facebook-pixel

Bill C-27 Digital Charter: What You Need to Know in 2026

L
Lunyb Security Team
··10 min read

Canada's privacy laws are undergoing their most significant transformation in more than two decades. Bill C-27, the Digital Charter Implementation Act, proposes to replace the aging Personal Information Protection and Electronic Documents Act (PIPEDA) with a modern framework built for the age of artificial intelligence, cross-border data flows, and always-on connected services. If you run a business in Canada, handle Canadian customer data, or build AI systems, understanding this legislation is no longer optional.

This guide breaks down what Bill C-27 actually contains, who it applies to, the enforcement powers behind it, and the practical steps organizations should be taking now to prepare.

What Is Bill C-27?

Bill C-27, formally titled the Digital Charter Implementation Act, 2022, is a Canadian federal bill that bundles three separate pieces of legislation into a single reform package. It was introduced in the House of Commons in June 2022 and remains under parliamentary review as of 2026, with expected changes before final passage.

The three statutes inside Bill C-27 are:

  1. Consumer Privacy Protection Act (CPPA) – replaces the private-sector portions of PIPEDA and modernizes consumer privacy rights.
  2. Personal Information and Data Protection Tribunal Act (PIDPTA) – creates a new administrative tribunal to hear appeals and impose penalties.
  3. Artificial Intelligence and Data Act (AIDA) – Canada's first federal law specifically regulating high-impact AI systems.

Together, they represent the government's attempt to align Canada with international standards like the EU's GDPR while responding to public concerns about AI, data breaches, and corporate accountability.

Why Canada Needs New Privacy Legislation

PIPEDA was enacted in 2000, long before smartphones, social media, machine learning, or the modern data economy. Its consent-based model, weak enforcement powers, and vague standards have struggled to keep up. The European Commission also reviews Canada's "adequacy" status periodically—meaning if Canadian law falls too far behind GDPR, cross-border data transfers to Canada could face restrictions.

Bill C-27 aims to solve several problems at once:

  • Give the Office of the Privacy Commissioner (OPC) real enforcement teeth.
  • Modernize consent rules and add new rights for individuals.
  • Introduce specific protections for minors.
  • Establish national rules for high-risk AI systems.
  • Preserve Canada's GDPR adequacy status with the EU.

The Consumer Privacy Protection Act (CPPA) Explained

The CPPA is the centrepiece of Bill C-27 and the part most Canadian businesses will feel first. It applies to organizations that collect, use, or disclose personal information in the course of commercial activity, or across provincial or national borders.

Key Rights for Individuals

  • Right to disposal (deletion): Individuals can request their personal information be deleted, similar to GDPR's right to erasure.
  • Data mobility: Individuals can request their data be transferred to another organization under a data mobility framework.
  • Algorithmic transparency: If an automated decision system significantly affects someone, they can request an explanation.
  • Enhanced consent standards: Consent must be obtained in plain language at or before collection, describing purposes and consequences.
  • Special protection for minors: Information about minors is deemed "sensitive by default," triggering stricter handling requirements.

Key Obligations for Organizations

  1. Implement a documented privacy management program proportionate to the volume and sensitivity of data handled.
  2. Designate an individual responsible for privacy compliance.
  3. Maintain records of purposes for which personal information is collected.
  4. Conduct assessments before deploying activities that may cause significant harm.
  5. Report breaches of security safeguards involving real risk of significant harm to the OPC and affected individuals.
  6. Ensure service providers offer equivalent protection to any personal information transferred to them.

The Artificial Intelligence and Data Act (AIDA)

AIDA is the most controversial and closely watched component of Bill C-27. It would create Canada's first federal statute governing AI systems, focused specifically on "high-impact" systems—a category to be defined by regulation.

Core AIDA Requirements

  • Risk assessment: Those responsible for a high-impact system must assess whether it is high-impact and, if so, put mitigation measures in place.
  • Monitoring and record-keeping: Ongoing monitoring for bias, harm, and performance drift, with documentation available to regulators.
  • Transparency: Public plain-language descriptions of high-impact systems, including intended use, content generated, and mitigation measures.
  • Notification duty: The Minister of Innovation must be notified if a system causes or is likely to cause material harm.
  • Prohibitions: Making AI systems available that are likely to cause serious harm, or using personal information obtained unlawfully to design AI, would be criminal offences.

What Counts as "High-Impact"?

The government has signalled that high-impact systems will likely include those used in employment decisions, service provision (like credit or insurance), biometric identification, content moderation at scale, healthcare, and safety-critical applications. Precise definitions will come through regulation after AIDA is passed.

Penalties: Why This Bill Has Teeth

One of the biggest departures from PIPEDA is enforcement. Under the current regime, the Privacy Commissioner can investigate and publish findings, but has no power to fine. Bill C-27 changes this dramatically.

Violation TypeMaximum Administrative PenaltyMaximum Criminal Fine
CPPA administrative violationsGreater of $10 million CAD or 3% of global revenue
CPPA serious offences (on indictment)Greater of $25 million CAD or 5% of global revenue
AIDA regulatory offencesUp to $10 million CAD or 3% of global revenue
AIDA serious criminal offencesUp to $25 million CAD or 5% of global revenue

These figures are among the highest in the world and are explicitly modelled to be comparable with GDPR-level penalties. For a large multinational with billions in revenue, a 5% fine could easily reach hundreds of millions of dollars.

Who Does Bill C-27 Apply To?

The CPPA applies to any organization that collects, uses, or discloses personal information in the course of commercial activity in Canada, including foreign organizations targeting Canadian users. AIDA applies to those who design, develop, make available, or manage the operation of AI systems in the course of international or interprovincial trade and commerce.

Practically, that means:

  • Canadian businesses of nearly any size handling customer data.
  • Foreign e-commerce, SaaS, and platform companies serving Canadian users.
  • AI vendors selling models or services into Canada.
  • Employers using automated tools for hiring, monitoring, or performance decisions.

Provinces with substantially similar private-sector privacy laws (Quebec, British Columbia, and Alberta) will continue to apply their own statutes for intra-provincial activity, but the CPPA governs anything crossing provincial or national borders.

How Bill C-27 Compares to GDPR and Quebec's Law 25

FeatureBill C-27 (CPPA)EU GDPRQuebec Law 25
Right to deletionYes ("disposal")YesYes
Data portabilityYes (framework-based)YesYes (since 2024)
Algorithmic transparencyYes, on requestYes, on requestYes
Max fine (% of revenue)5%4%4%
Dedicated AI lawYes (AIDA)Separate EU AI ActNo
Breach notificationRequired (real risk of significant harm)Required (72 hours)Required
Minors' dataSensitive by defaultSpecial protectionsEnhanced consent

How to Prepare Your Organization

Even though Bill C-27 has not yet received royal assent as of early 2026, waiting is risky. Many of its requirements build on existing PIPEDA obligations, and Quebec's Law 25 is already in force. Getting ahead now reduces the scramble later.

A Practical Compliance Roadmap

  1. Map your data. Document what personal information you collect, why, where it lives, who you share it with, and how long you keep it.
  2. Review consent flows. Rewrite privacy notices in plain language. Ensure purposes are specific and disclosed at or before collection.
  3. Appoint a privacy lead. Formally designate someone accountable, even in small organizations.
  4. Build a privacy management program. Include policies, training, incident response, and vendor due diligence.
  5. Inventory AI and automated decision systems. Identify which could qualify as high-impact under AIDA.
  6. Tighten vendor contracts. Include equivalent-protection clauses for any processor handling Canadian personal information.
  7. Prepare deletion and access workflows. Make sure you can respond to requests within reasonable timelines.
  8. Test breach response. Tabletop exercises reduce the odds of a compliance failure during a real incident.

Reducing Your Data Footprint

One of the most effective ways to reduce privacy risk is to collect less data in the first place. Review analytics tools, tracking pixels, and third-party integrations. Where possible, choose privacy-respecting alternatives. For example, if you share links across marketing channels, using a shortener that does not resell click data—like Lunyb—keeps campaign analytics under your control rather than feeding third-party ad networks. You can read our honest review of Lunyb or compare options in our 2026 URL shortener buyer's guide to see how vendor choice affects your data exposure.

Common Criticisms of Bill C-27

Bill C-27 is not without controversy. Civil liberties groups, academics, and industry associations have raised several concerns during committee study:

  • AIDA is too vague: Critics argue that leaving "high-impact" undefined until regulation gives too much discretion to the executive branch.
  • Weaker than GDPR in places: The bill introduces exceptions for "legitimate interest" and "business activities" that some view as loopholes.
  • Tribunal adds delay: The new Personal Information and Data Protection Tribunal could slow enforcement compared with giving the OPC direct fining power.
  • Consultation gaps: Indigenous groups and small businesses have said they were under-consulted during drafting.

Amendments continue to move through committee, so the final version may differ meaningfully from the version introduced in 2022.

Timeline and What Happens Next

Bill C-27 has moved through second reading and committee study in the House of Commons. Once passed by Parliament, most provisions would come into force on a date fixed by order of the Governor in Council, typically giving organizations a transition period of one to two years. AIDA in particular is expected to have a longer runway while regulations defining high-impact systems are drafted through public consultation.

Organizations should assume that:

  • Final passage is likely within the next parliamentary cycle.
  • A 12–24 month transition period will follow for the CPPA.
  • AIDA regulations will be developed and consulted on in parallel.
  • Enforcement will ramp up gradually, but early high-profile cases are likely to set the tone.

Frequently Asked Questions

Is Bill C-27 law yet?

As of early 2026, Bill C-27 has not yet received royal assent. It is progressing through parliamentary review, and its provisions are not enforceable until it is passed and proclaimed into force. However, PIPEDA and provincial laws like Quebec's Law 25 remain fully in effect.

Does Bill C-27 apply to small businesses?

Yes. The CPPA applies to any organization engaged in commercial activity involving personal information, regardless of size. That said, obligations like the privacy management program are meant to be "proportionate" to the volume and sensitivity of data handled, so a small business's program will look very different from a bank's.

How is Bill C-27 different from Quebec's Law 25?

Quebec's Law 25 already imposes GDPR-like requirements on organizations operating in Quebec, including data portability, privacy impact assessments, and stiff penalties. Bill C-27 is federal and would create a similar baseline for the rest of Canada, plus add AIDA for AI systems. Organizations subject to both must comply with the stricter standard in each area.

What is a "high-impact" AI system under AIDA?

The bill does not fully define this term; it will be set out in regulations. Government guidance suggests systems used in employment, essential services, biometrics, healthcare, content moderation at scale, and safety-critical contexts are likely candidates. Organizations should inventory their AI use cases now so they can classify them quickly when the regulations arrive.

What are the penalties for non-compliance?

Administrative monetary penalties can reach the greater of $10 million CAD or 3% of global gross revenue. For serious offences pursued by indictment, fines can rise to the greater of $25 million CAD or 5% of global gross revenue—making these among the highest privacy penalties in the world.

Final Thoughts

Bill C-27 represents a generational shift in Canadian privacy and AI regulation. For businesses, the message is clear: the era of privacy as a checklist item is ending, and the era of enforceable, well-funded privacy oversight has arrived. Whether the final bill matches every detail of the current draft or not, the direction of travel is unmistakable—stronger rights, higher penalties, and real accountability for how organizations collect data and deploy AI.

The organizations that will fare best are those that treat compliance as an ongoing operational discipline rather than a one-off project. Start mapping data, review vendor relationships, document your AI systems, and build the habits now that a modern privacy regime will require of you tomorrow.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles