Standby thefireman.fyi · board briefing
0:00 / 0:00 Board·Advisor Manifesto Dispatches EN · FR Bill C-36
Pre-incident governance · For the board

Before the fire.

New obligations do not become an IT problem on the day they take effect. They become a board problem when nobody decided, in advance, how accountability, consent, identity, access, retention and auditability would actually work.

The question is not whether you have a policy. Can the board demonstrate that the organization was designed to follow it?
Reading~7 min AudienceBoards · General counsel · CIOs FiledGovernance
Listen · Board briefing Read by the board and its advisor Two voices · ambient bed · headphones recommended
Status of the file

Bill C-36 has not passed. That is the entire opportunity.

Bill C-36 · Protecting Privacy and Consumer Data Act 45th Parliament, 1st session
Introduced
15 June 2026, first reading in the House of Commons. Would enact the Protecting Privacy and Consumer Data Act and replace Part 1 of PIPEDA, Canada's private-sector privacy law of the last twenty-five years.
Where it sits
Still at first reading. The House resumes 21 September 2026, with second reading and committee study expected in the fall sitting. Amendments are likely.
When it binds
There is no fixed in-force date. Commencement is left to order in council, so the transition period is a decision the Governor in Council has not yet made.
Prior attempts
The third federal attempt in six years. Bill C-11 (2020) and Bill C-27 (2022) both died on the Order Paper. Read honestly, that cuts both ways: this bill may not pass either, and the direction of travel has now been consistent across three governments and three drafts.
Why it matters now
The obligations below are not yet law and should not be treated as exposure. They are the best available description of what the board will be asked to demonstrate, at the cheapest moment to design for it.
The governance window

The legislation arrives.
The architecture should already exist.

Legislative
requirements
Board
decisions← you are here
Policy +
ownership
Technical
controls
Auditable
evidence
Fire prevention

Govern before the incident.

Before

Map data, authority, vendors, consent, identity, retention and access. Name the owner. Define exceptions before somebody needs one.

During

Make technical controls enforce the decision. Exceptional access and de-anonymization require authority, purpose and a traceable record.

After

Reconstruct what happened without archaeology: which rule applied, who had authority, what the system did and what evidence proves it.

Board-to-system translation

Governance has to compile.

Twelve words a board can say out loud. Each one resolves to a clause somebody has to build, staff and evidence.

Accountabilitys. 8, s. 9
Consents. 18
Identitys. 2(1)
Accesss. 63
Anonymizations. 2(1)
De-anonymizations. 75
Retentions. 52
Auditabilitys. 9
Vendor authoritys. 11(2)
Exception pathss. 18, s. 75
Decision ownerships. 8(1)
Incident evidences. 114, s. 132
What the Act actually requires

Seven clusters, as introduced.

Section references are to Bill C-36 as tabled on 15 June 2026 and may change in committee. Each cluster pairs the statutory duty with the operational capability that produces the evidence.

01

Accountability

  • s. 8(1)An organization must designate one or more individuals responsible for matters related to its obligations under the Act.
  • s. 9(1)A documented programme of policies, practices and procedures, scaled to the volume and sensitivity of the information held, producible to the Commission on request.
Operational counterpartA named role with standing authority and the budget to use it, and a programme maintained as a living record. A binder assembled after the request has already failed the test.Practices Workforce and Talent Management · Governance (Service Value System)
02

Consent and its exceptions

  • s. 18(2)Collection and use without consent for defined business activities, including providing a product or service the individual requested and information security purposes.
  • s. 18(3)Use where the organization has a legitimate interest that outweighs any reasonably foreseeable adverse effect on the individual.
Operational counterpartThe balancing test is a risk assessment with an author, a date and a file. An exception that lives only in somebody's recollection cannot be produced two years later.Practices Risk Management · Business Analysis
03

De-identification and anonymization

  • s. 2(1)To de-identify is to modify personal information so that an individual cannot be directly identified from it, "although a risk of the individual being identified remains."
  • s. 2(1)To anonymize is to "irreversibly and permanently" modify it so that there is no reasonably foreseeable risk of identification.
  • s. 75An organization must not use de-identified information to identify an individual, subject to narrow exceptions including testing the effectiveness of its own safeguards.
Operational counterpartThe two words are not synonyms and the distinction is load-bearing. Most organizations say "anonymized" and hold de-identified data. Re-identification needs an authority, a stated purpose and a record written at the time, not afterwards.Practices Change Enablement · Service Validation and Testing · Information Security Management
04

Retention and disposal

  • s. 52(1)Information must not be retained longer than necessary to fulfil the purposes for which it was collected.
  • s. 54Disposal on an individual's written request, subject to enumerated exceptions.
Operational counterpartRetention is an asset and configuration question before it is a legal one: you cannot delete on request what no inventory records you hold. Disposal on request is an intake path with a queue, an owner and a measurable time to completion.Practices IT Asset Management · Service Configuration Management · Service Request Management
05

Vendors and borders

  • s. 11(2)A service provider becomes subject to obligations where it uses or discloses transferred information for purposes other than those for which it was transferred.
  • s. 57(1)A privacy impact assessment, and measures to mitigate the risks identified, before disclosing or transferring personal information outside Canada.
Operational counterpartSupplier management with contract terms that match the assessment actually performed. In practice most transfers outside Canada are made by a vendor's default region setting, which is to say by nobody.Practices Supplier Management · Risk Management · Architecture Management
06

Automated decisions

  • s. 63(4)-(5)On request, an explanation of a prediction, recommendation or decision made by an automated system, including the type of personal information used, its source, and the reasons.
Operational counterpartExplainability is a build requirement, not a reporting one. It cannot be retrofitted onto a system that never logged why. This is the single obligation on this page most likely to require code that does not exist yet.Practices Software Development and Management · Service Configuration Management
07

Enforcement and evidence

  • s. 85(1)Oversight moves to the Digital Safety and Data Protection Commission of Canada, led by a Privacy and Consumer Data Commissioner.
  • s. 114Administrative monetary penalties. As introduced, up to the greater of $10 million or 3% of gross global revenue.
  • s. 145Offences. As introduced, up to the greater of $25 million or 5% of gross global revenue.
  • s. 132A private right of action for damages following an established contravention.
Operational counterpartMeasurement and reporting, on a cadence the board actually sees. The exposure that matters is rarely the incident itself. It is the inability to show what was decided, by whom, on what authority, and when.Practices Measurement and Reporting · Continual Improvement
The distinction · ITIL

Restoring service is not the same as removing the cause.

ITIL draws this line on purpose. Incident Management is measured on one thing: restoration of normal service operation, as fast as possible. Problem Management is measured on something else entirely: reducing the likelihood and impact of incidents by identifying and removing their causes. Different people, different clocks, different definitions of success.

Almost every organization funds the first and improvises the second. That is affordable while the only cost of a recurring failure is the cost of fixing it again. It stops being affordable when a statute attaches a penalty and a private right of action to the recurrence, and asks the board to produce the record of what it decided beforehand.

Do not hire us to fight the fire. Hire us to determine why the building can catch fire, who owns the extinguisher, and whether it works before anyone needs it.
Corporate board briefing

Use the implementation window.

What the engagement produces

Obligations → decisions → ownership → technical controls → evidence.

A board-level pre-incident governance review against Bill C-36 as it stands, plus the obligations that survived unchanged across C-11 and C-27 and are therefore the safest to build against now. The objective is not another binder. It is an organization capable of demonstrating that foreseeable governance risks were identified, assigned, engineered and monitored before they became incidents.

Request a briefing
board@firemen.fyi