Canada - AI and Privacy Reform (Bill C-27)

Digital Charter Implementation Act (Bill C-27) — An Act to enact the Consumer Privacy Protection Act, the Personal Information and Data Protection Tribunal Act and the Artificial Intelligence and Data Act

Canada

RAI-CA-NA-DCICEXX-2022
Withdrawn(Failed, vetoed or pulled)
BillData Protection and PrivacyRisk ManagementGovernance and Oversight
Export PDF

Bill C-27 (Digital Charter Implementation Act, 2022) proposed three new federal statutes: the Consumer Privacy Protection Act (CPPA), the Personal Information and Data Protection Tribunal Act (PIDPTA), and the Artificial Intelligence and Data Act (AIDA). It sought to modernize private‑sector privacy law, create an administrative tribunal for privacy enforcement, and establish a risk‑based regulatory framework for certain AI systems. The bill advanced to committee but died on the Order Paper following prorogation of Parliament on January 6, 2025.

Summary

The Digital Charter Implementation Act, known as Bill C‑27 (2022), was a Government of Canada bill to restructure federal private‑sector privacy law and to introduce a federal regulatory framework for artificial intelligence. The bill had three Parts: (1) the Consumer Privacy Protection Act (CPPA), intended to replace Part 1 of PIPEDA, which would strengthen individual rights, introduce enhanced consent requirements, mandatory privacy management programs, record‑keeping and breach reporting obligations, new rules around de‑identification and prohibitions against re‑identification, and administrative monetary penalties; (2) the Personal Information and Data Protection Tribunal Act (PIDPTA), which would create an administrative tribunal to hear appeals from orders issued by the Privacy Commissioner, and to impose administrative monetary penalties recommended by the Commissioner; and (3) the Artificial Intelligence and Data Act (AIDA), a risk‑based federal statute aimed at private‑sector AI activity in international and interprovincial trade and commerce, defining obligations for design, development and deployment of AI systems, requirements for assessments and mitigation for high‑impact systems, transparency and record‑keeping obligations, powers for regulators (including production orders and audits), and prohibitions on certain uses of personal information (including use of illegally obtained personal information and making available for use systems likely to cause serious harm).

Bill C‑27 sought to modernize enforcement by enabling the Commissioner to initiate inquiries and audits, to issue orders, and to seek administrative monetary penalties through the new tribunal; the proposed AMP ceiling that received wide attention was up to CA$25 million or 5% of worldwide revenue for the most serious contraventions under the CPPA. AIDA contained both administrative penalty mechanisms (to be detailed by regulation) and new offence provisions for specific, blameworthy conduct (some carrying fines or imprisonment). The bill was subject to detailed study by the House Standing Committee on Industry and Technology and to submissions from stakeholders (including the Office of the Privacy Commissioner). Although it completed second reading and was referred to committee (April 24, 2023), it did not become law: the bill died on the Order Paper when Parliament was prorogued on January 6, 2025. The policy aims and many of the technical design choices (consent modernization, privacy management programs, oversight augmentation, risk‑based AI regulation) continue to inform debate and future federal proposals.

Full article

Read full text ↗

Overview

The Digital Charter Implementation Act (Bill C‑27) was a multi‑part Government bill that proposed to rewrite the federal private‑sector privacy legal framework and to create an AI‑specific federal statute. Its three statutory parts were the Consumer Privacy Protection Act (CPPA), the Personal Information and Data Protection Tribunal Act (PIDPTA), and the Artificial Intelligence and Data Act (AIDA). The CPPA would have replaced the federal PIPEDA privacy regime for commercial activities and introduced modern compliance duties (privacy management programs, stronger consent rules, de‑identification standards and enhanced complaint, inquiry and audit powers for the Privacy Commissioner). The PIDPTA would have established an independent administrative tribunal to hear appeals and impose administrative monetary penalties. The AIDA proposed a risk‑based regulatory architecture for private‑sector AI operating in interprovincial and international trade and commerce, including obligations for high‑impact systems and prohibitions on certain harmful or unlawful practices. For the legislative text and progression see Bill C‑27 (LegisInfo) and the Department of Justice explanatory note at Department of Justice: Bill C‑27.

Definitions

Key statutory definitions in the bill included (inter alia) "personal information," "organization" and "commercial activity" for the CPPA; "high‑impact AI system" and "regulated activity" for AIDA; and definitions describing "government institution" exclusions and the tribunal's scope. The CPPA used familiar privacy‑law concepts (consent, de‑identification, controller/processor analogues) but updated them for modern digital contexts; AIDA defined regulated persons as those involved in designing, developing, or making available AI systems in interprovincial or international trade and commerce, excluding certain defence and national security activities.

Governance and Institutional Framework

The bill strengthened and expanded institutional roles. The Office of the Privacy Commissioner (OPC) would retain and expand investigative, audit and order‑making authorities under the CPPA (with the ability to recommend AMPs to the new tribunal). The Personal Information and Data Protection Tribunal (to be created under PIDPTA) would be the decision‑maker empowered to hear appeals and impose administrative monetary penalties; the Tribunal would operate with administrative law safeguards and statutory criteria to determine penalties. Under AIDA, the Minister of Innovation, Science and Industry (or a delegated official) would hold regulatory and enforcement powers, including production and audit orders, publication of compliance directions, and the power to initiate administrative penalty processes under rules established by regulation. For details on powers and oversight, see the Justice explanatory note and the Library of Parliament legislative summary: Justice Canada explanatory note and Library of Parliament legislative summary (PDF).

Key Focus Areas

Bill C‑27 centered on several reform themes: (1) stronger individual rights — clearer consent standards, access, correction, deletion and portability; (2) organizational accountability — mandatory privacy management programs, breach record‑keeping and reporting where significant harm is likely, and detailed record retention obligations; (3) enforcement modernization — expanded inquiry and audit powers for the OPC, creation of the PIDPTA to impose AMPs, and expanded criminal offences against certain reckless or intentional misconduct (including re‑identification of de‑identified data and obstruction of investigations); (4) AI risk mitigation — AIDA’s risk‑based obligations required assessments for high‑impact systems, mitigations for biased output or safety risks, documentation and traceability practices, transparency obligations for specific systems, and prohibitions on making available for use systems likely to cause serious harm or built on illegally obtained personal information; and (5) rulemaking dependency — many operational details (AMP rules, thresholds, definitional refinements, procedural rules for the tribunal, and specific AI obligations) were to be set by future regulations, which stakeholders criticized as leaving too many core elements undeveloped in primary legislation. For technical analysis see the Legislative Summary at Library of Parliament (YM32‑3/441‑C27E) and OPC issue papers at OPC Issue Sheet on Bill C‑27.

Implementation Framework

Implementation depended on multi‑stage rulemaking and institution building. The CPPA and AIDA were to come into force on days fixed by orders in council; detailed operational obligations — AMP methodology, filing and reporting forms, standards for de‑identification, lists of high‑impact systems, and timelines for breach reporting — were delegated to regulation. The PIDPTA required establishment of administrative infrastructure and rules of procedure. The bill provided the Minister and the Governor in Council with expansive regulatory authority to specify: (a) criteria for assessing high‑impact AI systems; (b) procedural rules for penalty imposition; and (c) limits on disclosure of confidential business information. Stakeholders repeatedly urged that core obligations be in statute rather than left to subordinate instruments to ensure predictability and parliamentary scrutiny.

Monitoring and Evaluation

Monitoring responsibilities were divided. The OPC would monitor compliance with CPPA obligations through complaints, inquiries and audits and would maintain publication powers related to systemic issues. Under AIDA the Minister could require audits and third‑party assessments, compel production of records, and publish findings regarding systems posing serious risks of harm. The PIDPTA would create administrative precedents and publish decisions that would shape compliance expectations. The bill contemplated data‑driven monitoring (reporting by organizations, required documentation of risk assessments and mitigation steps, and mandatory record‑keeping) to enable regulators to target enforcement and policy adjustments.

Penalties, Liability, and Appeals

Bill C‑27 combined administrative and penal enforcement. Under the CPPA, the OPC could recommend administrative monetary penalties that the tribunal could impose; public commentary highlighted the proposed ceiling of CA$25 million or 5% of worldwide revenue for the most serious contraventions. The CPPA also preserved and expanded certain criminal offences (e.g., re‑identification and knowingly obstructing an inquiry). Under AIDA, administrative monetary penalties were to be specified by regulation and new criminal offences were proposed for knowingly or recklessly making available an AI system that causes serious harms, or for using illegally obtained personal information in AI development. Judicial review and statutory appeal routes were available against tribunal decisions. The combination of administrative sanctions and criminal offence provisions drew debate about proportionality and due process protections.

Relationship to Other Instruments

Bill C‑27 would have repealed Part 1 of the Personal Information Protection and Electronic Documents Act (PIPEDA) and renamed remaining PIPEDA provisions as the Electronic Documents Act. It intersected with other federal initiatives (telecommunications/cyber bills, sectoral regulators such as the Office of the Superintendent of Financial Institutions for the financial sector, and provincial privacy laws) and with international instruments (e.g., GDPR alignment considerations). The legislative design attempted to avoid overlap with existing federal statutes (Privacy Act exclusions for government institutions and national security carve‑outs), while creating federal norms intended to be interoperable with provincial regimes where possible.

International Alignment

The bill reflected Canada’s goal of aligning more closely with global privacy and AI regulatory trends (e.g., stronger enforcement and risk‑based AI rules similar in policy approach to frameworks emerging in the EU, UK and other jurisdictions). Specific design features (AMPs, data portability, de‑identification rules, and risk‑based AI obligations) were chosen to improve cross‑border interoperability and to support international trade and data flows, subject to adequacy and regulatory dialogues. However, the bill’s heavy reliance on regulation and the absence of some prescriptive provisions drew concern that Canada might lag the EU’s more prescriptive instrument unless regulations were promptly and robustly enacted.

Implementation Timeline

EventDate
First reading (House of Commons)2022-06-16
Library of Parliament legislative summary published2022-07-12
Second reading and referral to committee2023-04-24
Committee study and proposed amendments (Minister’s submissions)2023-10-03 to 2023-11-28 (committee meetings through Nov 2023)
Bill remained under committee consideration2023-11-28 to 2024 (ongoing)
Prorogation of Parliament — bill died on the Order Paper2025-01-06

Sources and References

SourceType
Bill C‑27 — LegisInfo (Parliament of Canada)Primary Source
Department of Justice — Explanatory Note: Bill C‑27Primary Source
Library of Parliament — Legislative summary (YM32‑3/441‑C27E)Primary Source

Requirements for a company

What an organisation has to do under Canada - AI and Privacy Reform (Bill C-27), at a glance. Not legal advice.

No current requirements. This instrument is withdrawn; it imposes nothing today.

© Regulations.AI · updated on 13-Jun-2026