Bill C-36 vs. CCPA vs. GDPR: What Canadian Businesses With U.S. Reach Actually Need to Know

A customer in Toronto signs up on your site at 9:14 on a Tuesday morning. By 9:15, that record is sitting on a U.S. email platform's servers, mirrored into your analytics, and queued into an ad audience. So between PIPEDA, CCPA, and GDPR, whose rules is that record playing by? Strictly speaking, just PIPEDA's. But it's a trick question, because the pipeline that record just traveled is the same one carrying your California customers and your EU visitors, and that pipeline answers to all three.
I wrote about what's actually in Bill C-36 when it was tabled in June. Since that post went live, the question I keep getting from worried clients isn't about the bill. It's how the bill stacks up against the laws they already answer to, California's CCPA and Europe's GDPR. Which is a fair question. If you sell into the U.S., you're already living under one of them, and maybe both.
My advice hasn't changed. Don't build a data privacy compliance program for one law. Build one program to the strictest rule on each topic, because that's where all three are headed anyway.
One customer record, three privacy laws
Follow that 9:14 signup and count the hops.
The first hop is the collection itself, in Ontario. Today that's PIPEDA territory. If Bill C-36 passes, it becomes PPCDA territory, and as the bill is tabled, sending that record anywhere outside Canada would first require a privacy impact assessment.
The second hop happens a second later, when the record lands on your email platform's U.S. servers and gets mirrored into your analytics. That's the cross-border data transfer most Canadian stacks make hundreds of times a day without anyone thinking about it. And if the same list holds Californians, and at any real volume it does, CCPA applies to you directly, not just to your vendor.
The third hop is the one you didn't plan. A shopper in Munich fills out the same form. GDPR applied to that record from the first keystroke. The EU reaffirmed Canada's adequacy status in January 2024, its first full review since 2001, which keeps EU data flowing to PIPEDA-covered businesses without extra paperwork.
Same record, three rulebooks. And because your stack runs one consent setup, one retention schedule, and one set of tags for everyone who flows through it, the strictest rule ends up being the real rule.
Bill C-36 vs. CCPA vs. GDPR at a glance
People ask me for the PIPEDA vs. GDPR comparison or the PIPEDA vs. CCPA comparison, and the honest answer is that the useful comparison now runs three ways.
| Bill C-36 (PPCDA) | CCPA (California) | GDPR (EU) | |
|---|---|---|---|
| Status | Proposed. First reading June 15, 2026 | In force since 2020, new regulations effective January 1, 2026 | In force since May 2018 |
| Who it covers | Organizations handling personal information in commercial activity in Canada | For-profit businesses doing business in California that meet a threshold, wherever they're based | Any organization offering goods or services to people in the EU, or monitoring them |
| Regulator | Digital Safety and Data Protection Commission of Canada (proposed) | California Privacy Protection Agency and the Attorney General | National data protection authorities |
| Who can come after you | The Commission, plus a private right of action for individuals | The CPPA, the AG, and residents in breach cases | DPAs, plus individual complaints and lawsuits |
| Maximum penalties | Greater of $25M CAD or 5% of gross global revenue for serious offences | $2,663 USD per violation, $7,988 if intentional or involving minors, no cap on the count | Greater of €20M or 4% of global annual turnover |
| Cross-border transfers | Privacy impact assessment before personal information leaves Canada | No transfer restriction, contractual duties with service providers | Adequacy decision or safeguards such as standard contractual clauses |
| Children's data | Under 18 treated as sensitive by definition | Opt-in required to sell or share data of consumers under 16 | Parental consent under 16, member states may lower to 13 |
Comparison current as of September 2026. Bill C-36 figures reflect the bill as tabled and may change in committee.

If the table feels abstract, here's the same mistake with three price tags. Tim Hortons tracked app users' locations even when the app was closed, and Canada's regulator could order nothing but recommendations. Honda made opting out harder than opting in and paid $632,500 in a settlement over CCPA violations. Meta moved data across a border without valid safeguards and was fined €1.2 billion. The gap between those outcomes is the gap Bill C-36 was written to close, which is why the Canadian column in that table won't stay quaint.
Does CCPA apply to Canadian companies? It already might
Yes, if you do business in California and clear one of three thresholds, and neither your incorporation papers nor your postal code changes that.
A company I know has been making the same product for over thirty years. Mid-sized, established, nobody's idea of a data business. So I was surprised to spot a consent management platform on their website, and I asked the owner about it. California had already served them a demand letter. I'd have lost money betting on that one. Large or small, it does not matter.
The demand letter is the part people typically miss. In most U.S. states, only the attorney general can bring a privacy suit, and attorneys general have limited time and long lists. California is where private plaintiffs get into the act, whether that's a breach claim under the CCPA or a wiretapping claim over your tracking tags, so enforcement often arrives as a demand letter from a plaintiff's firm instead of a press release from a regulator. Bill C-36 would give Canadians their own route to damages, nationwide.
The current thresholds are annual gross revenue above $26.6 million, buying, selling, or sharing personal information of 100,000 or more California consumers or households, or earning half your revenue from selling or sharing personal information. The one mid-market companies trip is the 100,000 mark, and the thing that usually trips it is the email list, as it's usually the one thing that keeps accumulating. Fines run $2,663 per violation and $7,988 when it's intentional or involves minors, applied per consumer, so the math gets loud fast.
And the rules have tightened this year. New CCPA regulations took effect January 1, 2026, with automated decision-making rules following January 1, 2027 and risk assessments to be conducted by December 31, 2027. Here's a question I typically ask my clients. When did anyone last test whether your site honors a Global Privacy Control signal? Sephora paid $1.2 million partly for ignoring GPC, and it's a browser setting most Canadian teams have never once tested against their own site.
Privacy impact assessments are where Bill C-36 goes past GDPR
GDPR polices transfers by destination. Data can leave the EU when the receiving country holds an adequacy decision or safeguards like standard contractual clauses are in place, and skipping that step is expensive. Uber was fined €290 million by the Dutch regulator for moving EU driver data to the U.S. without them.
Bill C-36, as tabled, doesn't care about the destination. It requires a privacy impact assessment before personal information leaves Canada at all, the U.S. included. The ordinary hop into a U.S. email platform, the one nobody thinks about, becomes the regulated event.
A PIA sounds heavier than it is. In practice it's an inventory of your hops, a risk read on each one, and a mitigation you can defend in writing. If you've never mapped where your customer data actually goes, that map is the whole job, and it's the same map GDPR and California's risk assessments draw from.
Some acronym housekeeping, because this space is crowded. The PPCDA is the proposed Canadian act inside Bill C-36. The CPPA is California's privacy regulator, and it was also the name of Canada's failed 2022 attempt. If a vendor pitch mixes those up, ask more questions.
Two more places C-36 sets the strictest bar. It treats anyone under 18 as a child and their data as sensitive by definition, tougher than CCPA's under-16 opt-in and GDPR's default of 16, and regulators grade this category hardest everywhere. TikTok's €345 million fine over children's defaults is the proof. And the bill draws a hard line between de-identified data, which stays regulated, and truly anonymized data, which falls outside the act.
One privacy program beats three compliance projects
Where companies get bogged down is they try to boil the ocean, one project per law. The overlap is most of the work, so build once against the strictest rule.
- Map your data flows first. Every hop out of Canada, every vendor, every mirror. C-36's PIAs, GDPR's records, and California's risk assessments all draw on the same map.
- Run one retention schedule. All three frameworks punish keeping data forever, and C-36 adds a disposal right individuals can invoke.
- Build one assessment template. C-36 wants privacy impact assessments, California wants risk assessments conducted by the end of 2027, and GDPR has required them since 2018. One document, three headers.
- Take consent management past the banner. The free self-test is a tool like Ghostery, change your consent settings, reload, and watch which tags still fire. Marketing and advertising tags are the ones that bring the lawsuits, so triage there. The five consent gaps we see most often all survive a pretty banner.
- Treat under-18 data as sensitive everywhere you operate, and check your consent basis before old data feeds anything new. Consent to collect is not consent to model, and AI projects are where legacy data comes back to bite.
If your data genuinely never leaves Canada and you sell nowhere else, the U.S. and EU parts of this can wait. You still answer to PIPEDA today, Quebec's Law 25 already has real penalties if you have customers there, and C-36 would apply to you in full the day it takes effect. Besides, I've been doing this a long time and I've never audited a stack that self-contained.
Frequently asked questions
Does CCPA apply to Canadian companies? Yes, when they do business in California and meet a threshold. The current thresholds are $26.6 million in annual gross revenue, personal information of 100,000 or more California consumers or households, or half of revenue from selling or sharing personal information.
Does GDPR apply to Canadian companies? Yes, when they offer goods or services to people in the EU or monitor their behavior, regardless of where the company is based. There is no revenue threshold.
What is the difference between the PPCDA and California's CPPA? The PPCDA is the Protecting Privacy and Consumer Data Act, the proposed Canadian law inside Bill C-36. The CPPA is the California Privacy Protection Agency, the regulator that enforces CCPA. Canada's failed 2022 bill also used the acronym CPPA, which is why the two get confused.
Do I need separate privacy programs for Canada, the U.S., and Europe? No. The three frameworks overlap on data mapping, retention, assessments, and consent. One program built to the strictest requirement on each topic covers the bulk of all three.
Could Canadian businesses still use U.S. cloud providers under Bill C-36? Yes. The bill does not require data localization. As tabled, it requires a privacy impact assessment and appropriate risk mitigation before personal information is transferred outside Canada.
The record doesn't wait for royal assent
That signup from 9:14 already crossed a border, and whichever way Bill C-36 moves this fall, CCPA and GDPR are done moving. In the past, we spent an hour on how consent becomes a competitive advantage if you want the deeper walkthrough. And if you'd rather just know where your own stack stands, we'd love to continue the conversation. The longer you wait to start, the fewer options you'll have.
A quick note from me. I work in data and analytics, not law, and Northern is not a law firm. This post is general information, current as of September 18, 2026. It is not legal advice. Bill C-36 is a proposed law and its details may change, so talk to your privacy counsel before making compliance decisions.
Stay informed, sign up for our newsletter.