The Digital Charter Implementation Act (DCIA) never became law: Bill C-11 died at the 2021 election and Bill C-27 on prorogation in January 2025. Its successor, Bill C-36, the Protecting Privacy and Consumer Data Act, was tabled on 15 June 2026. What still applies today — PIPEDA, Quebec's Law 25, Ontario's FIPPA amendments, CASL — and how we help organizations get consent, retention and assessments right.
Three federal bills since 2020, none yet law. What applies today is PIPEDA, the provinces and the sectors — and the site has to get consent right regardless.
since 2020 — none yet law
3 billssince 2020 — none yet law
Bill C-36 tabled, at first reading
15 June 2026Bill C-36 tabled, at first reading
Ontario's FIPPA amendments in force
1 July 2025Ontario's FIPPA amendments in force
Three bills, one law still standing
The Digital Charter Implementation Act was the federal government’s plan to replace PIPEDA, the private-sector privacy law Canada has had since 2000, with a Consumer Privacy Protection Act modelled partly on Europe’s GDPR: consent by purpose, data mobility, a right to disposal, transparency for algorithms, and penalties in the tens of millions. It was tabled as Bill C-11 in November 2020 and died at the 2021 election; tabled again as Bill C-27 in June 2022, studied in committee for two years, and died on the order paper when Parliament was prorogued on 6 January 2025. On 15 June 2026 the government tabled its third attempt under a new name — Bill C-36, the Protecting Privacy and Consumer Data Act — and Parliament rose three days later. Second reading is expected this fall.
So, as of September 2026, PIPEDA is still the law, and the obligations that have actually changed in the past two years are provincial and sectoral: Quebec’s Law 25, fully in force; Ontario’s Bill 194, which made privacy impact assessments and breach reporting mandatory for public-sector institutions on 1 July 2025; PHIPA for health custodians; CASL for anyone sending commercial email.
What to do now
Prepare for C-36 the way you should already be complying with PIPEDA and Law 25: know what you collect and why, ask for consent by purpose in language people understand, keep information only as long as the purpose needs, write the assessments before the data moves, and make every consent mechanism accessible — because for Ontario organizations the accessibility obligation is already law. When C-36 passes, the organizations that did this will change some documents; the ones that did not will change everything.
Not legal advice
We are engineers, not lawyers. We keep this page current as the bills move, we build the technical side of compliance, and we work with your counsel on the rest.
What applies today
As of September 2026 the federal reform is a bill; these are the laws
PIPEDA — still the federal law
Canada’s private-sector privacy law since 2000: meaningful consent, purposes limited to what a reasonable person would expect, safeguards, access, and mandatory breach reporting since 2018. Every bill since 2020 has proposed to replace its Part 1; none has yet, so it governs your organization today.
Quebec's Law 25 — in force
Phased in from 2022 to 2024: a designated privacy officer, privacy impact assessments before information leaves the province, consent by purpose in clear language, and penalties that reach into the millions. If you have customers in Quebec, it applies now.
Ontario public sector — Bill 194
FIPPA institutions have had mandatory privacy impact assessments and breach reporting to the Information and Privacy Commissioner, at the real-risk-of-significant-harm threshold, since 1 July 2025, with whistleblower protections since January 2025. The Commissioner can now review practices and order corrections.
Health and marketing — PHIPA and CASL
Ontario’s health custodians answer to PHIPA; anyone sending commercial email answers to CASL, in force since 2014 and enforced. Both predate the federal reform and are unaffected by it.
Bill C-36 — what would change
Tabled 15 June 2026 as the Protecting Privacy and Consumer Data Act: a new Digital Safety and Data Protection Commission replacing the Privacy Commissioner, a legitimate-interest exception to consent, a line between de-identified and anonymized data, explanations for automated decisions with significant effects, assessments before data leaves Canada, administrative penalties up to the greater of $10 million or 3 per cent of global revenue, offences up to $25 million or 5 per cent, and a private right of action. Second reading is expected in the fall.
Cookie consent, in practice
Analytics that do not profile or influence people have sat inside a business-activities exception in every draft; advertising that does has not. We wrote about it when C-11 was tabled — Accept cookies? Does the DCIA mean nagging for Canadians? — and the direction has held through three bills.
How we help
The engineering side of privacy — with your counsel, not instead of them
Map what you collect
Every form, cookie, analytics tag, integration and export, with its purpose, its legal basis and where it goes. Most organizations discover collection they did not know they had.
Fix consent and retention
Consent asked for the purpose, in plain language, accessible to everyone; retention and disposal written down and automated rather than remembered.
Prepare the assessments
Privacy impact assessments in the form your regulator expects — mandatory for Ontario institutions since July 2025, for Quebec transfers under Law 25, and for cross-border disclosure under C-36 if it passes.
Build it into the site
Consent mechanics that actually work in your stack, tested with assistive technology, and a record of what was shown and when. This site runs no client-side analytics at all — a choice we can make for you too.
Who this is for
Ontario public-sector institutions
Ministries, agencies, municipalities, universities, hospitals and boards under FIPPA and MFIPPA, now with mandatory assessments and breach reporting — and an obligation to build accessibly at the same time.
Businesses under PIPEDA
Organizations that collect personal information in commercial activity, with customers in Quebec or across borders, who need to be right under today’s law and ready for C-36.
Health custodians
Clinics, family health teams and research organizations under PHIPA, whose websites, portals and forms carry the most sensitive information of all.
Questions we're asked
Is the DCIA law?
No. The Digital Charter Implementation Act was tabled twice — as Bill C-11 in November 2020, which died when the 2021 election was called, and as Bill C-27 in June 2022, which died when Parliament was prorogued on 6 January 2025. It was never reintroduced under that name.
What does DCIA mean?
Digital Charter Implementation Act — the name of the omnibus federal bills meant to implement Canada’s Digital Charter by replacing PIPEDA with a Consumer Privacy Protection Act, creating a tribunal and, in C-27, regulating artificial intelligence. Its successor has a different name: Bill C-36, the Protecting Privacy and Consumer Data Act.
What is Bill C-36?
The government’s third attempt at private-sector privacy reform, tabled on 15 June 2026 by the Minister of Artificial Intelligence and Digital Innovation. It would replace Part 1 of PIPEDA, create a new regulator, add a legitimate-interest exception, require explanations for consequential automated decisions and assessments before data leaves Canada, and raise penalties sharply. It is at first reading; second reading is expected when Parliament returns on 21 September 2026, and it must still pass committee, third reading and the Senate. Artificial intelligence is being handled separately.
Do Canadian websites need a cookie banner?
Under today’s law meaningful consent applies, and the Privacy Commissioner’s guidance has long distinguished analytics from tracking that profiles or targets people. Every federal draft has kept a business-activities exception for collection a reasonable person would expect and that does not influence their decisions — which is where privacy-respecting analytics sit — and none has exempted advertising. Quebec’s Law 25 is stricter. If you need a banner, it has to be accessible and it has to work; we test both.
What should an Ontario public-sector institution do now?
Treat Bill 194 as the deadline that has already passed: a privacy impact assessment for every new or changed collection of personal information, a breach process that assesses the real risk of significant harm and reports to the Commissioner and to affected people, and the safeguards the Commissioner can now review. We build the assessments and the technical controls with your privacy office.
Are you a law firm?
No. This page is informational, kept current as the bills move, and not legal advice. We build the technical side — the inventory, the consent mechanics, the retention automation, the assessments’ technical annexes — and we work with your counsel or privacy officer on the rest.