#
No standing position recorded for this category.
This is reported at Probable confidence: the underlying source has not independently confirmed Bill C-36's legislative reading-stage status on LEGISinfo this cycle. What is established with higher confidence is the backdrop against which this reform is being read: the enforcement gaps that Bill C-27 was intended to close - the absence of order-making power and of administrative monetary penalties available to the Privacy Commissioner - remain features of the current PIPEDA regime as it stands today.
Regulator and framework architecture, unchanged in substance. Canada's federal private-sector privacy law continues to be PIPEDA, enforced by the Office of the Privacy Commissioner of Canada. Quebec, British Columbia and Alberta continue to operate their own "substantially similar" provincial statutes, which displace PIPEDA for intra-provincial commercial activity in those provinces. This structural feature of Canadian privacy federalism is unaffected by the Bill C-36 development and remains the baseline against which any federal reform will operate.
The enforcement-power gap this cycle's reform targets - no order-making power, no OPC-levied administrative monetary penalties - is a matter this brief notes only in its data-protection dimension. Where such gaps intersect with anti-money-laundering supervisory design or payments-sector conduct obligations, those intersections are the proper subject of the financial-integrity and world-payments monitors respectively, not analysed further here.
The development to watch is whether Bill C-36 advances through further legislative readings toward enactment, and whether its proposed PPCDA framework would in fact close the order-making and administrative-monetary-penalty gaps that have persisted since Bill C-27's death. Confirmation of Bill C-36's precise reading-stage status on LEGISinfo would raise confidence in the reform's trajectory beyond the current Probable tier.
No standing position recorded for this category.
No standing position recorded for this category.
No standing position recorded for this category.
No standing position recorded for this category.
No standing position recorded for this category.
No standing position recorded for this category.
No standing position recorded for this category.
No standing position recorded for this category.
No standing position recorded for this category.
No standing position recorded for this category.
Filters combine as OR inside a group and AND across groups.
Blocking. 4 failing check(s).
schema_valid | pass |
min_t1_per_instrument_met | n/a — no subject in this jurisdiction |
min_quoted_text_present | FAIL |
translation_provenance_recorded | FAIL |
egress_verified | pass |
source_tier_integrity_ok | FAIL |
jurisdiction_source_floor_met | FAIL |
tier_a_b_national_primary_pct | 0.0 |
aggregator_only_jurisdiction_count | 0 |
manual_override |
Provenance only. Nothing below gates publication or affects the render.
| Field | Value |
|---|---|
trust.lawyer_review.status | never_reviewed |
trust.lawyer_review.reviewer | no reviewer on record |
trust.content_source | ai_generated |
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 0 sub-module(s), 0 claim(s) (0 category placement(s)), 4 source(s) in the cumulative register.
Think something on this page is wrong? Report an error.
Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).
| Article | Category | Sub-module |
|---|---|---|
Art. 5 | Controller/Processor Duties | accountability and dpia |
Art. 6 | Lawful Processing & Special Data | lawful bases |
Art. 7 | Lawful Processing & Special Data | consent thresholds |
Art. 9 | Lawful Processing & Special Data | special categories |
Art. 13 | Data Subject Rights | access right |
Art. 14 | Data Subject Rights | access right |
Art. 15 | Data Subject Rights | access right |
Art. 16 | Data Subject Rights | rectification and erasure |
Art. 17 | Data Subject Rights | rectification and erasure |
Art. 18 | Data Subject Rights | data portability |
Art. 19 | Data Subject Rights | rectification and erasure |
Art. 20 | Data Subject Rights | data portability |
Art. 21 | Data Subject Rights | restriction and objection |
Art. 22 | Algorithmic, Biometric & Surveillance Governance | automated decision making transparency |
Art. 25 | Controller/Processor Duties | accountability and dpia |
Art. 28 | Controller/Processor Duties | joint controller arrangements |
Art. 30 | Controller/Processor Duties | ropa requirements |
Art. 32 | Controller/Processor Duties | security measures |
Art. 33 | Controller/Processor Duties | breach notification |
Art. 34 | Controller/Processor Duties | breach notification |
Art. 35 | Controller/Processor Duties | accountability and dpia |
Art. 37 | Controller/Processor Duties | dpo requirements |
Art. 38 | Controller/Processor Duties | dpo requirements |
Art. 39 | Controller/Processor Duties | dpo requirements |
Art. 44 | Cross-Border & Adequacy | transfer mechanisms |
Art. 45 | Cross-Border & Adequacy | adequacy received |
Art. 46 | Cross-Border & Adequacy | adequacy granted |
Art. 47 | Cross-Border & Adequacy | sccs and bcrs |
Art. 48 | Cross-Border & Adequacy | transfer impact assessment |
Art. 49 | Cross-Border & Adequacy | data localisation |
Art. 77 | Enforcement & Redress | regulator powers and penalties |
Art. 78 | Enforcement & Redress | private right of action |
Art. 79 | Enforcement & Redress | private right of action |
Art. 80 | Enforcement & Redress | collective redress and class actions |
Art. 82 | Enforcement & Redress | private right of action |
Art. 83 | Enforcement & Redress | regulator powers and penalties |
Art. 84 | Enforcement & Redress | regulator powers and penalties |