facebook-pixel

Bill C-27 Digital Charter: What You Need to Know in 2026

L
Lunyb Security Team
··9 min read

Canada's privacy landscape is undergoing its most significant transformation in more than two decades. Bill C-27, the Digital Charter Implementation Act, promises to modernize how personal information is collected, used, and disclosed by private-sector organizations across the country. If passed in its current form, it will replace the aging Personal Information Protection and Electronic Documents Act (PIPEDA) and introduce Canada's first federal law dedicated to artificial intelligence.

This guide breaks down what Bill C-27 actually contains, why it matters, and what organizations and individuals should do to prepare.

What Is Bill C-27?

Bill C-27, formally titled the Digital Charter Implementation Act, 2022, is a proposed federal Canadian statute that modernizes private-sector privacy law and introduces new rules for artificial intelligence. It bundles three separate pieces of legislation into one omnibus bill.

The three components are:

  1. The Consumer Privacy Protection Act (CPPA) — replaces Part 1 of PIPEDA and updates rules on consent, data portability, and enforcement.
  2. The Personal Information and Data Protection Tribunal Act — creates a new administrative tribunal to hear appeals and impose penalties.
  3. The Artificial Intelligence and Data Act (AIDA) — Canada's first federal AI law, governing high-impact AI systems.

The bill was introduced by the Minister of Innovation, Science and Industry in June 2022 as a re-tabled and expanded version of the earlier Bill C-11, which died on the Order Paper in 2021. As of 2026, portions of the bill remain under parliamentary review, but organizations are already preparing for its expected passage and enforcement.

Why Bill C-27 Matters

PIPEDA was drafted in 2000, before smartphones, social networks, cloud computing, and generative AI reshaped how personal data is generated and processed. Bill C-27 is Canada's attempt to align its privacy regime with modern realities and international standards such as the EU's General Data Protection Regulation (GDPR) and Quebec's Law 25.

For businesses, the stakes are high. Non-compliance could lead to some of the largest administrative penalties in Canadian history — up to 5% of global revenue or CAD $25 million, whichever is greater, for the most serious violations. For consumers, the bill introduces meaningful new rights, including the right to have personal data deleted and the right to an explanation for automated decisions.

The Consumer Privacy Protection Act (CPPA)

The CPPA is the centerpiece of Bill C-27. It restructures Canada's private-sector privacy law with clearer definitions, stronger individual rights, and a modern enforcement regime.

Key CPPA Provisions

  • Meaningful consent — Organizations must obtain valid, informed consent using plain language. Long, opaque privacy policies will no longer be sufficient.
  • Exceptions to consent — Certain "business activities" (like fraud prevention or product safety) allow limited processing without express consent, provided a reasonable person would expect it.
  • Right to disposal (deletion) — Individuals can request that their personal information be deleted, subject to legal retention requirements.
  • Data mobility — Individuals can request that their data be transferred between organizations under a designated framework.
  • Algorithmic transparency — Organizations using automated decision systems must provide an explanation of how a prediction, recommendation, or decision was made.
  • Enhanced protections for minors — The personal information of minors is treated as sensitive by default.
  • Codes of practice and certification — Industry groups can develop codes approved by the Privacy Commissioner.

Penalties Under the CPPA

The CPPA introduces two tiers of financial consequences:

  • Administrative monetary penalties: up to 3% of global revenue or CAD $10 million.
  • Offences for serious violations: up to 5% of global revenue or CAD $25 million.

The Personal Information and Data Protection Tribunal

The second act creates a dedicated administrative tribunal to hear appeals from the Privacy Commissioner's findings and to impose administrative monetary penalties. The Tribunal is intended to add a specialized layer of adjudication that combines legal and technical expertise.

The Tribunal will consist of three to six members, at least three of whom must have experience in information and privacy law. Critics have raised concerns about whether this additional layer will slow enforcement, while supporters argue it provides fairer, more expert review.

The Artificial Intelligence and Data Act (AIDA)

AIDA is Canada's first stand-alone federal AI statute. It targets "high-impact" AI systems and imposes obligations across their lifecycle — from design and development to deployment and monitoring.

Core AIDA Obligations

  1. Risk assessment — Organizations must assess whether their AI system is "high-impact" based on regulations still being finalized.
  2. Mitigation measures — High-impact systems must have measures to identify, assess, and mitigate risks of harm and biased output.
  3. Monitoring — Ongoing monitoring of compliance and system performance is required.
  4. Transparency — Public-facing information about the AI system must be published.
  5. Record keeping — Detailed records of assessments, datasets, and decisions must be maintained.

AIDA also creates new criminal offences for the reckless or intentional use of AI systems that cause serious harm, with penalties including imprisonment.

Bill C-27 vs. PIPEDA vs. GDPR

To understand where Canada is heading, it helps to compare Bill C-27's CPPA with the law it replaces and with the European standard it partly emulates.

FeaturePIPEDA (current)CPPA (Bill C-27)GDPR (EU)
Maximum penaltyCAD $100,000Up to 5% global revenue / CAD $25MUp to 4% global revenue / €20M
Right to deletionLimitedYes (right to disposal)Yes (right to erasure)
Data portabilityNoYes, via frameworkYes
Automated decision explanationsNoYesYes
Enhanced minor protectionsGeneralYes, sensitive by defaultYes
Dedicated AI lawNoYes (AIDA)Separate EU AI Act
Independent tribunalNoYesNational DPAs

Who Does Bill C-27 Apply To?

The CPPA applies to private-sector organizations that collect, use, or disclose personal information in the course of commercial activities across Canada. This includes federally regulated businesses and provincial businesses in provinces without "substantially similar" privacy laws.

Quebec, Alberta, and British Columbia have their own private-sector privacy laws that have been (or may be re-evaluated as) substantially similar. Organizations operating nationally will typically need to comply with multiple overlapping regimes.

AIDA applies to organizations involved in the design, development, and deployment of AI systems in the course of international or interprovincial trade and commerce.

Pros and Cons of Bill C-27

Pros

  • Brings Canada closer to GDPR-level protections, easing cross-border data flows.
  • Creates meaningful penalties that incentivize compliance.
  • Introduces modern rights: deletion, portability, and algorithmic transparency.
  • Provides Canada's first federal AI framework.
  • Strengthens protections for minors' personal information.

Cons

  • The additional Tribunal layer may slow enforcement compared with direct Commissioner orders.
  • AIDA has been criticized for leaving too many key definitions (like "high-impact") to future regulations.
  • Small and medium businesses face significant compliance costs.
  • Consent exceptions for "legitimate interest" and "business activities" have drawn criticism from privacy advocates.
  • Overlap with provincial laws creates a fragmented compliance landscape.

How Businesses Should Prepare

Even before Bill C-27 becomes fully enforceable, organizations should begin aligning their practices. A pragmatic preparation roadmap looks like this:

  1. Conduct a data inventory. Map what personal information you collect, why, where it lives, and who you share it with.
  2. Review consent mechanisms. Rewrite privacy notices in plain language. Confirm that consent is genuinely informed.
  3. Establish deletion and portability workflows. Ensure your systems can honor disposal and mobility requests within reasonable timelines.
  4. Assess automated decision systems. Document what they do, what data they use, and how you would explain their output to a user.
  5. Perform an AI risk classification. Determine whether any of your AI systems could be considered "high-impact" under AIDA.
  6. Update breach response plans. Ensure that breach reporting, record keeping, and notification procedures reflect CPPA requirements.
  7. Train staff. Privacy is not just a legal issue — front-line staff need to understand new rights and obligations.
  8. Consider a code of practice. Industry groups can develop sector-specific codes for Commissioner approval.

What Individuals Should Know

For everyday Canadians, Bill C-27 expands the toolkit available to protect personal information online. Once in force, you will have clearer rights to know what companies hold about you, to move that data, and to request its deletion. Automated decisions that affect you — for credit, hiring, or insurance — will require an explanation on request.

Still, legislation is only part of the picture. Practical digital hygiene matters just as much. That includes using privacy-respecting browsers, enabling encrypted DNS, being mindful of what you share on social platforms, and using trustworthy tools when you generate or share links online. If you shorten URLs frequently, choosing a privacy-conscious service like Lunyb — which doesn't monetize by aggressively tracking clickers — is a small but concrete step. You can read our honest review of Lunyb or compare options in our 2026 URL shortener buyer's guide.

The Road Ahead

Bill C-27 has moved through multiple readings and committee study, and its final form may still evolve. Recent amendments have addressed critiques around AIDA's scope, the independence of the Tribunal, and the treatment of minors' data. Regulations under AIDA — particularly the definition of "high-impact" systems — are expected to be published for consultation after the Act receives royal assent.

Organizations that treat Bill C-27 as a compliance-only exercise will likely find themselves scrambling. Those that treat it as an opportunity to modernize data governance — improving customer trust in the process — will be better positioned for the years ahead.

Frequently Asked Questions

When will Bill C-27 come into force?

Bill C-27 has not yet received royal assent as of 2026, and specific in-force dates will follow. Historically, major privacy laws have included transition periods (typically 12 to 24 months) before full enforcement begins, giving organizations time to prepare.

Does Bill C-27 replace PIPEDA entirely?

Not entirely. The CPPA replaces Part 1 of PIPEDA (the commercial privacy provisions), while Part 2 of PIPEDA, which deals with electronic documents, remains in force. Organizations that comply with the CPPA will not need to also comply with the repealed portions of PIPEDA.

What is considered a "high-impact" AI system under AIDA?

The definition of "high-impact" will be set by regulation, but proposed criteria include AI systems used in employment decisions, biometric identification, content moderation at scale, health-related decisions, and services essential to individuals. Organizations should assess their systems against the latest published guidance.

How does Bill C-27 affect small businesses?

Small and medium businesses are subject to the CPPA if they engage in commercial activity involving personal information. However, the law includes a reasonableness standard, meaning obligations scale with the sensitivity of data and the size of the organization. The Privacy Commissioner is expected to publish small-business guidance.

Will Bill C-27 be considered "adequate" by the EU?

Canada currently holds a partial adequacy decision under the GDPR for commercial data flows. Bill C-27 is broadly designed to preserve and strengthen this status by aligning key rights and enforcement powers with GDPR expectations, though the EU will conduct its own review after the law takes effect.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles