Back to Blog
Compliance June 29, 2026 7 min read

Bill C-27 CPPA: What Changes for Canadian Business, and How to Win Day Zero

Bill C-27 would hand the Privacy Commissioner real teeth and put penalties of up to 5% of global revenue on the table. The companies that prepare now inherit a head start the day a successor passes.

By Valdra Team

Bill C-27 CPPA: What Changes for Canadian Business, and How to Win Day Zero

A mid-sized Ontario retailer got a complaint last year. A customer wanted to know every place the company had shared their purchase history. Under the law as it stands, the retailer stalled, gave a vague answer, and the matter quietly went nowhere. The Office of the Privacy Commissioner can investigate and publish findings, but it cannot fine you a dollar for that kind of evasion. That single fact is what Bill C-27 was built to change.

For roughly two decades, the federal private-sector privacy regime, PIPEDA, has run on goodwill and reputational pressure. The Commissioner could name and shame. Courts could award damages, but only after a long road through Federal Court. Meanwhile Quebec rewrote its own rules under Law 25 and started building penalties that actually sting. The gap between a toothless federal statute and a sharp provincial one became impossible to ignore.

What the Bill C-27 CPPA Package Actually Replaces

Bill C-27 was a package, not a single law. It bundled three pieces: the Consumer Privacy Protection Act (CPPA), the Personal Information and Data Protection Tribunal Act, and the Artificial Intelligence and Data Act (AIDA). The CPPA is the part that touches almost every business in the country, so that is where your attention belongs.

The CPPA would repeal the privacy provisions of PIPEDA and put a modern statute in their place. Think of it less as a tweak and more as a replacement chassis. Consent rules get rewritten. Individual rights expand. And the enforcement model flips from "we'll publish a report" to "we can recommend a fine that ends with several commas."

A word on where the bill stands. C-27 was introduced in June 2022, cleared second reading, and spent a long stretch in committee at INDU. When Parliament was prorogued in early 2025, the bill died on the order paper. The project itself is not dead. The policy pressure behind it has only grown, and any serious privacy reform that returns will carry the same DNA: real penalties, stronger consent, an enforcement tribunal. Preparing for the CPPA is preparing for whatever Ottawa reintroduces, because the direction of travel is settled even where the exact wording is not.

The Penalty Numbers That Get a CFO's Attention

Here is the line that changes the conversation in the boardroom. Under the CPPA, the most serious contraventions could draw administrative monetary penalties of up to $10 million or 3% of global gross revenue, whichever is higher. For certain offences prosecuted on indictment, the ceiling rises to $25 million or 5% of global gross revenue.

Compare that to today. PIPEDA's existing offence provisions cap fines at $100,000, and they almost never get used. The CPPA does not just raise the number. It builds the machinery to impose it through a dedicated Personal Information and Data Protection Tribunal that hears the Commissioner's recommendations. The OPC investigates and recommends a penalty; the Tribunal has the final say on whether to impose one and how large it should be. That separation is deliberate, and it makes the threat credible in a way PIPEDA never managed.

If your business has global revenue in the tens of millions, a 3% exposure is not a rounding error. It is a number that justifies a privacy program on its own.

New Rights and Duties You Will Have to Honour

The CPPA hands individuals tools they do not meaningfully have under PIPEDA. The four that matter most:

  • Data mobility. People could request that their information move from one organization to another, where a data mobility framework applies. You would need to export structured personal data on demand.
  • Disposal on request. Individuals could ask you to delete their information, subject to limited exceptions. "We don't really know everywhere it lives" stops being an acceptable answer.
  • Algorithmic transparency. Where you use an automated decision system to make a prediction or decision about someone that could significantly affect them, you would have to explain it on request. This quietly drags every business using AI scoring or automated approvals into scope.
  • Plain-language consent. Consent must be meaningful, and the information you provide to obtain it has to be understandable to the people you are asking. Buried thirty-page policies will not cut it.

There are new accountability duties too. You would have to maintain a privacy management program and make it available to the Commissioner on request. That program is not a binder you write once. It is documented policies, a record of what data you hold and why, and evidence that you actually follow your own rules.

Quebec Already Showed Us the Future

Want to know what enforcement looks like once the rules grow teeth? Look at the Commission d'accès à l'information, Quebec's privacy regulator. Law 25 phased in from 2022 through 2024. Its administrative monetary penalties reach up to $10 million or 2% of worldwide turnover, while the most serious penal offences carry fines up to $25 million or 4% of worldwide turnover, whichever is greater. The CAI has been active. Appointing a person responsible for privacy became mandatory, breach reporting got formalized, and businesses operating in Quebec had to publish governance policies and run privacy impact assessments for new projects that handle personal information.

The companies that treated Law 25 as a fire drill scrambled. The ones that built a real program find the CPPA's likely requirements look familiar, because Ottawa borrowed heavily from the Quebec playbook. If you already operate in Quebec and took Law 25 seriously, you are most of the way to CPPA readiness. If you ignored it because "we're not really a Quebec company," that gap is about to get expensive twice over.

The Day-Zero Advantage Is Real

Here is the strategic point most coverage misses. When a major compliance regime takes effect, there is a brutal scramble. Consultants get booked solid and their rates spike. Law firms triage their biggest clients first, and everyone else waits. The businesses that come out ahead are the ones that did the unglamorous work before the deadline existed.

You do not need the final text of the CPPA to start. The foundations are stable and useful no matter what passes. Three moves you can make right now:

Map your data. You cannot honour a deletion request, a mobility request, or a transparency request if you do not know what personal information you hold, where it lives, and who you share it with. A current data inventory is the single highest-leverage thing a Canadian business can build today. Law 25 already requires it, the CPPA would require it, and it makes breach response faster either way.

Fix your consent flows. Audit every point where you collect personal data. Is the purpose clear? Is the language plain? Are you collecting more than you need? The CPPA's appropriate-purposes test and Quebec's data-minimization expectations both punish over-collection.

Stand up a real privacy management program. Appoint someone accountable. Write down your policies. Document your retention schedule. Run an assessment on any new project that touches personal data. This is the deliverable a regulator can demand, and it is the thing that takes longest to fake after the fact.

Most Canadian businesses are not going to hire a $500,000 enterprise consultant for this, and they shouldn't have to. The work is structured and repeatable: inventory, assess, document, monitor. The companies that operate without an in-house privacy team need tooling that does the heavy lifting and keeps a record they can hand to a regulator.

That is the gap Valdra's Bill C-27 readiness tracker was built to fill, so you can see exactly where you stand against the CPPA's likely requirements and close the gaps before the law forces your hand.

Bill C-27 CPPAConsumer Privacy Protection ActPIPEDA reformCanadian privacy lawCPPA compliancePIPEDA fines

AI governance and privacy compliance, simplified.

Valdra helps Canadian companies govern AI and meet PIPEDA and Law 25 — hosted in Canada.

Try Valdra

Our own compliance

We run our own compliance programme inside Valdra — the product we sell. Our SOC 2, ISO 27001 and ISO 42001 programmes are actively in progress; we do not claim certifications we do not yet hold.

Valdra compliance badge — click to verify
  • PIPEDA
  • Law 25 (Quebec)
  • CASL
  • Data hosted in Canada 🇨🇦
  • AI governance
View our Trust Centre

Self-declared, not audited by a third party. Click the badge to verify it is genuine and see what it covers.

Bill C-27 CPPA: How to Prepare Your Business | Valdra