Bill C-27 Digital Charter: What You Need to Know in 2026
Canada's privacy landscape is undergoing its most significant transformation in more than two decades. Bill C-27, formally known as the Digital Charter Implementation Act, is set to replace the aging Personal Information Protection and Electronic Documents Act (PIPEDA) with a modernized framework that reflects how businesses actually handle data in 2026. If you run a business, build software, market online, or simply care about how your personal information is used, understanding Bill C-27 is essential.
This guide breaks down what the Digital Charter contains, who it applies to, what penalties look like, how it treats artificial intelligence, and what practical steps organizations should take now to prepare.
What Is Bill C-27?
Bill C-27, the Digital Charter Implementation Act, is a federal Canadian bill that combines three separate pieces of legislation into a single omnibus package aimed at modernizing privacy, data protection, and artificial intelligence oversight. It was tabled by the Government of Canada in June 2022 and represents the federal response to years of criticism that PIPEDA had fallen behind global standards like the EU's GDPR.
The bill contains three components:
- Consumer Privacy Protection Act (CPPA) — replaces the private-sector portion of PIPEDA.
- Personal Information and Data Protection Tribunal Act (PIDPTA) — creates a new tribunal to handle appeals and penalties.
- Artificial Intelligence and Data Act (AIDA) — Canada's first federal AI-specific law.
Together, these acts establish new obligations for how organizations collect, use, disclose, and manage personal data and high-impact AI systems in Canada.
Why Bill C-27 Matters
PIPEDA was enacted in 2000, well before smartphones, social platforms, machine learning, and always-on tracking became the norm. Regulators, privacy commissioners, and business groups have all argued that Canadian law needs to catch up to reflect modern risks and to preserve "adequacy" status with the European Union, which allows data to flow freely between the two jurisdictions.
Bill C-27 matters because it:
- Introduces dramatically higher penalties for non-compliance.
- Grants Canadians new rights over their data, including data mobility and algorithmic transparency.
- Creates the first federal rules for "high-impact" AI systems.
- Aligns Canada more closely with GDPR-style principles.
- Establishes a dedicated tribunal to enforce compliance.
The Consumer Privacy Protection Act (CPPA)
The CPPA is the core privacy component of Bill C-27. It replaces Part 1 of PIPEDA and rewrites how private-sector organizations must handle personal information across Canada.
Key Principles Under the CPPA
- Meaningful consent — Organizations must obtain express consent using plain language that describes the purpose, nature, and consequences of collection.
- Purpose limitation — Data can only be used for purposes a reasonable person would consider appropriate.
- Right to disposal — Individuals can request that their personal information be deleted.
- Data mobility — Users can request that their data be transferred to another organization in a standardized format.
- Algorithmic transparency — When automated decision-making significantly affects a person, they can request an explanation.
- Protection of minors — The data of individuals under the age of majority is deemed "sensitive" by default, triggering stricter handling requirements.
New Exceptions to Consent
The CPPA also creates specific exceptions where consent is not required, such as for "business activities" like network security, product safety, or delivering a requested service. This gives organizations clearer ground rules than PIPEDA offered, but the exceptions are narrow and must be documented.
The Personal Information and Data Protection Tribunal
One of the most significant structural changes under Bill C-27 is the creation of a dedicated tribunal. Under PIPEDA, the Privacy Commissioner could investigate but had limited enforcement power. Under the new regime:
- The Privacy Commissioner investigates complaints and can recommend penalties.
- The Personal Information and Data Protection Tribunal reviews decisions and imposes administrative monetary penalties.
- Organizations and individuals can appeal to the tribunal rather than going straight to Federal Court.
This two-tier structure is designed to add expertise, speed, and consistency to privacy enforcement in Canada.
Penalties Under Bill C-27
Perhaps the most attention-grabbing part of the Digital Charter is its penalty regime. The fines are significantly larger than those under PIPEDA and are comparable to GDPR-level enforcement.
| Violation Type | Maximum Penalty |
|---|---|
| Administrative monetary penalties (CPPA) | The greater of $10 million CAD or 3% of global revenue |
| Serious offences (e.g., obstruction, knowingly using illegally obtained data) | The greater of $25 million CAD or 5% of global revenue |
| AIDA violations (high-impact AI misuse) | The greater of $25 million CAD or 5% of global revenue |
| PIPEDA (for comparison) | Up to $100,000 CAD per violation |
Beyond fines, individuals also gain a private right of action, meaning they can sue organizations that violate the CPPA and cause them harm.
The Artificial Intelligence and Data Act (AIDA)
AIDA is Canada's first federal attempt to regulate artificial intelligence. It focuses on "high-impact" AI systems — those that could pose material risks to health, safety, or human rights.
Core AIDA Obligations
- Risk assessment — Organizations must evaluate whether an AI system qualifies as "high-impact."
- Mitigation measures — Where risks are identified, safeguards must be implemented and documented.
- Transparency — Public-facing high-impact systems must disclose that AI is being used and how.
- Monitoring — Systems must be continuously monitored for bias, drift, and harm.
- Record-keeping — Detailed documentation must be maintained for regulators.
What Qualifies as "High-Impact"?
The bill leaves the exact definition to be developed through regulation, but government companion documents indicate that systems used for employment decisions, healthcare, biometric identification, content moderation at scale, and access to essential services will likely qualify.
Who Does Bill C-27 Apply To?
The CPPA applies to any private-sector organization that collects, uses, or discloses personal information in the course of commercial activity in Canada — including foreign companies whose services reach Canadians. AIDA applies to any organization designing, developing, or deploying high-impact AI systems in the course of international or interprovincial trade and commerce.
Provincial laws in Quebec (Law 25), British Columbia (PIPA), and Alberta (PIPA) continue to apply and may be deemed "substantially similar" to the CPPA, but organizations operating nationally will generally need to comply with the strictest applicable standard.
How Bill C-27 Compares to PIPEDA and GDPR
| Feature | PIPEDA | Bill C-27 (CPPA) | GDPR |
|---|---|---|---|
| Maximum Fine | $100K CAD | Up to 5% of global revenue | Up to 4% of global revenue |
| Right to Deletion | Limited | Yes | Yes |
| Data Portability | No | Yes | Yes |
| Algorithmic Transparency | No | Yes | Yes |
| Dedicated AI Rules | No | Yes (AIDA) | Separate EU AI Act |
| Private Right of Action | No | Yes | Yes |
| Enforcement Body | Privacy Commissioner | Commissioner + Tribunal | National DPAs + EDPB |
Practical Steps to Prepare for Bill C-27
Even though the bill has moved through committee stages and continues to evolve, forward-looking organizations are already aligning their practices. Here is a practical roadmap:
- Inventory your data. Map every category of personal information you collect, where it flows, who has access, and how long it's retained.
- Rewrite privacy notices. Use plain language, describe purposes concretely, and separate consent from terms of service.
- Implement deletion workflows. Build technical and procedural systems to honor disposal and correction requests within reasonable timeframes.
- Assess your AI systems. Identify any models that make consequential decisions about people, and start documenting risk assessments now.
- Update vendor contracts. Ensure processors and third parties handling Canadian data are contractually bound to CPPA-level protections.
- Train staff. Everyone from marketing to engineering should understand what personal data is and how the new rules affect their work.
- Appoint a privacy lead. The CPPA requires organizations to designate someone accountable for compliance.
- Review breach response plans. Notification obligations remain, and tribunals will look closely at how incidents are handled.
Privacy-Conscious Tools for Canadian Businesses
Compliance is not just about policies — it's also about the tools you use every day. Marketing links, analytics platforms, and tracking pixels are all points where personal data gets collected, often more than businesses realize.
Choosing services that minimize data collection by default helps reduce your compliance surface. For example, using a privacy-respecting link shortener like Lunyb lets you share, track, and manage campaign URLs without hoarding unnecessary personal identifiers. If you're evaluating options, our 2026 buyer's guide to URL shorteners compares privacy features across the leading providers, and our honest Lunyb review covers how the platform stacks up for Canadian businesses specifically.
What Happens Next?
Bill C-27 has moved through readings and committee study in the House of Commons, with ongoing amendments — particularly around AIDA and definitions of high-impact systems. Once passed, most provisions are expected to include a transition period (likely two years) before full enforcement begins. That means organizations still have time to prepare, but the runway is shorter than it appears once you factor in the engineering, legal, and training work required.
Even if political timelines shift, the direction of travel is clear: Canadian privacy law is moving toward stricter consent, real penalties, algorithmic accountability, and individual rights that mirror global standards. Businesses that treat this as a strategic opportunity — rather than a last-minute checkbox — will be far better positioned when enforcement begins.
Frequently Asked Questions
When will Bill C-27 come into force?
As of 2026, Bill C-27 is still progressing through the parliamentary process and has faced amendments and delays. Once passed, most provisions are expected to include a transition period of roughly two years before full enforcement, giving organizations time to adapt.
Does Bill C-27 apply to small businesses?
Yes. The CPPA applies to any organization engaged in commercial activity that collects personal information, regardless of size. However, obligations are scaled to be reasonable relative to the sensitivity of the data and the size of the organization, and small businesses will benefit from simpler consent and record-keeping requirements in lower-risk situations.
How is Bill C-27 different from Quebec's Law 25?
Quebec's Law 25 (formerly Bill 64) is already in force and imposes GDPR-style obligations at the provincial level. Bill C-27 is the federal equivalent and applies more broadly across Canada. Organizations operating in Quebec must comply with Law 25, and if they operate elsewhere in Canada, will also need to comply with the CPPA. The two frameworks are similar but not identical, and where they differ, the stricter standard usually applies.
What is considered a "high-impact" AI system under AIDA?
The final list will be set by regulation, but government guidance signals that systems used in employment, healthcare, biometric identification, essential services, content moderation at scale, and law enforcement contexts are likely to qualify. Organizations should assume that any AI system materially affecting people's rights, safety, or economic opportunities may fall within scope.
What are the penalties for non-compliance?
Administrative monetary penalties under the CPPA can reach the greater of $10 million CAD or 3% of global revenue, while serious offences and AIDA violations can reach the greater of $25 million CAD or 5% of global revenue. Individuals also gain a private right of action for damages resulting from violations.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
A complete 2026 guide to filing a privacy complaint with the Data Protection Commission (DPC) in Ireland. Learn the process, timelines, evidence you need, and what outcomes to expect under the GDPR.
OAIC Complaints: How to Report a Privacy Breach in Australia
A step-by-step Australian guide to OAIC complaints: what counts as a privacy breach, how to complain to the organisation first, how to lodge with the regulator, and what outcomes to expect. Includes evidence tips, timelines, and answers to common questions.
ICO Fines 2026: Biggest Data Protection Penalties in the UK
The ICO has issued record-breaking data protection fines in 2026, targeting healthcare providers, retailers and marketers. We break down the biggest UK penalties, the compliance failures behind them, and the practical steps every organisation should take to stay off the enforcement page.
Australia Privacy Act 2026: Your Rights Explained
The Australia Privacy Act 2026 delivers the biggest overhaul of Australian data protection law in decades. This guide explains your new rights — including erasure, direct legal action and protections around automated decisions — plus what businesses must do to comply.