Compliance & Privacy

Canada's Privacy Law Reform and Your Dental Practice: What the PPCDA Means in 2026

Bill C-36 is currently at second reading. If passed, it will replace PIPEDA with stricter consent rules, mandatory privacy impact assessments, and penalties up to $25M. Here is what Canadian dental practices need to know now.

August 28, 2026·9 min read

On 15 June 2026, the Canadian government tabled Bill C-36: the Protecting Privacy and Consumer Data Act (PPCDA). It is currently at second reading in the House of Commons and has not yet become law. If passed, it will replace PIPEDA entirely, introduce new patient data rights, and carry penalties reaching $25 million for the most serious violations. Dental practices that start preparing now will face far less disruption when the bill receives Royal Assent.

$25M
Max criminal penalty
45 days
To respond to data requests
3 rights
New for patients if passed

What Is the PPCDA and Where Does It Stand Right Now?

The PPCDA (Bill C-36) was introduced by the Minister of Innovation, Science and Industry on 15 June 2026. It is currently at second reading in the House of Commons, meaning it has been introduced and debated in principle but has not yet moved to committee review, third reading, or Senate passage. No date has been set for Royal Assent.

If passed, the PPCDA would repeal the Personal Information Protection and Electronic Documents Act (PIPEDA) and replace it with a modernised framework that describes privacy as a fundamental right rather than a commercial compliance rule. The bill also creates a new regulator: the Digital Safety and Data Protection Commission of Canada, which would absorb the current Office of the Privacy Commissioner’s private-sector mandate and gain enforcement powers the OPC does not currently hold, including the ability to levy financial penalties directly.

For dental practices, the practical question is not whether to wait until the bill passes. Preparatory work done now, such as auditing patient records, tightening consent forms, and reviewing software data flows, maps directly onto existing PIPEDA compliance obligations and will require no repeat effort when the PPCDA becomes law.

How the PPCDA Differs from PIPEDA: What Changes for Dental Clinics

PIPEDA has governed how Canadian dental practices handle patient data since 2001. It is a purpose-limitation framework: you must collect personal information only for stated reasons and keep it only as long as necessary. The PPCDA keeps that logic but adds several layers that directly affect how a dental practice operates day to day.

The most significant shift is the move from implied to explicit, purpose-specific consent. Under PIPEDA, a patient who hands you a completed intake form and receives treatment has implicitly consented to the collection of clinical data. Under the PPCDA, consent would need to name specific purposes in plain language, and patients would have the right to withdraw it for secondary uses such as marketing, recall communications, or sharing with third-party software vendors.

The second major change is mandatory privacy impact assessments (PIAs) before deploying any new technology that processes personal data. If your practice is considering switching to a cloud-based practice management system, adding an AI diagnostic tool, or onboarding a patient communication platform, a PIA would be required before go-live. The assessment documents what data flows into the system, who can access it, how long it is retained, and what risks it creates.

The third change is a children’s data protection clause. Any personal data collected from patients under the age of 16 would require verifiable parental or guardian consent and is prohibited from being used for profiling or secondary purposes outside direct clinical care.

Current PIPEDA consent rules permit practices to bundle consent: a single signature on an intake form can cover treatment, administrative data use, and communication preferences simultaneously. The PPCDA would disallow bundling where purposes are not directly related. Signing a form to receive dental care could not simultaneously constitute consent to receive recall reminders or promotional messages.

In practice, this means dental practices would need separate, clearly labelled consent fields for at least three categories: clinical data used for treatment, administrative data used for billing and scheduling, and optional communications such as appointment reminders and newsletters. Existing patient consent forms would need updating to meet this standard before the bill receives Royal Assent.

The PPCDA also introduces a meaningful consent requirement: consent obtained using complex or confusing language could be ruled invalid by the new Commission. Enforcement action could follow if a complaint demonstrated that a patient did not genuinely understand what they were agreeing to. Plain language, not legal boilerplate, would be the benchmark.

Test your current consent form against three questions
Does it name every purpose for which data is collected? Does it separate clinical consent from marketing consent? Is the language readable by someone without a legal or medical background? If any answer is no, your forms already fall short of where the PPCDA is heading and, likely, of PIPEDA’s current requirement for meaningful consent.

Data Rights Your Patients Will Have Under the PPCDA

The PPCDA introduces three rights that do not exist in PIPEDA today and will require operational changes at the practice level.

Right to data deletion. Patients would be entitled to request the deletion of their personal information when it is no longer required for the purpose for which it was collected. This does not override provincial record-retention requirements: in Ontario, for example, patient records must be kept for 10 years after the last entry for an adult patient. However, data collected for recall or marketing that is no longer in active use would be subject to deletion requests. Practices would have 45 days to respond to each request and must keep a log of requests received.

Right to data portability. Patients would have the right to receive their personal data in a structured, machine-readable format and to direct its transfer to another provider. For dental practices, this means ensuring your practice management system can export patient records cleanly and without proprietary lock-in that makes transfer impractical.

Right to explanation for automated decisions. Where AI or automated systems influence significant decisions affecting a patient, the practice would need to explain the logic used and offer a meaningful way to contest the outcome. This is unlikely to affect routine appointment scheduling, but it applies to AI diagnostic tools that influence treatment recommendations.

The interaction between these new rights and PHIPA (Ontario’s Health Information Protection Act) and Quebec’s Law 25 is still being mapped by provincial regulators. Dental practices in Ontario should review PHIPA compliance requirements alongside the federal reform to understand how the two frameworks will interact once the PPCDA passes.

Penalties and Enforcement: The New Compliance Stakes

The PPCDA’s penalty structure is a material departure from the current regime, under which the OPC can investigate and make findings but cannot levy fines. The bill proposes two tiers of financial penalty.

Administrative penalties of up to $10 million or 3% of global annual revenue, whichever is greater, would apply to non-compliance with the Act’s core obligations: failing to appoint a privacy officer, collecting data without proper consent, or not responding to patient data requests within the required timeframe.

Criminal penalties of up to $25 million or 5% of global annual revenue would apply to the most serious violations, including intentional misuse of patient data, knowingly collecting data without valid consent, or obstructing a Commission investigation.

For a dental practice, these figures scale directly with billings. A practice generating $2 million per year in revenue could face an administrative penalty of up to $60,000 under the 3% floor before the $10 million cap applies. The percentage floor is specifically designed to ensure penalties are proportionate for smaller organisations, not just large technology companies.

The Digital Safety and Data Protection Commission would also hold audit powers that do not require a prior complaint. Unlike the OPC, which largely responds to complaints, the Commission could proactively examine a dental practice’s data handling processes, share findings with provincial counterparts, and enter into compliance agreements that function as enforceable consent orders.

For an overview of how federal and provincial frameworks already interact across different provinces, see the guide to provincial privacy laws for dental clinics.

What Dental Practices Can Do Now to Prepare

Because the PPCDA is not yet law, practices cannot comply with it today. They can, however, use the bill’s proposed requirements as a roadmap for closing gaps in existing PIPEDA compliance. Work done now serves both current obligations and future ones.

4-step privacy readiness review
1
Audit your data collection points
Map every point where your practice collects patient data: intake forms, practice management system, email lists, and third-party software.
2
Review your consent language
Test your consent forms against a plain-language standard. Separate clinical, administrative, and marketing purposes into distinct fields.
3
Assess your software stack
Document what data flows into each tool you use, where it is stored, and whether vendors have signed data processing agreements with your practice.
4
Build a data-request workflow
Create a process for staff to respond to patient data requests within 45 days, including a log of requests received, actions taken, and completion dates.

On the technology side, the PPCDA’s PIA requirement means the due diligence applied before adopting any new platform should now include data flow documentation. When evaluating patient communication tools, PMS upgrades, or diagnostic software, ask vendors: where is data stored, which sub-processors handle it, and what is the data residency jurisdiction?

For a structured checklist of the steps required under the existing federal framework, see the PIPEDA compliance checklist for dental practices. Most items on that list align directly with the PPCDA’s proposed baseline obligations, so completing them now closes two gaps at once.

The Office of the Privacy Commissioner of Canada has published guidance on the direction of federal privacy reform. The full text of Bill C-36 and its legislative history are available through Parliament of Canada’s LegisInfo for practices that want to monitor its progress through each reading.

Frequently Asked Questions

Does the PPCDA apply to dental practices right now?

No. The PPCDA (Bill C-36) was tabled on 15 June 2026 and is currently at second reading in the House of Commons. It has not received Royal Assent and is not yet law. Dental practices are currently governed by PIPEDA at the federal level, and by provincial health information laws such as PHIPA in Ontario and Law 25 in Quebec where those apply.

When will the PPCDA become law?

No date has been confirmed. A bill at second reading must still complete committee review, third reading in both the House of Commons and the Senate, and receive Royal Assent before it takes effect. The legislative process typically takes many months. Practices should monitor progress through the Office of the Privacy Commissioner or Parliament’s LegisInfo service.

What happens to PIPEDA if the PPCDA passes?

The PPCDA would repeal PIPEDA in its entirety and replace it. Any transition period would be defined in the bill’s commencement provisions, which have not yet been finalised. Provincial health information laws such as PHIPA and Law 25 would remain in force alongside the new federal framework.

Will my existing patient consent forms still be valid under the PPCDA?

Probably not without modification. The PPCDA proposes granular, purpose-specific consent, which is more detailed than what most current dental consent forms provide. Practices that bundle clinical, administrative, and marketing consent into a single signature would need to update their forms to separate these purposes clearly before the bill receives Royal Assent.

What is a privacy impact assessment and does my practice need one?

A privacy impact assessment (PIA) is a structured review of how a new system or process collects, stores, uses, and shares personal data, along with an evaluation of associated risks. Under the PPCDA, a PIA would be required before deploying any new technology that processes patient data. Practices considering a PMS upgrade, patient communication software, or AI diagnostic tools should build PIA documentation into their vendor evaluation process now, as it aligns with due diligence already expected under PIPEDA.

How large are the fines under the PPCDA?

The bill proposes two tiers. Administrative penalties can reach up to $10 million or 3% of global annual revenue, whichever is greater, for non-compliance with core obligations. Criminal penalties for the most serious violations, such as intentional misuse of patient data, can reach up to $25 million or 5% of global annual revenue. For a mid-sized dental practice, the administrative percentage floor typically applies first, ensuring the penalty reflects clinic size rather than a flat cap.

Preparing your practice for Canada’s evolving privacy landscape?
DentRecall is built for Canadian dental practices. All patient data is stored in Canadian data centres, every automated communication includes a compliant opt-out, and consent tracking is built into the platform from the ground up. If you are reviewing your compliance posture ahead of the PPCDA, book a 15-minute demo to see how we handle data obligations on your behalf.

Keep reading

More from the DentRecall Blog