Privacy commissioners don't just enforce regulations; they shape them. When the Office of the Privacy Commissioner of Canada issued its preliminary reaction to Bill C-30, it opened a formal consultation window that many organizations overlook. If you're managing privacy compliance for a Canadian operation, you need a structured way to submit your concerns before the legislative window closes.
This template provides a framework to document your organization's position on proposed privacy legislation and submit it to the relevant supervisory authority. Use it for Bill C-30 responses, provincial privacy law consultations, or any legislative comment period where your compliance obligations are at stake.
Purpose of This Template
This stakeholder submission template structures your organization's formal response to proposed privacy legislation. It ensures you:
- Document specific compliance impacts on your current data processing activities
- Identify provisions that create operational conflicts with existing obligations
- Propose concrete amendments with regulatory precedent
- Create an audit trail showing you participated in the legislative process
The template follows the consultation format used by the Office of the Privacy Commissioner of Canada and most provincial supervisory authorities. You can adapt it for submissions to Innovation, Science and Economic Development Canada (ISED), provincial legislators, or sectoral regulators.
Prerequisites
Before you complete this template, gather:
- The full text of the proposed bill or regulation
- Your current data processing inventory (systems, purposes, legal bases)
- Your existing privacy policies and consent mechanisms
- Any regulatory guidance already issued by the supervisory authority
- Relevant case law or enforcement decisions that support your position
You'll need sign-off from your legal counsel and Chief Privacy Officer. If the legislation affects cross-border transfers, involve your data protection officer in other jurisdictions to check for conflicts with GDPR, UK General Data Protection Regulation, or other frameworks.
The Template
STAKEHOLDER SUBMISSION
Re: [Bill Number and Short Title]
Submitted by: [Organization Legal Name]
Date: [Submission Date]
Contact: [Name, Title, Email]
SECTION 1: ORGANIZATIONAL CONTEXT
1.1 Scope of Operations
We are a [industry sector] organization operating in [provinces/territories]. We process personal information for [primary purposes: employment, customer service, product delivery, etc.].
1.2 Current Compliance Framework
Our privacy program currently complies with:
- Personal Information Protection and Electronic Documents Act (PIPEDA)
- [Provincial legislation, if applicable]
- [Sectoral regulations: PHIPA, PIPA-AB, PIPA-BC, etc.]
- [International frameworks: GDPR, UK General Data Protection Regulation, CPRA]
1.3 Data Processing Volume
We maintain records for approximately [number] individuals and process [number] data subject access requests annually under PIPEDA Section 8.
SECTION 2: SPECIFIC PROVISIONS OF CONCERN
For each provision that creates compliance risk, use this structure:
2.1 [Provision Reference: e.g., "Clause 15: Consent Requirements"]
Current Legislative Text:
[Quote the exact language from the bill]
Impact on Our Operations:
[Describe the specific conflict with your current processing activities. Be precise: "This provision would require [Informed Consent](/glossary/informed-consent) for employment verification checks, but PIPEDA Section 7(1)(b) permits processing necessary for contract performance without consent."]
Regulatory Precedent:
[Cite relevant guidance: "The OPC's 2019 guidance on consent exceptions clarifies that..." or "Article 6(1)(b) GDPR permits similar processing without consent when..."]
Proposed Amendment:
[Suggest specific legislative language: "Add an exception: 'This section does not apply to processing reasonably necessary to fulfill an existing employment contract or [legal obligation](/glossary/legal-obligation).'"]
SECTION 3: CROSS-FRAMEWORK CONFLICTS
3.1 Conflicts with PIPEDA
[Identify where the new bill contradicts existing federal obligations]
3.2 Conflicts with Provincial Legislation
[Document inconsistencies with Alberta PIPA, BC PIPA, Quebec Law 25, etc.]
3.3 Conflicts with International Frameworks
[Flag provisions that would make GDPR adequacy decisions or UK General Data Protection Regulation transfer mechanisms unworkable]
SECTION 4: IMPLEMENTATION CONCERNS
4.1 Compliance Timeline
[If the bill includes a transition period, explain why it's insufficient: "The 12-month implementation window does not account for the 18-24 month procurement cycle required to replace our current consent management platform."]
4.2 Technical Feasibility
[Identify provisions that require capabilities your sector doesn't have: "Clause 22's requirement for algorithmic transparency presumes access to source code, which our organization does not receive from SaaS vendors."]
4.3 Cost Impact
[Quantify where possible, but don't invent numbers. Instead: "Implementing the proposed breach notification timeline would require 24/7 security operations coverage, which our current staffing model does not support."]
SECTION 5: RECOMMENDED MODIFICATIONS
Priority 1: [Most Critical Change]
Provision: [Clause number]
Recommendation: [Specific amendment]
Rationale: [Why this change is necessary for workable compliance]
Priority 2: [Second Most Critical Change]
[Repeat structure]
Priority 3: [Third Most Critical Change]
[Repeat structure]
SECTION 6: SUPPORTING DOCUMENTATION
Attached:
- Current privacy policy
- Data processing inventory (redacted for confidentiality)
- Consent form templates
- [Any internal impact assessments you've completed]
SECTION 7: REQUEST FOR FOLLOW-UP
We request the opportunity to:
- Provide oral testimony during committee hearings
- Submit supplementary technical documentation
- Participate in stakeholder working groups
Contact for follow-up: [Name, direct email, direct phone]
Respectfully submitted,
[Name]
[Title]
[Organization]
[Date]
How to Customize It
For Bill C-30 specifically: The Office of the Privacy Commissioner of Canada's preliminary reaction signals areas where the OPC sees gaps or concerns. Read their submission first, then identify where your operational experience adds evidence to their position or raises issues they didn't cover.
Tone and specificity: Supervisory authorities want concrete examples, not abstract concerns. Replace "this could be problematic" with "our current customer onboarding process collects email addresses under implied consent for service delivery; Clause 18's Informed Consent requirement would break this flow and create a 40% drop-off based on A/B testing we conducted in Quebec under Law 25."
Cross-border operations: If you transfer data outside Canada, explain exactly how the bill affects your Standard Contractual Clauses, Binding Corporate Rules, or adequacy decisions. The European Data Protection Board watches Canadian legislative developments for essential equivalence assessments.
Sectoral context: Healthcare organizations should reference Personal Health Information Protection Act (PHIPA) in Ontario or equivalent provincial health privacy laws. Financial institutions should cite federal sectoral rules that may conflict with general privacy legislation.
Validation Steps
Before you submit:
Legal review: Have counsel confirm that your proposed amendments don't create new liability exposure or contradict your current public privacy commitments.
Fact-check your claims: Every "this provision would require us to..." statement should map to a specific clause number and your documented current practice. Don't speculate about impacts you can't demonstrate.
Check the consultation deadline: Most legislative comment periods close 30-60 days after the bill's introduction. The Office of the Privacy Commissioner of Canada typically posts submission deadlines on their consultation page.
Coordinate with industry groups: If you're in a regulated sector (finance, health, telecommunications), check whether your industry association is submitting a collective response. Your individual submission should complement, not duplicate, the industry position.
Preserve your submission: Keep a timestamped copy. If the bill passes with provisions you flagged, your submission becomes evidence that you raised concerns during the legislative process, which matters for demonstrating good-faith compliance efforts.
The Office of the Privacy Commissioner of Canada's preliminary reaction to Bill C-30 is your signal to act. Supervisory authorities notice which organizations engage during consultation and which wait until enforcement. This template turns that engagement into a compliance asset.



