Bill C-36 Is Coming.

Is Your Privacy Notice Ready?

For many organizations, privacy notices have become a “set it and forget it” document.

At some point, a privacy notice was drafted, uploaded to the website, and checked off the compliance list. Since then, the business has evolved. New vendors have been onboarded, new technologies introduced, new marketing activities launched, and perhaps even AI tools adopted. Yet the privacy notice often remains unchanged.

Does this sound like your organization?

With the introduction of Bill C-36, the Protecting Privacy and Consumer Data Act (PPCDA) that approach may no longer be enough.

A New Era of Privacy Accountability

Bill C-36, the proposed PPCDA, signals a shift toward greater accountability and transparency for Canadian organizations.
Rather than simply expecting organizations to have privacy documentation, the legislation raises expectations around maintaining a demonstrable privacy program. In other words, organizations need to show that privacy management is embedded in their operations and that their privacy practices match what they tell individuals.
One of the most visible parts of that privacy program is the privacy notice. And that’s where many organizations have work to do. 

Having a Privacy Notice Isn't the Same as Having a Good One

Research from the Office of the Privacy Commissioner of Canada suggests that most Canadian businesses have a privacy notice 2025-2026 Survey of Canadian businesses on privacy-related issues – Office of the Privacy Commissioner of Canada.

That is encouraging, but the challenge is that many privacy notices don’t accurately describe how personal information is collected, used, shared, retained, and protected across the organization.

In our experience, privacy notices often focus almost entirely on websites, cookies, and online tracking technologies. But they are only one piece of the privacy picture.  What about:

  • Customer information collected through business operations?
  • Employee information?
  • Job applicant data?
  • Information shared with service providers?
  • Retention practices?
  • Data destruction processes?
  • Cross-border data transfers?

If those activities aren’t reflected in your privacy notice, you aren’t being transparent, nor are you compliant with the law.

The Cookie Problem

Another issue we encounter is incomplete disclosure around cookies and tracking technologies.  Many privacy notices state that cookies are used but the notice stops there.  What they don’t explain is:

  • Whether information collected through cookies is shared with third parties
  • Whether website visitors are tracked across other websites
  • Whether advertising technologies are being used
  • Whether information contributes to customer profiling or targeted marketing

Simply mentioning cookies is not enough.  People want to know what information is being collected, how it is being used, and who has access to it. If that information isn’t explained, the privacy notice may create a misleading impression, even if unintentionally.

Why Transparency Matters More Than Ever

As privacy requirements continue to evolve, organizations should think of privacy notices as more than a compliance document.  Customers, employees, and business partners increasingly want to understand how organizations handle personal information. When information is presented clearly, it demonstrates accountability and respect for privacy.

On the other hand, a generic privacy notice that is a cut and paste or is generated from a template often creates risk.  The problem isn’t that the language sounds wrong, the problem is that the notice may not reflect reality.  A privacy notice should describe your organization’s actual practices, not someone else’s.

What Should a Privacy Notice Include?

A privacy notice should tell the complete story of how personal information moves through your organization.  At a minimum, organizations should consider whether their privacy notice clearly explains:

Information Collected

People should know what personal information is collected, how it is collected and who it is collected from. The goal is to eliminate surprises.

Why Information Is Collected

People should never have to guess why their information is being collected.

Be specific about the purposes for collection. Avoid vague statements such as “for business purposes” and instead explain how information supports your operations and services.

Who Information Is Shared With

Most organizations rely on third parties to deliver products and services.

Your privacy notice should explain:

  • What information may be shared
  • Why it is shared
  • The types of organizations receiving it

Transparency around sharing is an effective way to build trust.

Digital Tracking and Profiling Activities

If your organization uses:

  • Cookies
  • Analytics tools
  • Advertising technologies
  • Tracking pixels
  • Device identifiers

Your privacy notice should explain how they are used.

Organizations should also disclose whether personal information is used for activities such as profiling, personalization, customer segmentation, behavioural advertising, or automated decision-making.

Retention and Destruction Practices

One of the most common questions individuals ask is:

“How long do you keep my information?”

Your privacy notice should explain:

  • Retention periods where possible
  • How retention decisions are made
  • Legal or business requirements that influence retention
  • How information is securely destroyed when it is no longer needed

Security Safeguards

While organizations shouldn’t disclose sensitive security details, individuals should know that reasonable safeguards are in place to protect their information.

Cross-Border Transfers

Many organizations use cloud providers and other vendors that process data outside of Canada.

Privacy notices should explain:

  • Whether information may be transferred outside the province or country
  • Purpose for the transfer
  • What safeguards are used to protect the information

Privacy Rights and Contact Information

Finally, individuals should know:

  • Their privacy rights
  • How to exercise their rights
  • Who to contact with questions or concerns

An effective privacy notice makes it easy for people to reach the organization when they need assistance.

Identify the Privacy Laws That Apply to Your Organization

A privacy notice should also explain the privacy laws and regulatory requirements that govern the organization’s handling of personal information.

Many organizations operate across multiple provinces, territories, or countries and may be subject to more than one privacy law. Helping individuals understand the legal framework that applies to the organization sets expectations regarding privacy rights and obligations.

Depending on the organization’s operations, this may include:

  • Federal private-sector privacy legislation
  • Provincial private-sector privacy legislation
  • Health privacy legislation
  • Public-sector privacy legislation
  • International requirements such as the General Data Protection Regulation (GDPR) or other foreign privacy laws

Don't Let Your Privacy Notice Become a Compliance Gap

A privacy notice should evolve as your business evolves.  If it hasn’t been reviewed in several years, there is a good chance it no longer reflects your current practices. New technologies, vendors, marketing activities, and regulatory expectations can all create gaps between what’s written in the notice and what’s happening inside the organization.

As Bill C-36 pushes organizations toward stronger privacy governance, now is the time to review your privacy notice.

How Garabyte Can Help

At Garabyte, we help organizations develop privacy notices that accurately reflect their business practices and support broader privacy program objectives.

Whether you are building a privacy program from the ground up, reviewing existing documentation, or preparing for evolving regulatory requirements, we’ll help ensure your privacy notice tells the complete story of how personal information is handled within your organization.

Garabyte can help you build a privacy program that drives growth, not hesitation.