Basenews

Bill C-36: Understanding Canada's privacy reform and what Bill C-27 had planned for AI

Published on 26 August 2026 par David Beauchemin, Ph. D.

A Quebec logistics company discovered that its pricing algorithm systematically disadvantaged certain rural regions, without anyone internally being able to explain why. This type of situation perfectly illustrates the issues that Bills C-27 and C-36 seek to regulate: the protection of personal information and the accountability of artificial intelligence (AI) systems in the private sector.

Tabled in June 2022 by the Minister of Innovation in the House of Commons, Bill C-27 represented the most ambitious reform of Canadian privacy legislation since the adoption of PIPEDA in 2000. It died on the Order Paper during the parliamentary prorogation in January 2025. On June 15, 2026, the government tabled Bill C-36, a third attempt at reform. C-36 retains the core of the CPPA, but abandons standalone AI regulation.

In this article, we explain what Bill C-27 provided for the protection of personal information and AI regulation, why it died on the Order Paper in January 2025, and what its successor, Bill C-36 (tabled on June 15, 2026), concretely changes for your organization. We also provide practical tips to anticipate compliance right now.

Bill C-27 at a Glance

Bill C-27 was not limited to a simple update of consumer privacy legislation. It introduced an entirely new framework for regulating AI in Canada, a first in Canadian legislative history. This bill consisted of three distinct acts, each serving a specific role in protecting the rights of Canadians:

Act Acronym Main Purpose
Consumer Privacy Protection Act CPPA Replaces PIPEDA for the private sector. Strengthens individual rights and obligations of organizations handling personal information.
Artificial Intelligence and Data Act AIDA First Canadian federal framework dedicated to AI. Regulates commercial "high-impact" systems in the private sector.
Personal Information and Data Protection Tribunal Act N/A Creates an independent tribunal to hear appeals of Commissioner decisions and impose penalties.
KEY TAKEAWAY

Bill C-27 died on the Order Paper in January 2025: it has no current legal force. Without this bill, federal PIPEDA (2000) and provincial laws, including Law 25 in Quebec, apply. However, the directions set out in C-27 remain a clear signal of where Canadian regulation is headed, and the government tabled Bill C-36 on June 15, 2026, at first reading. This new bill drops AIDA and focuses on consumer privacy protection via the CPPA.

Legislative Journey of Bill C-27

Understanding where Bill C-27 stands in the Canadian parliamentary process is essential for evaluating the urgency to act. Here are the key milestones of this bill since its introduction in the House of Commons.

Stage Date Details
First Reading Table June 2022 The Minister of Innovation introduces Bill C-27 in the House of Commons during the 44th Parliament.
Second Reading and Debate 2022–2023 General debates on the principle of the bill. Bipartisan criticism regarding certain provisions of AIDA.
Referred to Standing Committee November 2023 Bill C-27 is referred to the Standing Committee on Industry and Technology for clause-by-clause study.
Committee Study 2023–2024 The Standing Committee holds numerous hearings, hears experts, and proposes substantial amendments to AIDA.
Died on the Order Paper January 2025 Parliamentary prorogation ends the session. Bill C-27 dies on the Order Paper. PIPEDA remains the applicable law.
Bill C-36 Tabled June 2026 On June 15, 2026, Minister Evan Solomon tables Bill C-36, proposing the Consumer Privacy and Data Protection Act (CPPA). Unlike C-27, C-36 does not include an AI legislative framework. It is at first reading.

Bill C-27 was subjected to thorough scrutiny by the House of Commons Standing Committee on Industry and Technology. Key criticisms centred on the lack of clarity in defining high-impact AI systems, the expansive powers of the AI Commissioner, and the absence of explicit references to fundamental rights in the text of the law.

Since the tabling of Bill C-36 on June 15, 2026, a successor to C-27 is undergoing parliamentary review. It retains the essence of the CPPA but takes a different approach: no AIDA, a new regulator (the Canadian Digital Safety and Data Protection Commission), and AI oversight limited to automated decision-making within privacy law. In Quebec, Law 25 is already in effect. Organizations that have begun complying with it are well-positioned for C-36 as well.

What Bill C-27 Changes for Canadians

A Concrete Strengthening of Consumer Rights

The Consumer Privacy Protection Act (CPPA) introduces rights that Canadians do not yet have under current federal legislation, but which Quebec residents are already familiar with thanks to Law 25. These rights protect privacy in the digital economy:

  • Right to disposal/erasure: anyone can request that an organization delete their personal information when it is no longer necessary for the purposes for which it was collected.
  • Right to mobility/portability: individuals can request to receive their data in a structured, machine-readable format to transfer it to another service provider.
  • Enhanced control over consent: consent must be explicit for sensitive uses of personal information, and individuals can withdraw it more easily.
  • Right to contest automated decisions: anyone affected by a fully automated decision can request a human explanation and contest the decision.

For private sector organizations, these rights translate into concrete obligations: mapping collected data, documenting the legal basis for processing personal information, and establishing mechanisms to respond to access requests within strict timelines.

Canada's First AI Framework

The Artificial Intelligence and Data Act (AIDA) is the cornerstone of Bill C-27 for technology companies. It introduces the central concept of "high-impact AI systems": any system whose decisions or recommendations can have significant repercussions on a person's health, safety, or fundamental rights and freedoms. AIDA targets commercial activities exclusively. Governmental and national security activities remain outside its scope.

GOOD TO KNOW

A standard customer service chatbot will likely not be considered a high-impact system. On the other hand, an algorithm that decides whether to grant or deny a loan, or that filters job applications, very likely falls into this regulated category.

Breakdown of Bill C-27 Components

The Consumer Privacy Protection Act (CPPA)

The CPPA modernizes PIPEDA, the 2000 law governing personal information protection in the private sector, whose fines currently cap at $100,000 for willful infractions. The CPPA draws heavy inspiration from the European GDPR while retaining a Canadian risk-management approach rather than an exhaustive list of prescriptive obligations.

New Obligations for Organizations

  • Clear language privacy policy: the law requires simple and understandable communication regarding personal information collection and use practices.
  • Privacy management program: organizations must establish internal policies, designate a responsible individual, and document protection practices.
  • Privacy Impact Assessment (PIA): mandatory prior to deploying any new product or service handling sensitive personal information.
  • Breach reporting: any breach presenting a real risk of significant harm must be reported to the Privacy Commissioner and affected individuals.

Penalties That Demand Attention

Offence Type Maximum Proposed Penalty Comparison with Current PIPEDA
Serious offences (unauthorized use, failure to report breach) Higher than $25M or 5% of global revenue vs. $100,000 maximum today
Less serious offences (procedural lapses, records) Higher than $20M or 4% of global revenue vs. $100,000 maximum today

For a Quebec SME with an annual turnover of $10M, a serious violation under Bill C-27 could theoretically result in a $500,000 penalty. It is no longer a theoretical risk.

The Artificial Intelligence and Data Act (AIDA)

Important note: Bill C-36, tabled in June 2026 to succeed C-27, does not include a separate AI act. The AIDA described below is specific to C-27 and serves as a reference for understanding what was proposed. AI regulation in C-36 is handled through automated decision-making provisions in the CPPA.

The Artificial Intelligence and Data Act is the first Canadian federal law regulating AI in the private sector. This legislative framework applies to organizations that design, develop, market, or operate AI systems in the context of commercial activities. The law also creates a new AI Commissioner equipped with investigative and oversight powers.

Most Impacted Commercial Sectors

AIDA targets commercial interprovincial or international activities exclusively. Governmental and national security activities are outside its scope. The commercial sectors most likely to be affected include:

  • Human resources and algorithmic recruitment
  • Financial services: credit, insurance, automated investment
  • Healthcare and social services
  • Commerce and essential services (housing, transportation, telecommunications)
  • Large-scale digital platforms (content recommendation, targeted advertising)

Obligations for High-Impact Systems

  • Risk assessment: identify and document risks of harm prior to deploying any AI system.
  • Mitigation measures: establish concrete mechanisms to reduce identified risks, particularly algorithmic bias.
  • Ongoing monitoring: monitor system performance post-deployment and maintain monitoring data.
  • Transparency: inform individuals when interacting with a high-impact AI system.
  • Records: keep detailed documentation on systems, accessible to the AI Commissioner upon request.

The AI Commissioner: A New Watchdog

Under C-27, AIDA would have created an AI Commissioner with investigation, audit, and sanction recommendation powers, able to compel record production, order the shutdown of problematic systems, and refer cases to the Tribunal. This role was one of the most criticized points in committee due to the breadth of its powers. C-36 does not include this position: privacy oversight is entrusted to the Canadian Digital Safety and Data Protection Commission.

Personal Information and Data Protection Tribunal

Under C-27, this Tribunal would have served two functions: providing an appeal mechanism for Commissioner decisions and imposing administrative monetary penalties. C-36 abandons this model; these functions are entrusted to the Canadian Digital Safety and Data Protection Commission, a new body whose members are appointed by the Governor in Council rather than Parliament.

Generative AI in Enterprise: ChatGPT, Copilot, and Bill C-27

The widespread adoption of generative AI tools (ChatGPT, Microsoft Copilot, Google Gemini, GitHub Copilot) in Canadian companies raises specific questions that Bills C-27 and C-36 help address.

What Generative AI Use Entails Under C-27

When an employee uses ChatGPT to draft customer communications, or Microsoft Copilot accesses an organization's internal emails and documents, personal information of customers, partners, or employees is potentially processed by a third-party system. Bill C-36, replacing C-27, regulates these uses via its automated decision-making and legitimate interest provisions rather than a dedicated AI act. Under Bill C-27, this triggers several obligations:

  • Consent and transparency: if customer personal information is submitted to a generative AI system, the organization remains responsible for its use. Consent from affected individuals may be required.
  • Contracts with AI vendors: Microsoft, OpenAI, and Google are service providers under the CPPA. Data protection contractual clauses must govern these relationships.
  • Risk assessment: if a generative AI system is used for high-impact tasks such as drafting HR decisions or analyzing customer files, a risk assessment is required.
  • Hallucinations and automated decisions: results from a generative AI system must not be presented as final decisions without human oversight, especially when affecting individual rights.
WARNING

Submitting personal data of customers, employees, or partners to a generative AI tool without prior assessment is an immediate compliance risk, even under current PIPEDA and Law 25. Data protection authorities in Europe and Canada have opened investigations into OpenAI's collection practices.

Immediate Best Practices for Businesses

  • Draft an acceptable use policy for AI tools explicitly covering generative tools.
  • List approved and prohibited generative AI tools for processing personal information.
  • Train teams on cases where generative AI use requires prior data anonymization.
  • Verify privacy settings for used tools (e.g., Microsoft Copilot has an "enterprise" mode with stricter confidentiality guarantees).

Comparison with International Privacy Regulations

Parallels with the European GDPR

For anyone who has navigated the European Union's General Data Protection Regulation, Bill C-27 feels like a Canadian cousin, albeit with notable differences.

Aspect GDPR (European Union) C-27 / CPPA (Canada)
Individual rights Access, rectification, erasure, portability, objection Access, rectification, disposal, portability. Similar rights
Consent Legitimate interest possible without explicit consent Consent generally required; "legitimate commercial interests" (LCI) more restricted
AI Regulation European AI Act, separate regulation adopted in 2024 C-27: Integrated AIDA (dedicated AI regulation). C-36: Regulation via automated decisions in CPPA (no separate AI act)
Maximum penalties Up to 4% of global turnover Up to 5% of global turnover (more severe)
Supervisory authority One per Member State (e.g., CNIL in France) C-27: Privacy Commissioner + AI Commissioner + Tribunal. C-36: Canadian Digital Safety and Data Protection Commission
Extraterritorial application Yes, for non-EU companies processing EU residents' data Yes, similar scope for personal information of Canadian residents

Positioning Relative to US Laws

The United States lacks a federal privacy framework. For Canadian organizations exporting there, compliance with C-27 facilitates relations with European partners subject to the GDPR.

LAW 25: QUEBEC

The Act modernizing legislative provisions as regards the protection of personal information (Law 25) is already in effect in Quebec. It imposes the following obligations on any organization holding personal information of Quebec residents: designation of a Privacy Officer, published privacy policy, mandatory incident reporting, access and rectification rights. Quebec organizations compliant with Law 25 are well-positioned for Bill C-36 as well.

AI in the Enterprise: What You Need to Know

Impacts on SMEs and Startups

Bill C-27 impacts SMEs as much as large enterprises. SMEs collecting customer personal information, using behavioral analytics, or deploying recommendation tools are directly affected.

  • Data mapping: identify where all personal information resides within the organization.
  • Documentary governance: maintain processing records, impact assessments, and updated internal policies.
  • Third-party contracts: cloud service providers, SaaS, and marketing vendors must be contractually bound.
  • Privacy by design: integrating privacy protection right from design—a principle explicitly recognized by the CPPA—provides a structural advantage for startups.

Risks and Responsibilities Related to Enterprise AI Use

Managing Algorithmic Bias

An AI system trained on historical data reflects the bias inherent in that data. If past decisions underrepresented certain groups, your AI system will replicate that pattern, and you will be held legally responsible under AIDA. Evaluating bias is a legal obligation for high-impact systems.

Automated Decisions and Fundamental Rights

When an AI system makes a decision that significantly affects an individual (credit refusal, candidate elimination, insurance premium modification), that person will have the right to request an explanation and contest the decision. Fundamental rights of individuals facing automated systems are at the core of AIDA.

Legal and Reputational Liabilities

  • Civil liability: an individual harmed by a flawed AI system or a privacy breach could file a civil claim for damages.
  • Reputational damage: a publicized data breach or algorithmic bias incident can permanently harm brand reputation and customer trust.
  • Administrative penalties: penalties under Bill C-27 can reach up to 5% of global turnover.

Implementation Challenges for Businesses

Data Mapping: Your Starting Point

Before you can protect personal information, you must know where it is, who has access to it, why it was collected, and how long it is retained. Practical implementation steps include:

  1. Inventory all systems that collect, process, or store personal information.
  2. Document for each data flow: legal basis for processing, recipients, retention periods.
  3. Identify security gaps and processing that potentially non-complies with privacy law.
  4. Prioritize corrective actions based on risk and potential impact.

Training and Corporate Culture

  • Staff awareness: train employees to recognize personal information, breach reporting obligations, and responsible use of generative AI technologies.
  • Privacy by design: collect only necessary data, encrypt sensitive information, embed access controls into system design from inception.
  • Contract updates: updated privacy policy, data protection clauses with service providers, acceptable AI use policy.

Bill C-36 and Data Protection: Get Expert Guidance

With Bill C-36 tabled on June 15, 2026 (the third reform attempt in six years), the direction is clear: Canadian private sector organizations will need to comply with heightened requirements regarding personal information protection. C-36 retains the core of C-27 while dropping AIDA. AI regulation is addressed through provisions on automated decision-making and impact assessments (Sources: Fasken, Norton Rose Fulbright, Canada.ca).

In the meantime, Law 25 in Quebec already mandates many of these obligations. Organizations that have complied possess a significant head start on future requirements under Bill C-36. Compliance is not merely a cost: it builds trust, protects reputation, and provides a sustainable competitive advantage in a market where AI ethics are increasingly scrutinized.

KEY TAKEAWAY

Organizations that anticipate by mapping their personal information, evaluating their generative AI systems, training their teams, and adopting privacy by design will be ready on day one and gain a genuine competitive edge.

At Baseline, our team supports SMEs and organizations in the responsible integration of AI and compliance implementation: compliance assessment, personal information mapping, design of explainable and auditable AI systems, generative AI policy drafting, and team training.

Let's Discuss Your Compliance Strategy

Bill C-27: Frequently Asked Questions

The questions below primarily address Bill C-27 and its provisions. Bill C-36, tabled on June 15, 2026, modifies several elements, notably the regulatory structure and AI oversight. Differences are highlighted throughout the answers.

Is Bill C-27 in effect?

No. Bill C-27 died on the Order Paper in January 2025. It has no legal effect. Federal PIPEDA and Quebec's Law 25 currently apply. On June 15, 2026, the government tabled Bill C-36 (Consumer Privacy and Data Protection Act, CPPA), a direct successor to C-27, currently at first reading at the time of publication of this article.

What are the expected implementation timelines?

Bill C-36, tabled on June 15, 2026, is at first reading. Its adoption timeline remains uncertain: it must pass parliamentary stages, and its entry into force is tied to creating the new Canadian Digital Safety and Data Protection Commission, itself dependent on another bill (C-34). Following the model of Law 25, a transition period of 12 to 36 months is plausible once passed.

Which businesses are covered by Bill C-27?

The CPPA will apply to private sector organizations that collect, use, or disclose personal information in the course of commercial activities, covering the vast majority of Canadian businesses, including SMEs. AIDA would apply to organizations that design, develop, or operate AI systems in the course of interprovincial or international commercial activities.

What are the main changes compared to previous legislation?

Compared to PIPEDA (the 2000 personal information protection law capped at $100,000 fines), Bill C-36 (successor to C-27) introduces: data disposal and portability rights, penalties up to $25M or 5% of global revenue, mandatory breach reporting, transparency on automated decisions, and a legal definition of "sensitive" information. Key difference vs C-27: C-36 does not contain a separate AI act. Sources: Fasken, Norton Rose Fulbright.

How do you know if an AI system is "high-impact"?

Under C-27, the precise definition was to be established by regulation. C-36 does not include AIDA, so the concept of high impact does not appear in that exact form. Regulation of automated decisions is handled through the CPPA. General indicators: does the system significantly affect a person's fundamental rights, health, or economic situation? Does it operate in a sensitive commercial sector (health, employment, credit, housing)? Can system errors cause harm that is difficult to repair? If yes to any, a thorough analysis is needed. Important: AIDA targets commercial activities; government activities are excluded.

How can businesses prepare for compliance?

Priority steps: (1) map personal information collected and processed, (2) evaluate deployed AI systems, (3) update privacy policies and vendor contracts, (4) draft a generative AI use policy, (5) train staff, (6) designate a Privacy Officer, (7) integrate privacy by design into new developments. Organizations already compliant with Law 25 have completed a large part of this work.

What are the penalties for non-compliance?

Serious offences under Bill C-27—unauthorized personal information use, failure to report a breach, or operating a high-impact AI system without required measures—can carry penalties up to $25M or 5% of global revenue. Less serious offences are punishable by penalties up to $20M or 4% of global turnover. These penalties are imposed by the Tribunal following Commissioner recommendations. This is a radical departure from current PIPEDA fines capped at $100,000.

Ce site web utilise des témoins pour améliorer votre expérience de navigation
Ceci inclus les témoins essentiels nécessaires pour l'opération du site, incluant d'autres témoins utilisés pour l'usage de statistiques anonymes, pour une expérience comfortable et l'affichage de contenu personnalisé. Vous pouvez approuver les catégories désirées. Veuillez noter que selon vos réglages, certaines fonctionnalités du site pourraient être désactivées.
Ce site web utilise des témoins pour améliorer votre expérience de navigation
Ceci inclus les témoins essentiels nécessaires pour l'opération du site, incluant d'autres témoins utilisés pour l'usage de statistiques anonymes, pour une expérience comfortable et l'affichage de contenu personnalisé. Vous pouvez approuver les catégories désirées. Veuillez noter que selon vos réglages, certaines fonctionnalités du site pourraient être désactivées.
Vos préférences de témoin ont été sauvegardées.