Bill C-27 Digital Charter: What You Need to Know
Canada's privacy landscape is on the verge of its biggest transformation in more than two decades. Bill C-27, formally known as the Digital Charter Implementation Act, 2022, proposes to replace parts of the aging Personal Information Protection and Electronic Documents Act (PIPEDA) and introduce Canada's first federal law regulating artificial intelligence. For businesses handling personal data and for Canadians who care about how their information is used, understanding Bill C-27 is no longer optional.
This guide breaks down what the Digital Charter contains, why it matters, how it compares to global privacy laws, and what organizations should be doing now to prepare.
What Is Bill C-27?
Bill C-27 is a Canadian federal bill introduced in June 2022 that would enact three separate pieces of legislation under one umbrella: the Consumer Privacy Protection Act (CPPA), the Personal Information and Data Protection Tribunal Act, and the Artificial Intelligence and Data Act (AIDA). Together, they modernize how personal data and AI systems are governed in the private sector.
The bill is the successor to Bill C-11, which died on the order paper in 2021. It forms the legislative backbone of Canada's Digital Charter, a ten-principle framework the federal government introduced in 2019 to build trust in the digital economy.
The Three Acts Inside Bill C-27
- Consumer Privacy Protection Act (CPPA) — Replaces Part 1 of PIPEDA and modernizes rules on consent, data portability, and enforcement.
- Personal Information and Data Protection Tribunal Act — Creates a new administrative tribunal to hear appeals and impose penalties.
- Artificial Intelligence and Data Act (AIDA) — Canada's first federal law focused specifically on "high-impact" AI systems.
Why Bill C-27 Matters
PIPEDA was enacted in 2000, long before smartphones, social media, or generative AI. Regulators, businesses, and privacy advocates have long argued it is outdated compared with the EU's GDPR, Quebec's Law 25, or California's CPRA. Bill C-27 aims to close that gap.
For Canadians, the bill promises stronger control over personal information, clearer consent rules, and real financial consequences for organizations that mishandle data. For businesses, it introduces significantly higher compliance obligations and some of the steepest privacy fines in the world.
The Stakes for Businesses
Under the CPPA, administrative monetary penalties can reach up to 3% of global revenue or $10 million, whichever is greater. For the most serious offences prosecuted as indictable, fines can climb to 5% of global revenue or $25 million. Those numbers meet or exceed the GDPR's headline penalties.
The Consumer Privacy Protection Act (CPPA) Explained
The CPPA is the heart of Bill C-27. It reshapes how private-sector organizations collect, use, and disclose personal information in the course of commercial activity across Canada.
Key CPPA Requirements
- Plain-language consent: Organizations must explain, in clear terms, the purpose of data collection, the type of information involved, and any reasonably foreseeable consequences.
- Right to disposal: Individuals can request that organizations delete personal information they have collected.
- Data mobility: Canadians will be able to move their data between organizations designated under a data mobility framework.
- Algorithmic transparency: Individuals can request an explanation of any prediction, recommendation, or decision made about them by an automated decision system.
- Privacy management programs: Every organization must maintain a documented program proportional to the volume and sensitivity of the personal data it handles.
- Enhanced protections for minors: Information about minors is deemed "sensitive by default," triggering stricter handling requirements.
- De-identified and anonymized data: The Act defines both terms and sets different rules for how each can be used or shared.
New Rights for Canadians
The CPPA expands individual rights well beyond PIPEDA. Canadians gain the ability to withdraw consent, request deletion, challenge automated decisions, and lodge complaints that could result in meaningful penalties. This mirrors the trajectory of privacy regulation globally.
The Personal Information and Data Protection Tribunal
Bill C-27 establishes a new administrative body — the Personal Information and Data Protection Tribunal — to hear appeals from decisions of the Privacy Commissioner and to impose administrative monetary penalties.
The tribunal will consist of three to six members, at least three of whom must have experience in information and privacy law. Its role is designed to add procedural rigor and specialized expertise to privacy enforcement, similar to how the Competition Tribunal supports the Competition Bureau.
The Artificial Intelligence and Data Act (AIDA)
AIDA is the first federal law in Canada devoted specifically to artificial intelligence. It focuses on "high-impact" AI systems — those that could cause significant harm to health, safety, or human rights, or lead to biased outcomes.
Core AIDA Obligations
- Risk assessment: Organizations must assess whether an AI system qualifies as high-impact.
- Mitigation measures: They must implement measures to identify, assess, and mitigate risks of harm or biased output.
- Monitoring: High-impact systems must be continuously monitored for compliance.
- Transparency: Organizations that make high-impact AI available for use must publish a plain-language description of the system.
- Record-keeping: Detailed documentation of datasets, design decisions, and testing must be maintained.
AIDA also introduces new criminal offences for making AI systems available while knowing they will cause serious harm, or for using unlawfully obtained data to build them.
How Bill C-27 Compares to Other Privacy Laws
Canadian organizations that already handle EU or Quebec data will find much of Bill C-27 familiar, but there are important differences.
| Feature | Bill C-27 (CPPA) | GDPR (EU) | Quebec Law 25 | CPRA (California) |
|---|---|---|---|---|
| Maximum fine | 5% global revenue / $25M CAD | 4% global revenue / €20M | 4% global revenue / $25M CAD | $7,500 USD per intentional violation |
| Right to deletion | Yes | Yes | Yes | Yes |
| Data portability | Framework-based | Yes | Yes | Limited |
| Automated decision rights | Yes (on request) | Yes | Yes | Limited |
| Dedicated AI law | Yes (AIDA) | EU AI Act (separate) | No | No |
| Enforcement body | OPC + new Tribunal | National DPAs | CAI | CPPA (California) |
Pros and Cons of Bill C-27
Pros
- Modernizes a two-decade-old privacy regime.
- Introduces meaningful penalties that incentivize compliance.
- Provides Canadians with expanded, GDPR-aligned rights.
- Creates Canada's first framework for AI accountability.
- Better positions Canada for adequacy status with international partners.
Cons
- Compliance costs will be substantial, especially for small and mid-sized businesses.
- AIDA has been criticized for lacking detail; many rules will be set later in regulations.
- Some consumer groups argue exceptions for "legitimate interest" and "business activities" weaken consent.
- The tribunal adds another procedural layer that could slow enforcement.
How Businesses Should Prepare for Bill C-27
Even though Bill C-27 is still moving through Parliament, forward-looking organizations are already treating it as a planning priority. Once passed, the transition period is expected to be short, and provinces like Quebec have shown that regulators do not wait long to act.
A Practical Readiness Checklist
- Map your data. Know exactly what personal information you collect, why, where it is stored, and who has access.
- Rewrite consent language. Move from legalese to plain-language explanations of purpose and consequences.
- Build a privacy management program. Document policies, training, breach response, and vendor oversight.
- Prepare for deletion and portability requests. Establish workflows before requests arrive.
- Inventory automated decision systems. Identify which qualify as high-impact under AIDA.
- Reassess third-party tools. Marketing, analytics, and link-tracking platforms all process personal data. Choose vendors with strong privacy postures — for example, when you share links, a privacy-respecting shortener like Lunyb can reduce the amount of user data exposed to third parties.
- Update contracts. Data processing agreements with service providers must reflect CPPA obligations.
- Train staff. Everyone from marketing to engineering should understand the basics of the new regime.
What Bill C-27 Means for Everyday Canadians
For most Canadians, the practical impact will show up in three ways: clearer privacy notices, easier ways to delete or move personal data, and more transparency when algorithms make decisions about them — from credit scoring to targeted advertising.
It also means Canadians can expect more visible enforcement actions. When large organizations mishandle data, the combination of the Privacy Commissioner's investigatory powers and the tribunal's penalty authority creates real deterrence, something PIPEDA has long lacked.
Practical Privacy Tips While the Law Evolves
You don't have to wait for Bill C-27 to become law to take control of your privacy. A few habits go a long way:
- Use browsers and search engines that limit tracking by default.
- Enable encrypted DNS (DNS over HTTPS) on your devices.
- Review app permissions monthly and revoke what you no longer use.
- Prefer link shorteners and analytics tools that are transparent about what they collect. Comparisons like our 2026 URL shortener buyer's guide can help you evaluate options.
- Turn on multi-factor authentication for any account that supports it.
Current Status of Bill C-27
As of the most recent parliamentary session, Bill C-27 has progressed through committee study in the House of Commons but has not yet received Royal Assent. Its future depends on the parliamentary calendar and political priorities. Even if the current version is delayed or amended, the underlying direction — stronger privacy rights, AI accountability, and meaningful penalties — is unlikely to change.
Organizations that treat compliance as a moving target rather than a one-time project will be best positioned no matter which version ultimately becomes law.
Frequently Asked Questions
Is Bill C-27 the same as PIPEDA?
No. Bill C-27 would repeal Part 1 of PIPEDA and replace it with the Consumer Privacy Protection Act. It also introduces two entirely new laws: one creating a data protection tribunal, and one governing artificial intelligence (AIDA). PIPEDA's electronic documents provisions remain in force.
When will Bill C-27 come into force?
Bill C-27 has not yet passed. If enacted, most provisions are expected to have a transition period, likely one to two years, before full enforcement begins. AIDA is expected to be implemented in phases, with core obligations activated after supporting regulations are finalized.
Who does Bill C-27 apply to?
The CPPA applies to private-sector organizations that collect, use, or disclose personal information in the course of commercial activity across Canada, including foreign organizations doing business with Canadians. AIDA applies to organizations that design, develop, or make available high-impact AI systems in the course of international or interprovincial trade.
What penalties can organizations face under Bill C-27?
Administrative monetary penalties can reach 3% of global revenue or $10 million CAD, whichever is greater. For the most serious offences prosecuted as indictable, fines can reach 5% of global revenue or $25 million CAD. AIDA introduces additional criminal offences with their own penalties.
How does Bill C-27 affect small businesses?
Small businesses are not exempt, but obligations are meant to be proportionate to the volume and sensitivity of the data they handle. Even so, small organizations should expect to invest in updated consent processes, a documented privacy management program, and clearer procedures for handling access, deletion, and complaint requests.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
ICO Fines 2026: Biggest Data Protection Penalties in the UK
The ICO issued record data protection penalties in 2026, with fines topping £6 million for ransomware failures and multi-million pound sanctions for marketing abuses. This guide examines the biggest UK fines of the year and the compliance lessons every organisation must learn.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
Learn how to file a privacy complaint with Ireland's Data Protection Commission (DPC). This step-by-step guide covers evidence gathering, submission channels, timelines, and what happens after you complain under GDPR.
Data Protection Act 2018 Ireland: Complete Guide
A complete guide to Ireland's Data Protection Act 2018, covering its relationship with the GDPR, individual rights, business obligations, DPC enforcement powers, and penalties. Learn what your organisation needs to do to stay compliant.
Singapore PDPA vs GDPR: Key Differences for Businesses in 2026
Singapore's PDPA and the EU's GDPR both protect personal data but differ significantly in scope, consent standards, penalties, and rights. This guide compares the two frameworks side-by-side so businesses can build a compliance strategy that works across borders.