facebook-pixel

Bill C-27 Digital Charter: What You Need to Know in 2026

L
Lunyb Security Team
··9 min read

Canada's privacy landscape is on the cusp of its biggest transformation in more than two decades. Bill C-27, formally known as the Digital Charter Implementation Act, is set to modernize how Canadian organizations collect, use, and disclose personal information — and to introduce the country's first federal law regulating artificial intelligence. If you run a business, build software, or simply want to understand your rights as a consumer, this guide breaks down everything you need to know.

What Is Bill C-27?

Bill C-27, the Digital Charter Implementation Act, 2022, is proposed Canadian federal legislation that would overhaul private-sector privacy law and introduce new rules for artificial intelligence systems. It replaces the aging Personal Information Protection and Electronic Documents Act (PIPEDA) with a more modern, GDPR-aligned framework.

The bill actually bundles three separate laws into one legislative package:

  1. The Consumer Privacy Protection Act (CPPA) — the new private-sector privacy law replacing Part 1 of PIPEDA.
  2. The Personal Information and Data Protection Tribunal Act — creating a new tribunal to review privacy decisions and impose penalties.
  3. The Artificial Intelligence and Data Act (AIDA) — Canada's first federal law regulating high-impact AI systems.

Together, these three acts represent the operational backbone of Canada's Digital Charter — a broader set of ten principles introduced in 2019 aimed at building trust in the digital economy.

Why Bill C-27 Matters

PIPEDA was enacted in 2000, long before smartphones, social media, generative AI, or large-scale data brokers. Regulators have struggled to enforce it, fines have been minimal, and Canadian consumers have watched other jurisdictions — the EU with GDPR, California with CCPA/CPRA, Brazil with LGPD — pass far stronger frameworks.

Bill C-27 addresses this gap in three important ways:

  • Real financial penalties. Maximum fines can reach the greater of $25 million CAD or 5% of global gross revenue — putting Canada in line with GDPR-level enforcement.
  • Expanded consumer rights. Canadians gain new rights to data mobility, algorithmic transparency, and deletion (the "right to disposal").
  • AI accountability. AIDA sets out obligations for anyone designing, developing, or deploying "high-impact" AI systems in Canada.

The Consumer Privacy Protection Act (CPPA) Explained

The CPPA is the heart of Bill C-27. It governs how private-sector organizations handle personal information in the course of commercial activity. Here are the key elements every Canadian business should understand.

1. Consent Requirements Get Sharper

Consent must be obtained in plain language, at or before the point of collection, and must clearly explain:

  • The purposes of collection, use, or disclosure
  • How the information will be used
  • The reasonably foreseeable consequences
  • Any third parties who will receive the data

Buried privacy policies and pre-checked boxes will no longer meet the standard.

2. New Exceptions for "Legitimate Interest"

The CPPA introduces a legitimate interest exception, similar to GDPR's Article 6(1)(f). Businesses can process data without express consent when the benefit outweighs privacy impacts, provided a documented assessment is completed.

3. Right to Disposal

Canadians can request that organizations delete their personal information. There are exceptions (legal obligations, ongoing contracts, freedom of expression), but the default posture flips: personal data should be deletable on request.

4. Data Mobility

Once data mobility frameworks are established between designated organizations (starting with banking and telecom), consumers can request that their data be transferred directly from one provider to another.

5. Algorithmic Transparency

If an organization uses an automated decision system to make a prediction, recommendation, or decision that could significantly impact an individual, that individual can request an explanation of how the decision was made and what factors were used.

6. Special Protections for Minors

Information of minors is deemed "sensitive by default," triggering higher protection standards, restrictions on targeted advertising, and easier deletion rights.

The Artificial Intelligence and Data Act (AIDA)

AIDA is Canada's first federal statute targeting AI. It applies to organizations that design, develop, make available, or manage the operation of AI systems in the course of international or interprovincial trade and commerce.

What Counts as a "High-Impact" AI System?

The bill originally left the definition to regulation, but proposed amendments identify categories such as:

  • Employment screening and hiring tools
  • Systems used in provision of essential services (credit, insurance)
  • Biometric identification and behaviour classification
  • Content moderation and prioritization on large platforms
  • Healthcare diagnostic tools
  • Systems used by law enforcement or courts

Obligations Under AIDA

  1. Risk assessment — Assess whether the system is "high-impact" and document reasoning.
  2. Mitigation measures — Implement measures to identify and reduce risks of harm and biased output.
  3. Monitoring — Continuously monitor compliance and effectiveness of mitigation.
  4. Transparency — Publish plain-language descriptions of the system on public websites.
  5. Record-keeping — Maintain records of assessments and mitigation strategies.
  6. Incident reporting — Report serious harms to the Minister of Innovation, Science and Industry.

Penalties and Enforcement

One of the most consequential shifts in Bill C-27 is the introduction of meaningful penalties. Below is a comparison of maximum administrative and criminal fines across major privacy regimes.

Regime Maximum Administrative Penalty Maximum Criminal/Serious Fine
PIPEDA (current) None (only $100K per offence) $100,000 CAD
Bill C-27 (CPPA) Greater of $10M or 3% global revenue Greater of $25M or 5% global revenue
GDPR (EU) €10M or 2% global revenue €20M or 4% global revenue
CPRA (California) $2,500 per violation ($7,500 intentional) Civil actions available
AIDA (Bill C-27) Up to $10M or 3% global revenue Up to $25M or 5% global revenue

The bill also creates a new Personal Information and Data Protection Tribunal to hear appeals of the Privacy Commissioner's findings and impose administrative monetary penalties — giving enforcement teeth that PIPEDA never had.

How Bill C-27 Compares to GDPR

Bill C-27 is often described as "GDPR-lite" or "GDPR-aligned." Both aim for similar outcomes, but there are important differences.

Feature Bill C-27 (CPPA) GDPR
Lawful basis Consent-based with legitimate interest exception Six lawful bases including consent
Right to erasure Yes (right to disposal) Yes (right to be forgotten)
Data portability Limited to designated sectors Broad right
DPO required Privacy officer required DPO for certain organizations
Breach notification Real risk of significant harm Within 72 hours if risk to rights
Max fine 5% global revenue or $25M CAD 4% global revenue or €20M

Who Does Bill C-27 Apply To?

The CPPA applies to any private-sector organization that collects, uses, or discloses personal information in the course of commercial activity in Canada, or across provincial or national borders. This includes:

  • Canadian businesses of all sizes
  • Foreign companies offering goods or services to Canadians
  • SaaS providers with Canadian users
  • Charities and non-profits engaged in commercial activity

AIDA applies more narrowly — to organizations involved in international or interprovincial AI-related trade and commerce. Provincial AI regulations may fill remaining gaps.

How to Prepare Your Business for Bill C-27

Whether or not Bill C-27 passes in its current form, the direction of Canadian privacy law is clear. Here is a practical readiness checklist.

  1. Map your data. Document what personal information you collect, why, where it lives, and who accesses it.
  2. Update consent flows. Rewrite privacy notices in plain language and remove pre-ticked boxes.
  3. Appoint a privacy officer. Assign clear accountability, even in small organizations.
  4. Build a disposal workflow. Create a documented process for handling deletion requests within a reasonable timeframe.
  5. Implement privacy management programs. The CPPA requires organizations to have a formal program covering policies, practices, and training.
  6. Assess automated decision systems. Inventory any AI or algorithmic systems that make decisions about individuals.
  7. Review vendor contracts. Ensure processors have appropriate safeguards and breach-notification obligations.
  8. Harden security. Encrypt data at rest and in transit, enforce MFA, and adopt privacy-respecting infrastructure. If you share links containing user identifiers, consider tools like Lunyb to shorten and control link exposure without leaking parameters.
  9. Prepare breach response. Document your "real risk of significant harm" assessment methodology in advance.
  10. Train staff. The best policy fails without informed employees.

What About Provincial Laws?

Canada's privacy landscape is layered. Quebec's Law 25 is already in force and, in many respects, stricter than Bill C-27. Alberta and British Columbia have their own private-sector privacy laws (PIPA). If your organization operates across provinces, you'll need to comply with the strictest applicable regime — usually Quebec.

Bill C-27 has been drafted to be "substantially similar" to these provincial regimes so overlapping compliance obligations remain manageable.

Current Status of Bill C-27

Bill C-27 was first introduced in June 2022. It progressed through committee study at the House of Commons Standing Committee on Industry and Technology through 2023 and 2024, attracting extensive amendments — particularly around AIDA. As of the latest parliamentary session, the bill's progress has been complicated by prorogation and political turnover, meaning it may need to be reintroduced. Regardless of timing, the substantive framework is highly likely to survive in the next iteration.

Practical Impact on Everyday Canadians

For individual Canadians, Bill C-27 promises tangible changes:

  • Clearer privacy notices you can actually understand
  • Easier ways to delete accounts and data
  • The right to ask how AI decisions about you were made
  • Real consequences when companies mishandle your information
  • Stronger safeguards for children's data online

For businesses, it means privacy can no longer be treated as a checkbox exercise. Building trust through transparent data practices is becoming a competitive advantage — and, soon, a legal necessity.

Related Reading

Frequently Asked Questions

When will Bill C-27 come into force?

There is no firm date. Even after Royal Assent, the CPPA and AIDA include transition periods — likely one to two years — before enforcement begins, giving organizations time to update systems, policies, and contracts.

Does Bill C-27 apply to small businesses?

Yes. The CPPA applies to any organization engaged in commercial activity, regardless of size. However, obligations are scaled to the sensitivity and volume of personal information handled. A small e-commerce shop faces different practical burdens than a national bank.

How does Bill C-27 differ from Quebec's Law 25?

Quebec's Law 25 is already in force and includes stricter rules on consent, data localization disclosures, and privacy impact assessments. Bill C-27 aligns with many of Quebec's requirements but is somewhat more flexible, especially around legitimate interest processing and consent alternatives.

Will Bill C-27 affect how I use AI tools like ChatGPT in my business?

Using general-purpose AI tools is not directly regulated, but deploying AI systems that make significant decisions about individuals — hiring, credit, healthcare, content moderation — would fall under AIDA. You'd need documented risk assessments, mitigation measures, and transparency notices.

What happens if my company violates the CPPA?

Depending on severity, consequences range from compliance orders and public findings to administrative monetary penalties (up to 3% of global revenue) and, for serious offences, fines up to 5% of global revenue or $25 million CAD — whichever is greater. Individuals may also gain a private right of action.

Final Thoughts

Bill C-27 represents a generational shift in Canadian data protection. Whether it passes in its current form or a successor bill, the underlying direction is unmistakable: stronger consumer rights, meaningful penalties, and formal AI accountability. Organizations that treat privacy as a strategic priority — not a compliance afterthought — will be far better positioned when the new rules land. Start mapping your data, tightening your consent flows, and documenting your AI systems now. Your future self, and your customers, will thank you.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles