Bill C-27 Digital Charter: What You Need to Know in 2026
Canada's privacy landscape is on the verge of its most significant transformation in over two decades. Bill C-27, formally known as the Digital Charter Implementation Act, proposes sweeping changes to how organizations collect, use, and disclose personal information — and how artificial intelligence systems are regulated across the country. If you run a business, handle customer data, or simply want to understand your rights as a Canadian, this legislation matters.
This guide breaks down what Bill C-27 actually contains, why it was introduced, how it differs from the existing Personal Information Protection and Electronic Documents Act (PIPEDA), and what steps organizations should take to prepare for compliance.
What Is Bill C-27?
Bill C-27 is a Canadian federal bill introduced in June 2022 that would enact three new laws: the Consumer Privacy Protection Act (CPPA), the Personal Information and Data Protection Tribunal Act, and the Artificial Intelligence and Data Act (AIDA). Together, these statutes are designed to modernize Canada's privacy framework, create a dedicated enforcement tribunal, and establish the country's first comprehensive rules for high-impact AI systems.
The bill is the successor to Bill C-11, which died on the order paper in 2021. It forms the legislative backbone of Canada's Digital Charter — a ten-principle framework announced in 2019 that emphasizes trust, transparency, and control over personal data in the digital economy.
The Three Pillars of Bill C-27
- Consumer Privacy Protection Act (CPPA) — Replaces Part 1 of PIPEDA and introduces stronger consent rules, new individual rights, and dramatically increased penalties.
- Personal Information and Data Protection Tribunal Act — Creates a specialized tribunal to hear appeals of Privacy Commissioner decisions and impose administrative monetary penalties.
- Artificial Intelligence and Data Act (AIDA) — Establishes obligations for organizations that design, develop, or deploy high-impact AI systems in Canada.
Why Canada Needs a New Privacy Law
PIPEDA has governed private-sector privacy in Canada since 2000. While it was groundbreaking at the time, it predates the smartphone, cloud computing, generative AI, and modern data brokers. Regulators, businesses, and privacy advocates have long agreed that PIPEDA lacks the teeth and specificity needed for today's digital economy.
Three pressures are driving reform:
- International alignment. The EU's General Data Protection Regulation (GDPR) set a global benchmark. Canada's adequacy status — which allows free-flowing data transfers with the EU — depends on maintaining comparably strong protections.
- Consumer expectations. Canadians increasingly want meaningful control over their data, portability rights, and the ability to demand deletion.
- Enforcement gaps. Under PIPEDA, the Office of the Privacy Commissioner (OPC) can investigate and recommend, but cannot directly fine organizations. Bill C-27 changes that dramatically.
The Consumer Privacy Protection Act (CPPA) Explained
The CPPA is the centrepiece of Bill C-27. It retains PIPEDA's foundation — consent-based collection, use, and disclosure of personal information — but modernizes almost every mechanism around it.
Key New Rights for Individuals
- Right to disposal (deletion). Individuals can request that an organization dispose of their personal information, subject to legal and contractual exceptions.
- Right to data mobility. Personal information can be transferred between organizations under a designated framework (similar to open banking).
- Algorithmic transparency. Individuals can request an explanation of any prediction, recommendation, or decision made about them by an automated decision system.
- Enhanced consent standards. Consent must be obtained in plain language, and organizations must clearly identify the purposes of collection at or before the time of consent.
- Special protections for minors. Information of minors is expressly deemed sensitive under the CPPA, triggering heightened obligations.
New Obligations for Organizations
- Privacy management programs. Every organization must implement and document a privacy management program proportionate to its size and the sensitivity of information handled.
- Breach reporting. Reinforces mandatory reporting to the OPC and affected individuals for breaches posing a real risk of significant harm.
- De-identification and anonymization standards. The CPPA distinguishes between the two, with different rules applying to each.
- Codes of practice and certification programs. Industry sectors can seek OPC approval for tailored codes.
- Legitimate interest exception. Limited circumstances allow processing without consent, but only after a documented assessment.
Penalties That Actually Bite
This is where the CPPA departs most sharply from PIPEDA. The proposed penalty regime includes:
| Penalty Type | Maximum Amount | Trigger |
|---|---|---|
| Administrative Monetary Penalty | 3% of global revenue or CAD $10 million (whichever is higher) | Serious contraventions of the CPPA |
| Fine on indictment | 5% of global revenue or CAD $25 million (whichever is higher) | Knowing or reckless offences (e.g. obstruction, retaliation against whistleblowers) |
| Private right of action | Damages set by courts | Individuals harmed by contraventions after OPC or tribunal findings |
These figures put Canada in the same enforcement tier as the GDPR and represent a paradigm shift in how privacy risk should be modelled at the board level.
The Personal Information and Data Protection Tribunal
Bill C-27 creates a new quasi-judicial body — the Personal Information and Data Protection Tribunal — that sits between the Privacy Commissioner and the Federal Court. Its role is to hear appeals of the Commissioner's findings and orders and to impose administrative monetary penalties recommended by the Commissioner.
Supporters argue the tribunal brings specialized expertise and faster resolution than general courts. Critics, including former Privacy Commissioners, worry it adds an unnecessary procedural layer that could slow enforcement. Either way, the tribunal will be composed of up to six members, at least three of whom must have privacy experience.
The Artificial Intelligence and Data Act (AIDA)
AIDA is Canada's first attempt at horizontal AI regulation. It focuses on high-impact AI systems — a category that will be defined further through regulations but is expected to include AI used in employment decisions, biometric identification, content moderation at scale, healthcare, and critical infrastructure.
Core AIDA Requirements
- Risk assessment and mitigation. Organizations must identify, assess, and mitigate risks of harm and biased output.
- Monitoring and record-keeping. Ongoing performance monitoring is required, with documentation of measures taken.
- Transparency. Public-facing information about how systems are used, their limitations, and the types of decisions made.
- Reporting serious incidents. Material harm caused by an AI system must be reported to the Minister of Innovation.
- Anonymized data governance. Records must show how anonymized data used for training was created and managed.
AIDA Enforcement
AIDA introduces both administrative and criminal penalties. Administrative penalties can reach the greater of CAD $10 million or 3% of global revenue. Criminal offences — such as knowingly using unlawfully obtained personal information to develop an AI system, or deploying a system that causes serious harm — can lead to fines of up to CAD $25 million or 5% of global revenue.
How Bill C-27 Compares to PIPEDA and GDPR
| Feature | PIPEDA (Current) | Bill C-27 / CPPA | EU GDPR |
|---|---|---|---|
| Maximum fine | CAD $100,000 | 5% of global revenue or CAD $25M | 4% of global revenue or €20M |
| Right to deletion | Limited | Yes (right to disposal) | Yes (right to erasure) |
| Data portability | No | Yes (with framework) | Yes |
| Automated decision explanations | No | Yes | Yes |
| AI-specific rules | No | Yes (via AIDA) | Separate EU AI Act |
| Dedicated tribunal | No | Yes | National DPAs |
| Minor protections | General | Deemed sensitive | Enhanced (Art. 8) |
What Bill C-27 Means for Canadian Businesses
Whether you operate a two-person marketing consultancy or a national retailer, Bill C-27 will reshape day-to-day data practices. Preparation should not wait for royal assent, because the compliance groundwork takes months.
Pros of the New Framework
- Clearer, plain-language consent rules reduce ambiguity in customer communications.
- Alignment with GDPR eases compliance for businesses operating in both markets.
- Statutory framework for de-identified data enables safer analytics and research.
- Codes of practice let industries create tailored, pre-approved rules.
Cons and Concerns
- Compliance costs will rise, especially for SMBs without in-house privacy expertise.
- Uncertainty around key definitions (e.g. "high-impact" AI, "sensitive" information beyond minors).
- The tribunal layer may lengthen enforcement timelines.
- Interaction with provincial privacy laws (Quebec's Law 25, Alberta's PIPA, BC's PIPA) creates a patchwork.
Preparing for Bill C-27: A Practical Checklist
- Map your data. Identify what personal information you collect, why, where it's stored, and who has access.
- Review consent flows. Rewrite privacy notices and consent prompts in plain language, and separate purposes clearly.
- Establish a privacy management program. Assign accountability, document policies, and train staff regularly.
- Prepare for individual rights requests. Build processes for deletion, portability, and algorithmic explanations.
- Audit vendors and processors. Ensure contracts include CPPA-aligned obligations and breach notification clauses.
- Inventory AI systems. Classify each system by potential impact and document risk assessments.
- Rehearse breach response. Run tabletop exercises against the CPPA's "real risk of significant harm" trigger.
- Watch provincial developments. Coordinate with Law 25 obligations in Quebec and pending reforms elsewhere.
Privacy Tools and Everyday Practices for Canadians
Bill C-27 gives Canadians stronger legal rights, but personal habits still matter. A few practical measures individuals can adopt today:
- Use encrypted DNS (DoH or DoT) to reduce network-level tracking of the sites you visit.
- Choose privacy-respecting browsers and search engines that minimize fingerprinting.
- Exercise your existing PIPEDA rights — request access to your data and correct inaccuracies.
- Prefer link-sharing tools that don't harvest analytics on your contacts. A privacy-focused shortener like Lunyb lets you share clean, branded links without exposing recipient behaviour to third-party ad networks. If you're evaluating options, our 2026 buyer's guide to URL shorteners compares the leading services.
- Review app permissions quarterly and revoke anything you no longer use.
Where Bill C-27 Stands Today
As of 2026, Bill C-27 has passed second reading and moved through extensive committee review at the House of Commons Standing Committee on Industry and Technology. The government has proposed amendments — particularly to AIDA — in response to feedback from industry, academics, and civil liberties organizations. The bill has not yet received royal assent, and further amendments are likely before it becomes law. Once passed, a transition period (expected to be 12–24 months for the CPPA, and longer for AIDA regulations) will give organizations time to comply.
Frequently Asked Questions
When will Bill C-27 come into force?
No firm date has been set. After royal assent, the CPPA is expected to have a transition period of roughly 12–24 months. AIDA's substantive obligations will depend on regulations that are being developed in parallel and are unlikely to take effect before 2026–2027.
Does Bill C-27 replace PIPEDA entirely?
Only Part 1 of PIPEDA (private-sector privacy) is replaced by the CPPA. Part 2, which deals with electronic documents and signatures, becomes the standalone Electronic Documents Act. Federal public-sector rules under the Privacy Act are not affected.
How does Bill C-27 interact with Quebec's Law 25?
Both laws will co-exist. Quebec's Law 25 applies to organizations operating in Quebec, while the CPPA applies federally to commercial activities across Canada. Organizations doing business in Quebec must comply with both, and the stricter requirement generally prevails on any given issue.
Do small businesses have to comply with Bill C-27?
Yes. The CPPA applies to any organization that collects, uses, or discloses personal information in the course of commercial activities, regardless of size. However, the privacy management program requirement is explicitly proportionate to volume and sensitivity, so obligations scale with risk.
What happens if my organization uses AI but not in a "high-impact" way?
AIDA's obligations focus on high-impact systems, so lower-risk uses face lighter requirements. That said, general CPPA rules on transparency, consent, and automated decisions still apply, and it's wise to document your classification rationale in case regulators disagree.
Final Thoughts
Bill C-27 represents Canada's most ambitious attempt to catch up with — and in some areas surpass — global privacy standards. For businesses, the message is clear: privacy is no longer a compliance afterthought but a strategic pillar with real financial and reputational stakes. For Canadians, the bill promises meaningful new rights and, for the first time, an enforcement regime capable of holding organizations genuinely accountable.
The organizations that thrive under Bill C-27 will be those that treat privacy and responsible AI as competitive advantages rather than burdens. Start mapping your data, updating your policies, and thinking critically about the systems that shape decisions about your customers — because the Digital Charter era is arriving whether you're ready or not.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
OAIC Complaints: How to Report a Privacy Breach in Australia
A step-by-step Australian guide to lodging a privacy complaint with the OAIC — including preparation, timelines, evidence, remedies and realistic outcomes. Learn exactly what to do when an organisation mishandles your personal information under the Privacy Act.
PIPEDA vs GDPR: Canadian Privacy Law Explained (2026 Guide)
PIPEDA and the GDPR both protect personal data, but they differ sharply on consent, individual rights, and penalties. This guide compares Canada's privacy law to Europe's GDPR and shows Canadian businesses exactly what compliance looks like in 2026.
Singapore PDPA: Your Personal Data Protection Rights Explained
Singapore's PDPA gives you clear rights over your personal data — from access and correction to data portability and breach notification. This guide explains each right, how to exercise it, and how to file a complaint with the PDPC in 2026.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
A step-by-step guide to filing a privacy complaint with Ireland's Data Protection Commission (DPC), including what evidence to gather, how to submit, and what to expect at each stage. Learn timelines, appeal rights, and practical privacy tips for Irish residents.