Canada Canada

Bill C-27 Died: What's Next for Canadian Privacy Reform

Bill C-27's CPPA and AIDA died with prorogation in January 2025. What the bill would have done and how to prepare for the successor.

Regulation

Bill C-27 (Digital Charter Implementation Act, 2022): CPPA, PIDPTA, AIDA (not enacted)

Max Penalty

Proposed: CAD 25 million or 5% of global revenue (never enacted; PIPEDA remains in force)

Enforcing Authority

OPC; proposed Personal Information and Data Protection Tribunal

Official Source

www.justice.gc.ca

Executive Summary

  • Bill C-27 would have replaced PIPEDA's privacy rules with the Consumer Privacy Protection Act (CPPA), created a data protection tribunal, and enacted the Artificial Intelligence and Data Act (AIDA).
  • It died on the order paper when Parliament was prorogued in January 2025, after stalling in committee. PIPEDA remains Canada's federal private-sector privacy law.
  • The CPPA's core ideas retain broad support: monetary penalties up to CAD 25 million or 5% of global revenue, disposal rights, data mobility, legitimate-interest exceptions, and stronger children's protections.
  • Companies aligned with Quebec Law 25 and GDPR are effectively pre-positioned for whatever successor legislation emerges.
  • AIDA's fate is more uncertain: Canada's AI regulation approach is being reconsidered rather than simply reintroduced.

For three years, Canadian privacy planning revolved around Bill C-27, the Digital Charter Implementation Act that would have replaced PIPEDA’s privacy regime with the Consumer Privacy Protection Act and added Canada’s first AI statute. That planning target evaporated on 6 January 2025, when prorogation killed every bill on the order paper. The reform pressure did not evaporate with it: the penalty gap with Quebec and the EU, and Canada’s adequacy relationship with Brussels, still point to a successor bill.

BillC-27 (44th Parliament): CPPA + Tribunal Act + AIDA
StatusDied on prorogation, 6 January 2025; PIPEDA still in force
Proposed penaltiesTo CAD 25M or 5% of global revenue
Legislative recordJustice Canada Bill C-27 record

What C-27 would have built

The CPPA kept PIPEDA’s consent-centric core but modernized it: express consent as default with codified exceptions (specified business activities, legitimate interest with assessment), a disposal right, data mobility frameworks, algorithmic transparency for predictions and decisions about individuals, anonymization versus de-identification standards, and minors’ information deemed sensitive. The tribunal act created a Personal Information and Data Protection Tribunal to impose the penalties the OPC recommended, answering the ombudsman-model critique in the OPC enforcement guide. AIDA targeted high-impact AI systems with assessment, mitigation, and reporting duties, Canada’s counterpart to the EU AI Act, though far thinner on the face of the statute.

Why readiness still matters

Three forces make a successor near-inevitable. Quebec’s Law 25 already enforces GDPR-grade duties with real fines, an untenable federal-provincial gap. The EU reaffirmed Canada’s adequacy in January 2024 while flagging that modernization is expected; adequacy underpins Canadian data-economy access to Europe. And every major trading partner (the EU, UK, and most US states) has moved to penalty-backed regimes.

The preparation that survives any drafting change: know your data (inventory and flows), fix consent quality to the meaningful-consent standard, build disposal and portability capability, document legitimate-interest style assessments where you rely on implied consent, and treat minors’ data as sensitive now. All of it is already required somewhere you likely operate, per PIPEDA’s principles, Law 25, or GDPR. A free scan shows where your site stands on the consent and tracking basics that every version of reform targets.

Frequently Asked Questions

Is Bill C-27 law?

No. It passed second reading and spent two years in committee, but died when Parliament was prorogued on 6 January 2025. PIPEDA continues to apply unchanged, alongside provincial laws in Quebec, Alberta, and BC.

What would the CPPA have changed?

Real penalties (administrative penalties to CAD 10 million or 3% of global revenue; offences to CAD 25 million or 5%), a new tribunal reviewing OPC-recommended penalties, disposal and mobility rights, codified legitimate-interest and business-activity exceptions to consent, anonymization standards, and treating minors' data as sensitive.

Should we pause compliance work until a new bill lands?

No. The stable strategy is to build to the strictest law you already face: Quebec Law 25 today imposes most of what the CPPA proposed, with 4%-of-turnover penalties in force now. Programs meeting Law 25 and GDPR will absorb a PIPEDA successor with minor adjustments.

What was AIDA?

The Artificial Intelligence and Data Act, C-27's third part: obligations for high-impact AI systems (risk assessment, mitigation, transparency, incident reporting) with penalties up to CAD 25 million or 5% of global revenue. It drew heavy criticism for delegating substance to regulations, and its successor path is less clear than the privacy parts.

What signals should we watch for the successor bill?

A reintroduced CPPA-style bill with children's privacy strengthened, possible separation of AI regulation from privacy reform, and the EU adequacy review: Canada's 2001 adequacy was reaffirmed in January 2024, but the Commission noted reform expectations, which keeps pressure on Ottawa to modernize PIPEDA.

Regulatory Crosswalk

PIPEDAQuebec Law 25GDPREU AI Act

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.