New Consumer Privacy Law
An Act to enact the Protecting Privacy and Consumer Data Act, to amend the Personal Information Protection and Electronic Documents Act and to make amendments to other Acts
Summary
- Replaces PIPEDAās privacy regime with the Protecting Privacy and Consumer Data Act governing how businesses collect, use, disclose, retain, secure, and dispose of personal information, with consent rules, limited business and publicāinterest exceptions, and riskābased "appropriate purposes."
- Requires privacy management programs, data minimization, retention limits, security safeguards, breach reporting to a new federal commission and to affected individuals, and expanded individual rights including access, explanations for automated decisions, disposal (erasure) on request, and data mobility via future regulations.
- Establishes the Digital Safety and Data Protection Commission of Canada, a Privacy and Consumer Data Commissioner, and a specialized Division to guide, audit, order compliance, approve codes/certifications, and impose administrative penalties (up to the greater of $10M or 3% of global revenue) and criminal fines for egregious offences (up to the greater of $25M or 5%).
- Sets conditions for crossāborder transfers (privacy impact assessments and mitigation), authorizes deāidentification/anonymization with limits, provides whistleblower protections, and coordinates with the CRTC, Competition Bureau, and other statutes; includes national security and lawāenforcement exceptions.
- Renames the remainder of PIPEDA as the Electronic Documents Act and makes broad consequential amendments; most provisions come into force by order in council.
Builder Assessment
Overall, the bill strengthens trust in the digital economy, aligns Canada with major trading partners, and introduces data mobility and enforcement tools that can enhance competitiveness and exports. However, without riskāproportionate implementation, the added compliance load and liability could weigh on SMEs and slow innovation; targeted adjustments can preserve safety and security while reducing drag on growth.
- Strong alignment with international norms can unlock market access, investor confidence, and consumer trustākey to prosperity and export growth.
- Data mobility and certification/codes can increase competition and lower switching costs, improving productivity.
- Compliance demands (privacy programs, PIAs for foreign transfers, documentation, heavy penalties) risk overāburdening SMEs and new entrants.
- Builders should press for riskābased thresholds and de minimis carveāouts for microāenterprises, with plainālanguage compliance toolkits.
- Builders should seek safeāharbour mechanisms via approved codes/certifications and standardized contractual clauses for crossāborder transfers to avoid caseābyācase PIAs where risk is low.
- Builders should advocate oneāstopāshop coordination with provincial regulators and clear, timeābound service standards for the Commission to prevent delays.
- Builders should ensure clear guidance on ālegitimate interests,ā automated decision explanations, and interoperability with EU/US frameworks to minimize friction.
- Builders should support phased implementation and transitional relief to avoid disruption while maintaining strong breachānotification and security safeguards for Canadians.
Question Period Cards
What concrete measures will protect small and mediumāsized businesses from disproportionate compliance costs, such as riskābased thresholds, standardized templates, or safeāharbour certifications to avoid duplicative audits and assessments?
Will the minister quantify the impact on crossāborder trade and confirm that transfer assessments will not become de facto data localization, and that this framework will secure EU adequacy and support interoperable flows with the United States?
What service standards and resources will the new Commission commit to for approving codes of practice, certifications, and resolving complaints so businesses and consumers get timely, predictable outcomes without regulatory pileāup with provincial privacy authorities?
Principles Analysis
Canada should aim to be the world's most prosperous country.
Modern, enforceable privacy rules can boost consumer trust and digital commerce, aligning Canada with global standards that support longārun prosperity.
Promote economic freedom, ambition, and breaking from bureaucratic inertia (reduce red tape).
Mandated privacy programs, crossāborder transfer assessments, extensive reporting, and high penalties add compliance burden, especially for SMEs, despite some flexible tools (legitimate interest, codes, certifications).
Drive national productivity and global competitiveness, including removing interprovincial trade barriers and improving labour mobility (one country, one market).
Data mobility, clear rights, and interoperable codes/certifications can spur competition and platform switching, while international alignment helps firms compete abroad.
Grow exports of Canadian products and resources, and move up the value chain by processing resources domestically rather than exporting them raw.
A robust privacy framework facilitates crossāborder data flows and adequacy with trading partners, reducing barriers to exporting digital services and dataāenabled goods.
Encourage investment, innovation, and resource development.
Regulatory certainty and trust can attract investment, but added compliance costs and liability risk may chill startup innovation unless implementation is riskābased.
Deliver better public services at lower cost (government efficiency).
Creates a centralized commission that could streamline enforcement and guidance, but also expands bureaucracy and ongoing operating costs.
Reform taxes to incentivize work, risk-taking, and innovation.
No material tax measures are included.
Focus on large-scale prosperity, not incrementalism.
This is a comprehensive overhaul of Canadaās privateāsector privacy law with significant marketāwide effects, not a minor tweak.
Did we get the builder vote wrong?
Email [email protected]