenders and affiliates, plus a province by province map.

Cris Ravazzano

Canada is on its third attempt in six years to replace the privacy law that governs almost every lead generation funnel in the country. On June 15, 2026, the federal government introduced Bill C-36, which would enact the Protecting Privacy and Consumer Data Act (PPCDA) and repeal the privacy half of PIPEDA. If it passes, it will be the biggest change to Canadian private sector privacy rules since PIPEDA came into force in 2001.

For anyone running loan offers, buying or selling leads, or operating a lender matching funnel, this is not an abstract compliance story. The parts of the bill that bite hardest are the parts that describe exactly what we do: collecting personal financial information from a consumer, using inferred data to score and route them, disclosing that information to third party lenders, and sometimes moving it across the border.

Status check, as of August 2026: Bill C-36 received first reading on June 15, 2026 and has not passed. Parliament rose for the summer and returns September 21, 2026. Coming into force is tied to an order in council and depends on the creation of a new regulator that itself depends on a separate bill, Bill C-34. PIPEDA is still the operative federal law today. Nothing in this article is a compliance deadline. It is a heads up on where the rules are heading and which of your current practices are most exposed.

What applies right now: the current map

Before getting to the new bill, it helps to be precise about the existing patchwork, because a lot of affiliates and even some lenders describe it inaccurately.

PIPEDA is the federal private sector privacy law. It applies to organizations collecting, using or disclosing personal information in the course of commercial activity. Critically, it applies in three situations that matter for our industry: to federally regulated businesses such as banks, to any commercial activity in a province that does not have its own substantially similar law, and to all interprovincial and international transfers of personal information, including in provinces that do have their own law. If you are an affiliate in Vancouver sending leads to a lender in Toronto, that flow is federal.

Three provinces have their own private sector privacy statutes that have been deemed substantially similar to PIPEDA: Alberta and British Columbia, each with a Personal Information Protection Act (PIPA), and Quebec, with the Act respecting the protection of personal information in the private sector, heavily amended by Law 25. Organizations covered by those laws are generally exempt from PIPEDA for activity that happens entirely within the province.

PIPEDA was amended in 2026. Bill C-15, the Budget 2025 Implementation Act, received royal assent on March 26, 2026 and added a data mobility framework to PIPEDA, the first federal data portability right in Canadian law. It is not yet in force. It comes into force by order in council and only becomes operational once regulations establish sector specific data mobility frameworks, which are expected to roll out industry by industry starting with banking under the Consumer Driven Banking Act. This is the regime that will eventually formalize consumer permissioned financial data sharing, so it is worth watching if you rely on instant bank verification in your funnel.

The adjacent regimes people forget

Privacy law is only one layer. Three others regularly catch loan affiliates off guard.

  • CASL governs commercial electronic messages and is enforced separately from privacy law, with its own consent, identification and unsubscribe requirements. Privacy consent and CASL consent are not the same thing and cannot be collected with the same checkbox language. If that distinction is fuzzy for you, start with our guide to CASL and email marketing in Canada, then look at the operational side in our email deliverability guide.
  • Consumer reporting and credit reporting statutes are provincial. Quebec's Credit Assessment Agents Act, in force since February 2023, gave residents security freezes, security alerts and explanatory statements on their credit files, supervised by the AMF. Ontario has been bringing amended provisions of its Consumer Reporting Act into force, with credit freezes becoming available to Ontarians as of July 1, 2026, and British Columbia has announced consumer protection amendments moving in the same direction. Frozen files change the economics of a funnel that assumes a bureau pull will always succeed.
  • Health privacy statutes in Ontario, New Brunswick, Nova Scotia and Newfoundland and Labrador have been deemed substantially similar for personal health information. Mostly out of scope for credit, but relevant if you run any offers touching medical or disability financing.

Province by province

Jurisdiction Private sector privacy law Regulator What to watch
Federal PIPEDA Office of the Privacy Commissioner of Canada Bill C-36 would replace it with the PPCDA and move oversight to a new commission
Quebec Act respecting the protection of personal information in the private sector, as amended by Law 25 Commission d'acces a l'information Strictest regime in Canada. Express consent for sensitive information, privacy impact assessments before out of province transfers, portability, private right of action, significant penalties
Alberta Personal Information Protection Act (PIPA) Office of the Information and Privacy Commissioner of Alberta Reform is live. A legislative committee published 12 recommendations in February 2025, including giving the OIPC power to levy administrative monetary penalties, and a public consultation ran February to May 2026
British Columbia Personal Information Protection Act (PIPA) Office of the Information and Privacy Commissioner for BC No private sector reform bill introduced as of mid 2026. BC's 2026 Bill 9 amended the public sector law only
Ontario PIPEDA applies. No general private sector statute OPC federally. Ontario IPC for health information under PHIPA Consumer Reporting Act amendments phasing in, including credit freezes from July 1, 2026
Manitoba, Saskatchewan PIPEDA applies OPC Provincial consumer protection and credit reporting statutes still apply separately
New Brunswick, Nova Scotia, Newfoundland and Labrador PIPEDA applies to commercial activity. Provincial health privacy statutes deemed substantially similar for health information OPC, plus provincial commissioners for health information No general private sector reform signalled
PEI, Yukon, NWT, Nunavut PIPEDA applies OPC No general private sector reform signalled

One structural point worth flagging: if the PPCDA passes, the provincial laws would need to be re-assessed as substantially similar against the new federal standard, not against PIPEDA. Practitioners generally expect Alberta and BC to move to realign. Alberta's own committee explicitly recommended monitoring federal reform to preserve that status. In the interim, the gap between the strictest regime, Quebec, and the loosest may widen before it narrows. We have written separately about the operational side of that gap in running loan offers in Quebec.

What Bill C-36 would actually change

The PPCDA carries over most of the substance of the Consumer Privacy Protection Act from the dead Bill C-27, including committee amendments. If you tracked C-27, you already know most of it. Two things are genuinely new: there is no bundled AI statute this time, and enforcement moves out of the Office of the Privacy Commissioner entirely.

A new regulator with real teeth. Rather than keeping the Privacy Commissioner and adding a separate tribunal, as C-27 proposed, Bill C-36 hands private sector privacy oversight to a Digital Safety and Data Protection Commission of Canada. That body does not exist yet. It would be created by Bill C-34, the online harms bill, which C-36 amends to rename and expand. A designated Privacy and Consumer Data Commissioner would investigate complaints and issue notices of contravention. The Commission would make orders and impose penalties, with appeals to the Federal Court. Administrative monetary penalties are capped at the greater of $10 million or 3 percent of gross global revenue, and the most serious offences carry fines up to the greater of $25 million or 5 percent of gross global revenue.

Consent gets specific, and this is the one that matters most for lead generation. Consent remains the default basis for collection, use and disclosure. Express consent becomes the default form, with implied consent available only where appropriate given the individual's reasonable expectations and the sensitivity of the information. Valid consent requires plain language disclosure of the purposes, the manner of collection, the reasonably foreseeable consequences, the specific types of information collected, and the names or types of third parties to whom the information may be disclosed. Consent obtained through false, misleading or deceptive practices would be invalid.

Read that last requirement carefully against your actual landing pages. A generic "we may share your information with our trusted partners" line is thin under PIPEDA guidance today and would be considerably weaker under a codified standard. Lenders should be asking sourcing questions about this now rather than after the fact. Our lender due diligence checklist covers the questions to put to a lead provider, and our guide to evaluating a Canadian loan affiliate program covers it from the other direction.

Two consent exceptions, with limits that cut against marketing. The bill carries forward a business activities exception, covering things like providing a product the individual requested, security, and product safety. It is limited to collection and use, not disclosure, and it explicitly cannot be relied on where the purpose is to influence the individual's behaviour or decisions. That carve out is aimed squarely at marketing. There is also a broader legitimate interest exception which, unlike in C-27, extends to disclosure as well as collection and use. But relying on it requires identifying and describing the interest and completing a privacy impact assessment identifying and mitigating foreseeable adverse effects, producible to the Commission on request.

Inferred information is expressly personal information. PIPEDA and the CPPA both defined personal information as information about an identifiable individual. The PPCDA adds information that is inferred about the individual. That likely captures scores, segments, propensity models and the output of AI processing. If you build audience segments or route leads based on derived signals, those derived signals are in scope. This is directly relevant to the kind of work described in our messaging playbook built from application data, and it is a good argument for keeping that analysis at the aggregate level.

A statutory definition of sensitive information, and children under 18. The bill defines a child as anyone under 18 and enumerates sensitive categories including a child's personal information, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic and health information, biometrics, and sexual orientation. Sensitivity drives obligations throughout the act, including safeguards, retention limits and whether implied consent is available at all. Notably, detailed financial information is not in the enumerated list, but sensitivity is assessed contextually and regulators have long treated financial data as sensitive.

Automated decisions get an explanation right and a human review right. The threshold shifts from decisions with a significant impact to predictions, recommendations or decisions with a legal or similarly significant effect, mirroring GDPR language. On top of the right to an explanation, individuals would get the right to make written representations to a human employee able to review the decision. Automated decline logic, eligibility gates and instant approval flows all sit inside that definition.

Cross border transfers require a privacy impact assessment. Before disclosing or transferring personal information outside Canada, an organization would have to carry out a PIA and implement measures mitigating the risks identified, through contractual protections, approved codes of practice or certification. The assessment must be available to the Commission on request. If you send Canadian leads to a US buyer, or use US based service providers for hosting, dialers, email or attribution, this becomes a documentation exercise you do not currently have to perform.

Service providers get direct statutory obligations. Transfers to a service provider would not require separate consent, but service providers themselves would carry direct duties around safeguards and breach notification, and a service provider that starts using data for its own purposes stops being a service provider. Worth reviewing against how your tracking, verification and enrichment vendors actually use your data.

De-identified and anonymized data are treated differently, and the anonymization test got more workable. De-identified information remains personal information and stays in scope, with re-identification prohibited. Anonymized information falls outside the act entirely. C-27's definition of anonymization was absolute and widely criticized as unusable. The PPCDA adopts a risk based test borrowed from Quebec's Law 25: no reasonably foreseeable risk in the circumstances that an individual can be identified. That makes anonymization a more realistic route for analytics and benchmarking work, though the requirement that modification be irreversible and permanent keeps the bar high.

Documented programs, not informal judgement. The bill requires a documented privacy management program scaled to data volume and sensitivity, producible to the Commission on request. Combined with the PIA requirements for legitimate interest and cross border transfers, the through line is that decisions need to be written down. Reasonable judgement that lives only in someone's head will not be enough.

Individuals can sue. The PPCDA retains a private right of action, contingent on a finding of contravention by the Commissioner, the Commission or a court, with a two year limitation period. This is new at the federal level and mirrors the litigation exposure that already exists under Law 25.

What to do in the next two quarters

Nothing here requires panic, and the bill will change in committee. But most of the following is defensible work regardless of whether C-36 passes in its current form.

  • Audit your consent language against the third party disclosure requirement. Can you name, or at minimum accurately categorize, every party receiving the lead? If a partner list is dynamic, decide now how you will describe it in plain language.
  • Separate privacy consent from CASL consent in your forms and in your records. They are different consents with different scopes.
  • Map where Canadian data goes. Every US vendor, every cross border buyer, every offshore call centre. That map is the raw input for the transfer PIAs the bill would require.
  • Inventory your inferred data. Scores, tiers, segments, model outputs. Decide what genuinely needs to stay identifiable.
  • Look at your automated decision points and ask whether you could explain any one of them to a consumer in writing, and who at your company would perform a human review.
  • Tighten identity and consent verification. Deceptively obtained consent would be invalid consent, which puts more weight on being able to prove the consumer you have on record is the one who actually submitted. Our piece on the limits of SMS OTP is relevant here.
  • Write things down. A short documented privacy management program is cheap now and expensive to reconstruct later.
  • Have a working rights request process. Access, correction, withdrawal and disposal requests all exist under PIPEDA today. Ours is at creditmarketing.ca/privacy-request.

The direction of travel across every Canadian jurisdiction is the same: more specific consent, more documentation, more consumer control over derived data, and regulators who can fine without going to court first. Bill C-36 is the federal expression of that. Operators who already run clean, verifiable consent will find the transition mostly administrative. Operators whose funnels depend on vague sharing language and undocumented data flows have more work ahead.

This article is general information for marketers and lenders, not legal advice. Bill C-36 is at first reading and its provisions may change substantially before enactment. Consult qualified Canadian privacy counsel about your specific practices.

Cris Ravazzano

Cris Ravazzano

Head of Marketing & Technology at Loans Canada and CreditMarketing.ca