For three years, Canadian privacy planning revolved around Bill C-27, the Digital Charter Implementation Act that would have replaced PIPEDA’s privacy regime with the Consumer Privacy Protection Act and added Canada’s first AI statute. That planning target evaporated on 6 January 2025, when prorogation killed every bill on the order paper. The reform pressure did not evaporate with it: the penalty gap with Quebec and the EU, and Canada’s adequacy relationship with Brussels, still point to a successor bill.
| Bill | C-27 (44th Parliament): CPPA + Tribunal Act + AIDA |
|---|---|
| Status | Died on prorogation, 6 January 2025; PIPEDA still in force |
| Proposed penalties | To CAD 25M or 5% of global revenue |
| Legislative record | Justice Canada Bill C-27 record |
What C-27 would have built
The CPPA kept PIPEDA’s consent-centric core but modernized it: express consent as default with codified exceptions (specified business activities, legitimate interest with assessment), a disposal right, data mobility frameworks, algorithmic transparency for predictions and decisions about individuals, anonymization versus de-identification standards, and minors’ information deemed sensitive. The tribunal act created a Personal Information and Data Protection Tribunal to impose the penalties the OPC recommended, answering the ombudsman-model critique in the OPC enforcement guide. AIDA targeted high-impact AI systems with assessment, mitigation, and reporting duties, Canada’s counterpart to the EU AI Act, though far thinner on the face of the statute.
Why readiness still matters
Three forces make a successor near-inevitable. Quebec’s Law 25 already enforces GDPR-grade duties with real fines, an untenable federal-provincial gap. The EU reaffirmed Canada’s adequacy in January 2024 while flagging that modernization is expected; adequacy underpins Canadian data-economy access to Europe. And every major trading partner (the EU, UK, and most US states) has moved to penalty-backed regimes.
The preparation that survives any drafting change: know your data (inventory and flows), fix consent quality to the meaningful-consent standard, build disposal and portability capability, document legitimate-interest style assessments where you rely on implied consent, and treat minors’ data as sensitive now. All of it is already required somewhere you likely operate, per PIPEDA’s principles, Law 25, or GDPR. A free scan shows where your site stands on the consent and tracking basics that every version of reform targets.