facebook-pixel

Bill C-27 Digital Charter: What You Need to Know

L
Lunyb Security Team
··10 min read

Canada's privacy landscape is on the verge of its most significant transformation in over two decades. Bill C-27, the Digital Charter Implementation Act, 2022, proposes to modernize how Canadian organizations collect, use, and disclose personal information, while introducing the country's first federal framework for artificial intelligence. Whether you run a small e-commerce shop, manage a marketing team, or simply want to understand your rights as a consumer, this legislation will affect you.

This guide breaks down what Bill C-27 contains, why it matters, how it compares to existing law, and what practical steps organizations should take to prepare.

What Is Bill C-27?

Bill C-27 is a proposed Canadian federal statute officially titled the Digital Charter Implementation Act, 2022. It bundles three separate but related pieces of legislation into a single bill:

  1. The Consumer Privacy Protection Act (CPPA) — replaces Part 1 of the current Personal Information Protection and Electronic Documents Act (PIPEDA).
  2. The Personal Information and Data Protection Tribunal Act — creates a new administrative tribunal to review Privacy Commissioner decisions and levy penalties.
  3. The Artificial Intelligence and Data Act (AIDA) — Canada's first federal law dedicated to regulating high-impact AI systems.

The bill was introduced by the federal Minister of Innovation, Science and Industry in June 2022 and has been undergoing extensive committee study. It is designed to bring Canada closer in line with international standards such as the European Union's General Data Protection Regulation (GDPR) and Quebec's Law 25.

Why Canada Needs a New Privacy Law

PIPEDA came into force in 2000 — a time before social media, smartphones, cloud computing, and generative AI. Regulators, businesses, and civil society groups have long argued that the law lacks the teeth and clarity needed for the modern data economy.

Key gaps in current law

  • No meaningful penalties. The Privacy Commissioner of Canada can investigate and publish findings but cannot issue fines directly.
  • Weak consent standards. Consent language has grown vague and buried in privacy notices.
  • No specific protections for minors. Children's data receives no elevated treatment under PIPEDA.
  • No AI-specific rules. Automated decision-making sits in a legal grey zone.
  • Inconsistency with provincial and international regimes. Quebec's Law 25 and the GDPR are far stricter, creating compliance friction.

The Consumer Privacy Protection Act (CPPA)

The CPPA is the backbone of Bill C-27. It replaces PIPEDA's privacy provisions and introduces a rights-based framework similar in spirit to the GDPR.

Key CPPA provisions

  • Plain-language consent. Organizations must explain, in clear terms, the purposes for which personal information is collected, used, or disclosed.
  • Right to erasure (data deletion). Individuals can request that their personal information be disposed of, subject to certain exceptions.
  • Right to data mobility. Individuals can request that their data be transferred between designated organizations.
  • Algorithmic transparency. Organizations using automated decision systems that produce significant impacts must provide an explanation on request.
  • Enhanced protections for minors. Information of minors is deemed "sensitive" by default, triggering heightened obligations.
  • De-identification and anonymization rules. Formal definitions and requirements for handling data that has been stripped of identifiers.
  • Codes of practice and certification programs. Industry-specific codes can be approved by the Privacy Commissioner.

Financial penalties under the CPPA

This is where Bill C-27 shows its teeth. The CPPA introduces two tiers of consequences:

  • Administrative monetary penalties of up to 3% of global revenue or CAD $10 million, whichever is higher.
  • Criminal fines for the most serious offences of up to 5% of global revenue or CAD $25 million, whichever is higher.

These figures put Canada in the same enforcement league as the European Union, and they represent one of the most consequential shifts in Canadian corporate compliance in a generation.

The Personal Information and Data Protection Tribunal

A new tribunal will be created to hear appeals of Privacy Commissioner decisions and to impose administrative monetary penalties. This structure separates the investigation function (Commissioner) from the adjudication function (Tribunal), which supporters argue provides procedural fairness. Critics — including the current Privacy Commissioner — have warned that the added layer may slow enforcement compared to jurisdictions where the regulator can fine directly.

The Artificial Intelligence and Data Act (AIDA)

AIDA is the most novel — and most debated — piece of Bill C-27. It creates a regulatory framework for "high-impact" AI systems and introduces obligations across the AI lifecycle.

Who does AIDA apply to?

AIDA applies to any person or organization that designs, develops, makes available for use, or manages the operations of an AI system in the course of international or interprovincial trade and commerce. That scope covers most commercial AI activity in Canada.

Core AIDA obligations

  1. Risk assessments. Determine whether a system qualifies as "high-impact."
  2. Mitigation measures. Establish measures to identify, assess, and mitigate risks of harm or biased output.
  3. Monitoring. Continuously monitor deployed systems for compliance with mitigation plans.
  4. Transparency. Publish plain-language descriptions of high-impact systems, including their intended uses and limitations.
  5. Record-keeping. Maintain detailed documentation of how systems are trained, tested, and deployed.
  6. Incident reporting. Notify the Minister when systems cause or are likely to cause material harm.

AIDA penalties

Violations can attract administrative penalties, regulatory fines up to 3% of global revenue or CAD $10 million, and — for the most serious offences involving knowingly using unlawfully obtained data or reckless deployment causing serious harm — criminal fines up to 5% of global revenue or CAD $25 million, plus potential imprisonment.

Bill C-27 vs. PIPEDA vs. GDPR: A Comparison

To understand where Canadian law is heading, it helps to see Bill C-27 against its predecessor and its closest international counterpart.

FeaturePIPEDA (current)Bill C-27 (proposed)GDPR (EU)
Maximum fineCAD $100,000Up to 5% global revenue / $25MUp to 4% global revenue / €20M
Right to erasureLimitedYesYes
Data portabilityNoYes (framework-based)Yes
Children's dataGeneral rulesDeemed sensitiveSpecial protections
Algorithmic transparencyNoYesYes (Art. 22)
Dedicated AI lawNoYes (AIDA)Yes (EU AI Act)
Regulator can fine directlyNoVia TribunalYes

Who Bill C-27 Affects

Businesses of all sizes

Any organization that collects personal information in the course of commercial activity — from a solo consultant to a multinational bank — will be subject to the CPPA. Small businesses will benefit from some proportionality in enforcement, but the underlying obligations remain.

Marketers and analytics teams

Consent, tracking, and profiling practices will face significantly higher scrutiny. Marketers who rely on link tracking, retargeting pixels, or behavioural segmentation should review their disclosures. Using privacy-respecting tools — such as a link management platform like Lunyb that provides analytics without invasive third-party trackers — can reduce compliance risk while preserving the insights you need. For a broader look at how modern shorteners handle privacy, see our 2026 URL shortener buyer's guide.

AI developers and deployers

Anyone building, integrating, or reselling AI systems — including generative AI products, credit scoring, hiring tools, or healthcare triage — should begin classifying whether their systems are "high-impact" and building governance processes.

Consumers

Canadians will gain enforceable rights to delete data, understand automated decisions affecting them, and receive stronger protections when they are minors.

What Businesses Should Do Now

Even though Bill C-27 has not yet received Royal Assent as of this writing, waiting is risky. Quebec's Law 25 is already in force, and provincial laws in Alberta and BC are being modernized in parallel. Organizations that prepare now will avoid a scramble later.

A practical seven-step readiness checklist

  1. Map your data. Know what personal information you collect, why, where it lives, and who has access.
  2. Update privacy notices. Rewrite them in plain language, purpose by purpose.
  3. Review consent flows. Ensure meaningful consent is obtained — no more pre-ticked boxes buried in long agreements.
  4. Establish data-subject request procedures. Build workflows for deletion, correction, and portability requests.
  5. Inventory automated decision systems. Document how they work, what data they use, and what impacts they produce.
  6. Appoint a privacy officer. Assign clear internal responsibility for compliance.
  7. Vet third-party vendors. Contracts should require equivalent safeguards from any processor handling your data.

Common Criticisms of Bill C-27

Bill C-27 has not been without controversy. Understanding the debate helps organizations anticipate how the final text may evolve.

  • Weaker than GDPR on "fundamental right" framing. Critics argue that privacy should be treated explicitly as a fundamental human right in the preamble.
  • Tribunal adds delay. Some argue the Privacy Commissioner should have direct enforcement power like the EU's data protection authorities.
  • AIDA drafted with limited consultation. Academic and civil society groups have criticized the AI portion for leaving too many key definitions to future regulations.
  • Business concerns about compliance costs. Small and medium-sized enterprises worry about proportionality of obligations.

Timeline and Current Status

Bill C-27 was introduced in June 2022 and has moved through second reading and extensive committee study at the House of Commons Standing Committee on Industry and Technology. Multiple amendments have been proposed, particularly to AIDA. Once passed, the CPPA and Tribunal Act would come into force on a date set by the Governor in Council, with AIDA expected to have a longer runway to allow regulations to be developed. Organizations should assume a transition period, but not one long enough to justify delay.

How Bill C-27 Interacts with Quebec's Law 25

Quebec's Law 25 (formerly Bill 64) is already fully in force and imposes many similar obligations: mandatory privacy officers, breach reporting, privacy impact assessments, data portability, and stiff fines. Organizations operating nationally should not treat Bill C-27 and Law 25 as duplicative — they overlap heavily, but each has unique requirements. A unified privacy program that meets the stricter of the two on each point is generally the most defensible path forward.

Practical Privacy Improvements You Can Make Today

Regardless of when Bill C-27 becomes law, several improvements are always defensible:

  • Adopt encrypted DNS (DoH or DoT) across your organization to reduce leakage of browsing metadata.
  • Use privacy-respecting analytics tools that avoid third-party cookies.
  • Minimize the personal data you collect — collect only what you actually need.
  • Encrypt data at rest and in transit as a baseline, not a premium feature.
  • Choose vendors that publish transparent privacy practices — for example, when sharing links, tools like Lunyb or alternatives reviewed in our Rebrandly 2026 review vary widely in what they log and share.

FAQ

Is Bill C-27 currently the law in Canada?

Not yet. As of this writing, Bill C-27 has been introduced and is undergoing committee study in Parliament. Until it receives Royal Assent and its provisions come into force, PIPEDA remains the governing federal privacy law for the private sector.

Does Bill C-27 apply to small businesses?

Yes. The CPPA applies to any organization that collects, uses, or discloses personal information in the course of commercial activity, regardless of size. However, enforcement is expected to consider proportionality, and specific obligations such as some AIDA requirements target larger, higher-risk operators.

What is a "high-impact" AI system under AIDA?

The bill defers detailed definition to regulations, but the government has signalled that systems used in employment decisions, provision of essential services, biometric identification, content moderation at scale, and health-related determinations are likely candidates. Organizations building or deploying such systems should assume they will fall in scope.

How is Bill C-27 different from the GDPR?

Both aim to modernize privacy protection and impose significant fines, but the GDPR frames privacy as a fundamental right and gives its regulators direct fining authority. Bill C-27 uses a Tribunal as an intermediate step, does not explicitly frame privacy as a fundamental right in its operative provisions, and pairs its privacy law with a dedicated AI statute (AIDA) — something the EU addresses in a separate AI Act.

What penalties can my company face under Bill C-27?

Administrative monetary penalties can reach 3% of global revenue or CAD $10 million (whichever is higher). Criminal offences involving the most serious violations can attract fines up to 5% of global revenue or CAD $25 million (whichever is higher). AIDA violations carry similar tiers.

When should my organization start preparing?

Now. Many Bill C-27 obligations mirror requirements already in force under Quebec's Law 25 and best practices under the GDPR. Building a modern privacy program today will position your organization to meet Bill C-27 with minimal disruption whenever it comes into force.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles