Briefing

Privacy Law Changes in 2026: What Canadian Employers Need to Know

Canada's privacy law framework shifted significantly in 2026. The CPPA has replaced PIPEDA, AIDA now governs AI in the workplace, and Quebec's Law 25 is fully enforced — leaving employers across every province with new consent, disclosure, and data management obligations.

By Kellie L. Johnston and Anna Vardar

2026 marks a turning point in Canadian privacy law. New federal and provincial privacy obligations are either now in force or actively being enforced, significantly affecting how employers collect, use, retain, and disclose employee information.

These changes reflect a national emphasis on accountability, transparency, and responsible technology use in the workplace.

Federal: The Consumer Privacy Protection Act (CPPA) and Artificial Intelligence and Data Act (AIDA)

The CPPA has replaced PIPEDA for private-sector organizations, introducing enhanced rights for employees and stricter compliance standards for employers.

Key requirements now in effect include:

  • Expanded consent obligations, with clear and specific consent required for most data collection.
  • Data mobility and deletion rights, allowing employees to access or request deletion of their personal information.
  • Mandatory privacy management programs, including documented policies, training, and risk assessments.

The AIDA now regulates the use of AI systems in the workplace, including tools used for recruitment, monitoring, scheduling, and performance evaluation. Employers using AI must ensure fairness, transparency, and explainability in automated decision-making processes.

Ontario: Modernised Privacy Framework (Proposed)

Ontario continues to explore a stand-alone provincial privacy law for the private sector, building on its 2025 consultation process. Measures now in effect or expected to be enforced throughout 2026 include:

  • Mandatory privacy breach reporting to both the regulator and affected individuals.
  • Employer obligations to minimise and anonymise employee data.
  • Potential restrictions on electronic monitoring and biometric data collection.

British Columbia and Alberta: Amendments to Private Sector Acts

Both provinces are implementing amendments to their private-sector privacy statutes, including:

  • Stronger consent and transparency requirements.
  • Expanded employee access and correction rights.
  • Mandatory breach notification and record-keeping.
  • Clarified rules for cross-border data transfers.

Quebec: Continued Enforcement of Law 25

Quebec’s Law 25 is now fully in force. Employers must:

  • Appoint a privacy officer and conduct privacy impact assessments for new systems.
  • Implement formal policies for data retention, destruction, and incident response.
  • Respect enhanced employee rights to access and portability of their personal information.

Cross-Provincial Considerations

Employers that operate in multiple jurisdictions will have increasingly different privacy obligations. We recommend harmonising privacy policies to meet the strictest standard, typically Quebec or the federal CPPA. This approach simplifies compliance and builds trust with employees.

Prepared for Privacy Compliance in 2026

Employers should now:

  • Review and update privacy policies and consent forms.
  • Conduct data mapping to identify where employee information resides.
  • Implement breach response procedures and privacy training programs.
  • Assess the use of AI or monitoring tools and document risk mitigation steps.

The Takeaway

Privacy is now a core governance obligation, not a compliance afterthought. Employers who have embedded privacy management into their operational culture are better positioned to reduce legal risk, build employee trust, and navigate Canada’s increasingly sophisticated data protection regime.