facebook-pixel

Bill C-27 Digital Charter: What You Need to Know in 2026

L
Lunyb Security Team
··10 min read

Canada's privacy landscape is undergoing its most significant transformation in more than two decades. Bill C-27, the Digital Charter Implementation Act, is set to replace parts of the aging Personal Information Protection and Electronic Documents Act (PIPEDA) and introduce Canada's first federal law governing artificial intelligence. Whether you run a small e-commerce shop in Toronto, manage a SaaS platform in Vancouver, or simply care about how your personal data is handled, understanding this legislation is essential.

In this guide, we break down what Bill C-27 actually contains, who it affects, the penalties for non-compliance, and the practical steps Canadian organisations should take now.

What Is Bill C-27?

Bill C-27, formally known as the Digital Charter Implementation Act, 2022, is Canadian federal legislation introduced to modernise the country's private-sector privacy framework and regulate artificial intelligence systems. It bundles three separate but related statutes into one bill.

The three components are:

  1. The Consumer Privacy Protection Act (CPPA) — replaces Part 1 of PIPEDA and governs how private-sector organisations collect, use, and disclose personal information.
  2. The Personal Information and Data Protection Tribunal Act (PIDPTA) — creates a new administrative tribunal to review decisions from the Office of the Privacy Commissioner and impose penalties.
  3. The Artificial Intelligence and Data Act (AIDA) — Canada's first federal AI law, focused on "high-impact" AI systems.

Together, these three acts represent a major shift toward a rights-based, enforcement-heavy privacy regime that more closely resembles the European Union's General Data Protection Regulation (GDPR).

Why Canada Needs New Privacy Legislation

PIPEDA was enacted in 2000, long before smartphones, cloud computing, targeted advertising, or generative AI existed at scale. Regulators, businesses, and civil society groups have long agreed that its principles-based, ombudsperson-style enforcement model is no longer sufficient.

Key drivers behind Bill C-27 include:

  • The need to maintain "adequacy" status with the EU under GDPR so that data can continue flowing between Canada and Europe.
  • Rising public concern about data breaches, surveillance advertising, and algorithmic decision-making.
  • Provincial pressure — Quebec's Law 25 already imposes GDPR-like obligations, creating a patchwork of standards.
  • The absence of any dedicated framework for AI accountability.

The Consumer Privacy Protection Act (CPPA) Explained

The CPPA is the centrepiece of Bill C-27. It preserves the ten fair information principles from PIPEDA but adds sharper teeth and clearer rights for individuals.

New and Strengthened Individual Rights

  • Right to disposal (deletion): Individuals can request that organisations delete their personal information, subject to limited exceptions.
  • Right to data mobility: Where a data-mobility framework exists between designated organisations, individuals can request their data be transferred.
  • Right to explanation: When an automated decision system makes a prediction, recommendation, or decision that could significantly impact an individual, they can request a plain-language explanation.
  • Enhanced consent standards: Consent must be obtained in plain language at or before the point of collection, with specified information about purposes and third parties.
  • Special protections for minors: The personal information of minors is deemed to be "sensitive" by default, triggering stricter handling requirements.

New Obligations for Organisations

Organisations subject to the CPPA will need to:

  1. Implement and maintain a documented privacy management programme proportionate to the volume and sensitivity of data handled.
  2. Make the programme available to the Privacy Commissioner on request.
  3. Conduct and document impact assessments for activities involving sensitive information or automated decision systems.
  4. Report breaches of security safeguards that pose a "real risk of significant harm" to affected individuals and the Commissioner.
  5. Publish clear, accessible information about their data practices, retention periods, and complaint mechanisms.

The Artificial Intelligence and Data Act (AIDA)

AIDA is the most novel — and most debated — part of Bill C-27. It focuses regulatory attention on "high-impact" AI systems, a category to be defined more precisely in regulations but expected to include systems used in employment, healthcare, credit decisions, law enforcement, and content moderation at scale.

Core AIDA Obligations

  • Assess whether an AI system qualifies as high-impact.
  • Establish measures to identify, assess, and mitigate risks of harm or biased output.
  • Monitor compliance with those mitigation measures on an ongoing basis.
  • Maintain records describing the system, training data, and risk assessments.
  • Publish a plain-language description of high-impact systems made available to the public.
  • Notify the Minister of material harms caused by a system.

AIDA also creates new offences for making AI systems available with the intent to defraud the public or cause serious harm, and for unlawful use of personal information in training datasets.

Penalties: A Serious Enforcement Regime

One of the most striking changes under Bill C-27 is the arrival of GDPR-scale financial penalties. This alone is why Canadian executives are paying close attention.

Violation TypeMaximum Administrative PenaltyMaximum Criminal / Offence Fine
CPPA contraventions (AMPs)Greater of $10 million or 3% of global revenue
Serious CPPA offencesGreater of $25 million or 5% of global revenue
AIDA regulatory contraventionsUp to $10 million or 3% of global revenue
AIDA criminal offencesUp to $25 million or 5% of global revenue

These figures apply to global gross revenue, not just Canadian revenue — an important detail for multinational companies.

Who Does Bill C-27 Apply To?

The CPPA applies to private-sector organisations that collect, use, or disclose personal information in the course of commercial activities, including federally regulated employers with respect to employee data. AIDA applies to persons responsible for designing, developing, making available, or managing the operation of AI systems in the course of international or interprovincial trade and commerce.

Provincial private-sector laws in Quebec, Alberta, and British Columbia may continue to apply where they are deemed "substantially similar," but the federal framework sets the floor for cross-border and interprovincial activity.

Bill C-27 vs. PIPEDA vs. GDPR

To help contextualise the changes, here is a high-level comparison of the three frameworks.

FeaturePIPEDA (current)Bill C-27 (CPPA)GDPR (EU)
Right to deletionLimitedYes ("right to disposal")Yes ("right to erasure")
Data portabilityNoYes, within frameworksYes
Automated decision explanationsNoYesYes
Maximum fines$100,000Up to 5% of global revenueUp to 4% of global revenue
Dedicated AI lawNoYes (AIDA)Separate EU AI Act
Enforcement modelOmbudspersonOrder-making + TribunalSupervisory authorities

Pros and Cons of Bill C-27

Pros

  • Meaningful enforcement finally aligns Canada with global standards.
  • Clearer individual rights, especially for minors and around automated decisions.
  • Helps preserve EU adequacy status, protecting Canadian exporters.
  • First federal AI framework establishes baseline accountability.
  • Reduces regulatory fragmentation across provinces over time.

Cons

  • Small and medium businesses face significant compliance costs.
  • AIDA has been criticised for being drafted without adequate public consultation.
  • Key definitions (e.g., "high-impact" AI) are left to regulations, creating uncertainty.
  • The new Tribunal adds a procedural layer that may slow enforcement.
  • Some critics argue consent exceptions for "legitimate interests" are too broad.

How Canadian Businesses Should Prepare

Even if final regulations are still being negotiated, organisations should not wait. The direction of travel is clear, and building compliance foundations now is far cheaper than retrofitting later. Here is a practical roadmap.

  1. Map your data. Document what personal information you collect, why, where it is stored, who accesses it, and how long you retain it.
  2. Update privacy notices. Rewrite policies in plain language, disclose automated decision-making, and specify retention periods.
  3. Refresh consent flows. Ensure consent is granular, informed, and easy to withdraw. Pay special attention to minors' data.
  4. Establish a privacy management programme. Assign accountability to a named individual, document policies, and train staff.
  5. Inventory AI systems. Identify any system that could be considered high-impact and begin risk assessments.
  6. Review vendor contracts. Ensure processors and cloud providers meet CPPA-level safeguards, particularly for cross-border transfers.
  7. Test breach response. Run tabletop exercises so your team can meet the "real risk of significant harm" notification threshold within reasonable timeframes.
  8. Minimise data at the source. The less personal data you collect, the less risk you carry.

Everyday Privacy: What Canadians Can Do Now

While Bill C-27 shifts obligations onto organisations, individuals also benefit from adopting stronger digital hygiene. Regardless of what Parliament ultimately passes, personal privacy habits pay dividends.

  • Use browsers and search engines with built-in tracker blocking.
  • Turn on encrypted DNS (DNS-over-HTTPS) at the device or router level.
  • Enable multi-factor authentication on every account that supports it.
  • Review app permissions on your phone quarterly.
  • Be cautious with the links you click and share. When sharing URLs publicly, use a privacy-respecting shortener such as Lunyb, which lets you shorten links without invasive tracking and gives you control over analytics you choose to enable.

For a deeper look at how link shorteners handle privacy, see our 2026 buyer's guide to URL shorteners and our honest review of Lunyb. Businesses evaluating branded link tools may also want to compare features in our Rebrandly 2026 review.

Current Status of Bill C-27

Bill C-27 was introduced in June 2022 and has progressed through parliamentary committee review, but its journey has been slowed by extensive study of AIDA in particular. The bill's ultimate form and coming-into-force dates depend on parliamentary schedules and any amendments. Organisations should monitor updates from the Office of the Privacy Commissioner of Canada and Innovation, Science and Economic Development Canada (ISED) for the latest guidance.

Regardless of the exact timeline, the substance of Bill C-27 reflects durable international norms. Even if the bill is amended or reintroduced, the direction — stronger rights, larger penalties, AI accountability — is unlikely to reverse.

Frequently Asked Questions

1. When will Bill C-27 come into force?

There is no single fixed date. Different parts of the bill will come into force through Order-in-Council after Royal Assent, and many operational details depend on regulations that must still be drafted. Most experts expect a transition period of at least 12 to 24 months before full enforcement begins.

2. Does Bill C-27 replace PIPEDA entirely?

No. The CPPA replaces Part 1 of PIPEDA (the private-sector privacy rules), while Part 2 of PIPEDA, which deals with electronic documents, remains in force. Public-sector federal privacy is still governed by the separate Privacy Act.

3. How does Bill C-27 affect small businesses?

All private-sector organisations engaged in commercial activity are covered, but obligations are proportionate to the volume and sensitivity of the data handled. Small businesses still need a privacy management programme, breach reporting procedures, and clear consent mechanisms, but the scale of documentation expected will be less onerous than for large enterprises.

4. What counts as a "high-impact" AI system under AIDA?

The precise definition will be set by regulation, but government guidance has pointed to systems used in employment decisions, provision of essential services, biometric identification, content moderation, healthcare, and law enforcement. If your AI could materially affect someone's rights, health, safety, or economic interests, assume it is in scope.

5. How does Bill C-27 compare to Quebec's Law 25?

Quebec's Law 25 is already in force and imposes GDPR-like obligations, including privacy impact assessments, breach reporting, and enhanced consent. Bill C-27 aligns the federal regime more closely with Law 25, though there are differences in wording, thresholds, and specific rights. Organisations operating nationally will typically design compliance programmes to meet the higher of the two standards.

Final Thoughts

Bill C-27 is not just another regulatory update — it is a generational shift in how Canada thinks about personal information and algorithmic accountability. Organisations that treat privacy as a strategic advantage, rather than a compliance burden, will be best positioned when the new rules take effect. Start mapping your data, tightening your consent flows, and asking hard questions about your AI systems today. Your customers, and eventually your regulators, will notice.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles