facebook-pixel

Bill C-27 Digital Charter: What You Need to Know in 2026

L
Lunyb Security Team
··10 min read

Canada's privacy landscape is undergoing its most significant transformation in more than two decades. Bill C-27, formally known as the Digital Charter Implementation Act, 2022, proposes to replace parts of the aging Personal Information Protection and Electronic Documents Act (PIPEDA) with modern frameworks designed for the realities of artificial intelligence, cross-border data flows, and the data-driven economy. If you run a business, build software, or simply care about how your personal information is handled, understanding Bill C-27 is essential.

This guide breaks down what the bill does, who it affects, how it compares to international laws like the GDPR, and what Canadian organisations should be doing right now to prepare.

What Is Bill C-27?

Bill C-27 is a Canadian federal legislative package that implements the government's Digital Charter by introducing three new statutes: the Consumer Privacy Protection Act (CPPA), the Personal Information and Data Protection Tribunal Act, and the Artificial Intelligence and Data Act (AIDA). Together, these laws would modernise federal private-sector privacy rules and create Canada's first dedicated AI legislation.

The bill was introduced in June 2022 by the Minister of Innovation, Science and Industry. It builds on the earlier (and lapsed) Bill C-11 and reflects feedback from privacy commissioners, industry stakeholders, academics, and civil society. While its passage has been slow and politically contested, its substantive requirements have already begun shaping how forward-looking Canadian businesses design products and handle data.

The Three Pillars of Bill C-27

  1. Consumer Privacy Protection Act (CPPA) — replaces Part 1 of PIPEDA and governs how private-sector organisations collect, use, and disclose personal information.
  2. Personal Information and Data Protection Tribunal Act — establishes a new administrative tribunal to review decisions and impose significant penalties.
  3. Artificial Intelligence and Data Act (AIDA) — introduces obligations for "high-impact" AI systems, including risk assessments, transparency, and record-keeping.

Why Canada Needs a New Privacy Law

PIPEDA was enacted in 2000, long before smartphones, cloud computing, social media platforms, and generative AI reshaped the data economy. Although PIPEDA has been amended over the years, its principles-based approach has struggled to keep pace with modern harms: large-scale breaches, algorithmic decision-making, dark patterns, and the commercial profiling of children.

At the same time, the European Union's General Data Protection Regulation (GDPR), Quebec's Law 25, Brazil's LGPD, and comprehensive U.S. state laws such as the CCPA/CPRA have raised global expectations. Without a credible modern framework, Canada risks losing its "adequacy" status with the EU, which would complicate cross-border data transfers for Canadian businesses.

The Consumer Privacy Protection Act (CPPA) Explained

The CPPA is the centrepiece of Bill C-27. It retains PIPEDA's familiar consent-based foundation while adding stronger individual rights, more precise obligations for organisations, and real enforcement teeth.

Key Individual Rights

  • Right to deletion (disposal): Individuals can request that organisations dispose of their personal information in many circumstances.
  • Data portability: Where a data mobility framework exists, individuals can have their information transferred to another organisation.
  • Algorithmic transparency: Organisations using automated decision systems to make predictions, recommendations, or decisions that could significantly impact an individual must provide a plain-language explanation on request.
  • Enhanced protections for minors: The information of minors is explicitly treated as "sensitive," triggering stricter handling requirements.
  • Withdrawal of consent: Clearer, more actionable rights to withdraw consent at any time.

Organisational Obligations

  1. Implement a privacy management programme proportionate to the volume and sensitivity of personal information handled.
  2. Provide plain-language privacy notices at or before collection, including purposes and third-party disclosures.
  3. Conduct and document assessments for sensitive activities, including profiling, cross-border transfers, and automated decision-making.
  4. Report significant breaches to the Office of the Privacy Commissioner (OPC) and notify affected individuals.
  5. Enter into written contracts with service providers to ensure equivalent protection of transferred data.

Penalties Under the CPPA

This is where Bill C-27 marks a dramatic shift. PIPEDA's enforcement regime has long been criticised as toothless. The CPPA changes that:

  • Administrative monetary penalties of up to the greater of $10 million CAD or 3% of global gross revenue.
  • Fines for the most serious offences of up to the greater of $25 million CAD or 5% of global gross revenue — among the highest in the world.

The Artificial Intelligence and Data Act (AIDA)

AIDA is Canada's first attempt at a cross-sectoral AI law. It focuses on "high-impact" AI systems, a category to be further defined in regulations but expected to include systems used in employment, healthcare, biometrics, content moderation at scale, and critical services.

Core AIDA Requirements

  1. Risk assessment and mitigation: Organisations must identify, assess, and mitigate risks of harm and biased output.
  2. Monitoring: Ongoing monitoring of compliance with mitigation measures.
  3. Transparency: Public disclosure of plain-language information about how a high-impact system is used, the types of content it generates, and the decisions it makes.
  4. Record-keeping: Documented evidence of compliance, available to regulators.
  5. Incident reporting: Notifying the Minister when a high-impact system causes material harm.

AIDA also creates new criminal offences for knowingly or recklessly making an AI system available for use that causes serious harm, as well as for unlawfully using personal information to design, develop, or use AI systems.

Bill C-27 vs. GDPR vs. Quebec Law 25

Canadian organisations often need to comply with multiple regimes simultaneously. The table below compares the key features.

FeatureBill C-27 (CPPA)EU GDPRQuebec Law 25
Max administrative penalty3% global revenue or $10M4% global revenue or €20M4% global revenue or $25M CAD
Right to deletionYes (disposal)Yes (erasure)Yes (de-indexing & deletion)
Data portabilityYes (framework-dependent)YesYes (as of 2024)
Automated decision transparencyYes, on requestYes, with right to human reviewYes, with right to human review
Privacy impact assessmentsRequired for sensitive activitiesRequired (DPIAs)Required (PIAs)
Dedicated AI rulesYes (AIDA)Separate EU AI ActNo dedicated AI law
Enforcement bodyOPC + new TribunalNational DPAs + EDPBCommission d'accès à l'information

Who Does Bill C-27 Apply To?

The CPPA applies to private-sector organisations that collect, use, or disclose personal information in the course of commercial activities, as well as to employee information of federal works, undertakings, and businesses. In practical terms, it covers:

  • Canadian companies of any size handling customer or user data
  • Foreign companies offering goods or services to individuals in Canada
  • Platforms, apps, SaaS vendors, retailers, and financial services
  • Marketing, analytics, and advertising technology providers

AIDA applies more narrowly to those who design, develop, make available, or manage the operations of high-impact AI systems in the course of international or interprovincial trade and commerce.

Pros and Cons of Bill C-27

Pros

  • Modernises a 25-year-old privacy framework.
  • Introduces meaningful penalties that align with international norms.
  • Strengthens protections for children and sensitive data.
  • Creates Canada's first dedicated AI governance framework.
  • Helps preserve EU adequacy and ease cross-border commerce.

Cons

  • AIDA has been criticised for being vague, with key definitions left to regulations.
  • The new Tribunal adds complexity and could slow enforcement.
  • Weaker in places than Quebec's Law 25, creating patchwork compliance challenges.
  • Business exceptions to consent are broader than some privacy advocates would like.
  • Legislative progress has been slow, creating uncertainty for planners.

How Businesses Should Prepare

Even if the final text of Bill C-27 shifts, the direction of travel is clear: more rights, more documentation, more accountability, and far larger fines. Canadian organisations should not wait for Royal Assent to begin preparing.

A Practical 7-Step Readiness Plan

  1. Map your data. Document what personal information you collect, where it is stored, who it is shared with, and why.
  2. Rewrite privacy notices. Use plain language, specify purposes, and clearly identify third parties and cross-border transfers.
  3. Build a privacy management programme. Assign accountability, document policies, and train staff.
  4. Operationalise individual rights. Create workflows for access, correction, disposal, and withdrawal of consent — with service-level targets.
  5. Inventory your AI systems. Identify which might be "high-impact" and begin risk assessments, bias testing, and documentation.
  6. Review vendor contracts. Ensure processors provide equivalent protection and support breach notification obligations.
  7. Harden your security posture. Encrypt data in transit and at rest, enforce strong authentication, use private DNS resolvers, and minimise data collection by design.

Privacy by Design in Everyday Tools

Compliance is not only about policies — it is also about the day-to-day tools your team uses. Shared links, campaign trackers, QR codes, and short URLs all touch personal data (clicks, IPs, approximate location, device metadata). Choosing vendors with transparent privacy practices, clear data retention, and Canadian-friendly handling helps reduce your overall exposure.

For example, if your marketing team relies on link shorteners, it is worth evaluating providers with a privacy-first stance. Our 2026 buyer's guide to URL shorteners compares the leading options, and tools like Lunyb are built around minimal data collection and encrypted delivery — a sensible fit for organisations trying to align with the CPPA's data minimisation principles. If you are considering legacy enterprise tools, our Rebrandly review is a useful counterpoint.

Enforcement: The New Tribunal

The Personal Information and Data Protection Tribunal is a novel feature. Under the proposed scheme, the Privacy Commissioner investigates and recommends penalties, which the Tribunal then reviews and imposes. Supporters argue this adds procedural fairness and expertise; critics warn it adds a layer that could delay accountability. Either way, organisations should expect more public findings, more orders, and more fines than under PIPEDA.

What Happens Next?

Bill C-27 has moved through committee study with substantial debate, particularly around AIDA. Amendments proposed by the government have attempted to tighten definitions, add alignment with the EU AI Act's risk categories, and clarify the role of the AI and Data Commissioner. Whether the bill passes in its current form, is split (with AIDA potentially carved out), or is reintroduced in a future session, the underlying policy direction is unlikely to reverse.

Organisations that treat Bill C-27 as a strategic opportunity — to earn trust, reduce risk, and modernise data practices — will be far better positioned than those that wait for a compliance deadline.

Frequently Asked Questions

Is Bill C-27 law in Canada yet?

As of early 2026, Bill C-27 has not yet received Royal Assent. It has progressed through committee review in the House of Commons but faces continuing debate, particularly around the Artificial Intelligence and Data Act. Even without passage, many organisations are preparing now because the policy direction and penalty levels are unlikely to be scaled back.

Does Bill C-27 replace PIPEDA entirely?

No. Bill C-27 would replace Part 1 of PIPEDA (the private-sector privacy rules) with the Consumer Privacy Protection Act. The electronic documents provisions in Part 2 of PIPEDA remain. Public-sector privacy continues to be governed by the federal Privacy Act, which is being reviewed separately.

How does Bill C-27 affect small businesses?

The CPPA applies to organisations of all sizes conducting commercial activities, but obligations like the privacy management programme are expected to be proportionate to the volume and sensitivity of data handled. Small businesses should still map their data, update privacy notices, and prepare to respond to individual requests. The real risk for smaller firms is reputational and operational, not just regulatory fines.

How does Bill C-27 interact with Quebec's Law 25?

Organisations operating in Quebec will need to comply with both. Where they overlap, the stricter requirement generally governs. Quebec's Law 25 is in some respects more prescriptive — for example, requiring explicit designation of a privacy officer and mandatory privacy impact assessments for certain projects — so compliance with Law 25 provides a strong foundation for CPPA readiness.

What should I do about AI systems I already use?

Begin by inventorying all AI and automated decision systems in use, including third-party tools embedded in software you license. Classify them by potential impact on individuals, document data inputs and model behaviour, test for bias, and ensure you can provide a plain-language explanation of decisions. Even if AIDA's final scope is narrower than proposed, these steps align with international AI governance norms and the CPPA's own automated decision-making transparency rule.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles