Basenews
Published on 26 August 2026 par David Beauchemin, Ph. D.
A Quebec logistics company discovered that its pricing algorithm systematically disadvantaged certain rural regions, without anyone internally being able to explain why. This type of situation perfectly illustrates the issues that Bills C-27 and C-36 seek to regulate: the protection of personal information and the accountability of artificial intelligence (AI) systems in the private sector.
Tabled in June 2022 by the Minister of Innovation in the House of Commons, Bill C-27 represented the most ambitious reform of Canadian privacy legislation since the adoption of PIPEDA in 2000. It died on the Order Paper during the parliamentary prorogation in January 2025. On June 15, 2026, the government tabled Bill C-36, a third attempt at reform. C-36 retains the core of the CPPA, but abandons standalone AI regulation.
In this article, we explain what Bill C-27 provided for the protection of personal information and AI regulation, why it died on the Order Paper in January 2025, and what its successor, Bill C-36 (tabled on June 15, 2026), concretely changes for your organization. We also provide practical tips to anticipate compliance right now.
Bill C-27 was not limited to a simple update of consumer privacy legislation. It introduced an entirely new framework for regulating AI in Canada, a first in Canadian legislative history. This bill consisted of three distinct acts, each serving a specific role in protecting the rights of Canadians:
| Act | Acronym | Main Purpose |
|---|---|---|
| Consumer Privacy Protection Act | CPPA | Replaces PIPEDA for the private sector. Strengthens individual rights and obligations of organizations handling personal information. |
| Artificial Intelligence and Data Act | AIDA | First Canadian federal framework dedicated to AI. Regulates commercial "high-impact" systems in the private sector. |
| Personal Information and Data Protection Tribunal Act | N/A | Creates an independent tribunal to hear appeals of Commissioner decisions and impose penalties. |
Bill C-27 died on the Order Paper in January 2025: it has no current legal force. Without this bill, federal PIPEDA (2000) and provincial laws, including Law 25 in Quebec, apply. However, the directions set out in C-27 remain a clear signal of where Canadian regulation is headed, and the government tabled Bill C-36 on June 15, 2026, at first reading. This new bill drops AIDA and focuses on consumer privacy protection via the CPPA.
Understanding where Bill C-27 stands in the Canadian parliamentary process is essential for evaluating the urgency to act. Here are the key milestones of this bill since its introduction in the House of Commons.
| Stage | Date | Details |
|---|---|---|
| First Reading Table | June 2022 | The Minister of Innovation introduces Bill C-27 in the House of Commons during the 44th Parliament. |
| Second Reading and Debate | 2022–2023 | General debates on the principle of the bill. Bipartisan criticism regarding certain provisions of AIDA. |
| Referred to Standing Committee | November 2023 | Bill C-27 is referred to the Standing Committee on Industry and Technology for clause-by-clause study. |
| Committee Study | 2023–2024 | The Standing Committee holds numerous hearings, hears experts, and proposes substantial amendments to AIDA. |
| Died on the Order Paper | January 2025 | Parliamentary prorogation ends the session. Bill C-27 dies on the Order Paper. PIPEDA remains the applicable law. |
| Bill C-36 Tabled | June 2026 | On June 15, 2026, Minister Evan Solomon tables Bill C-36, proposing the Consumer Privacy and Data Protection Act (CPPA). Unlike C-27, C-36 does not include an AI legislative framework. It is at first reading. |
Bill C-27 was subjected to thorough scrutiny by the House of Commons Standing Committee on Industry and Technology. Key criticisms centred on the lack of clarity in defining high-impact AI systems, the expansive powers of the AI Commissioner, and the absence of explicit references to fundamental rights in the text of the law.
Since the tabling of Bill C-36 on June 15, 2026, a successor to C-27 is undergoing parliamentary review. It retains the essence of the CPPA but takes a different approach: no AIDA, a new regulator (the Canadian Digital Safety and Data Protection Commission), and AI oversight limited to automated decision-making within privacy law. In Quebec, Law 25 is already in effect. Organizations that have begun complying with it are well-positioned for C-36 as well.
The Consumer Privacy Protection Act (CPPA) introduces rights that Canadians do not yet have under current federal legislation, but which Quebec residents are already familiar with thanks to Law 25. These rights protect privacy in the digital economy:
For private sector organizations, these rights translate into concrete obligations: mapping collected data, documenting the legal basis for processing personal information, and establishing mechanisms to respond to access requests within strict timelines.
The Artificial Intelligence and Data Act (AIDA) is the cornerstone of Bill C-27 for technology companies. It introduces the central concept of "high-impact AI systems": any system whose decisions or recommendations can have significant repercussions on a person's health, safety, or fundamental rights and freedoms. AIDA targets commercial activities exclusively. Governmental and national security activities remain outside its scope.
A standard customer service chatbot will likely not be considered a high-impact system. On the other hand, an algorithm that decides whether to grant or deny a loan, or that filters job applications, very likely falls into this regulated category.
The CPPA modernizes PIPEDA, the 2000 law governing personal information protection in the private sector, whose fines currently cap at $100,000 for willful infractions. The CPPA draws heavy inspiration from the European GDPR while retaining a Canadian risk-management approach rather than an exhaustive list of prescriptive obligations.
| Offence Type | Maximum Proposed Penalty | Comparison with Current PIPEDA |
|---|---|---|
| Serious offences (unauthorized use, failure to report breach) | Higher than $25M or 5% of global revenue | vs. $100,000 maximum today |
| Less serious offences (procedural lapses, records) | Higher than $20M or 4% of global revenue | vs. $100,000 maximum today |
For a Quebec SME with an annual turnover of $10M, a serious violation under Bill C-27 could theoretically result in a $500,000 penalty. It is no longer a theoretical risk.
Important note: Bill C-36, tabled in June 2026 to succeed C-27, does not include a separate AI act. The AIDA described below is specific to C-27 and serves as a reference for understanding what was proposed. AI regulation in C-36 is handled through automated decision-making provisions in the CPPA.
The Artificial Intelligence and Data Act is the first Canadian federal law regulating AI in the private sector. This legislative framework applies to organizations that design, develop, market, or operate AI systems in the context of commercial activities. The law also creates a new AI Commissioner equipped with investigative and oversight powers.
AIDA targets commercial interprovincial or international activities exclusively. Governmental and national security activities are outside its scope. The commercial sectors most likely to be affected include:
Under C-27, AIDA would have created an AI Commissioner with investigation, audit, and sanction recommendation powers, able to compel record production, order the shutdown of problematic systems, and refer cases to the Tribunal. This role was one of the most criticized points in committee due to the breadth of its powers. C-36 does not include this position: privacy oversight is entrusted to the Canadian Digital Safety and Data Protection Commission.
Under C-27, this Tribunal would have served two functions: providing an appeal mechanism for Commissioner decisions and imposing administrative monetary penalties. C-36 abandons this model; these functions are entrusted to the Canadian Digital Safety and Data Protection Commission, a new body whose members are appointed by the Governor in Council rather than Parliament.
The widespread adoption of generative AI tools (ChatGPT, Microsoft Copilot, Google Gemini, GitHub Copilot) in Canadian companies raises specific questions that Bills C-27 and C-36 help address.
When an employee uses ChatGPT to draft customer communications, or Microsoft Copilot accesses an organization's internal emails and documents, personal information of customers, partners, or employees is potentially processed by a third-party system. Bill C-36, replacing C-27, regulates these uses via its automated decision-making and legitimate interest provisions rather than a dedicated AI act. Under Bill C-27, this triggers several obligations:
Submitting personal data of customers, employees, or partners to a generative AI tool without prior assessment is an immediate compliance risk, even under current PIPEDA and Law 25. Data protection authorities in Europe and Canada have opened investigations into OpenAI's collection practices.
For anyone who has navigated the European Union's General Data Protection Regulation, Bill C-27 feels like a Canadian cousin, albeit with notable differences.
| Aspect | GDPR (European Union) | C-27 / CPPA (Canada) |
|---|---|---|
| Individual rights | Access, rectification, erasure, portability, objection | Access, rectification, disposal, portability. Similar rights |
| Consent | Legitimate interest possible without explicit consent | Consent generally required; "legitimate commercial interests" (LCI) more restricted |
| AI Regulation | European AI Act, separate regulation adopted in 2024 | C-27: Integrated AIDA (dedicated AI regulation). C-36: Regulation via automated decisions in CPPA (no separate AI act) |
| Maximum penalties | Up to 4% of global turnover | Up to 5% of global turnover (more severe) |
| Supervisory authority | One per Member State (e.g., CNIL in France) | C-27: Privacy Commissioner + AI Commissioner + Tribunal. C-36: Canadian Digital Safety and Data Protection Commission |
| Extraterritorial application | Yes, for non-EU companies processing EU residents' data | Yes, similar scope for personal information of Canadian residents |
The United States lacks a federal privacy framework. For Canadian organizations exporting there, compliance with C-27 facilitates relations with European partners subject to the GDPR.
The Act modernizing legislative provisions as regards the protection of personal information (Law 25) is already in effect in Quebec. It imposes the following obligations on any organization holding personal information of Quebec residents: designation of a Privacy Officer, published privacy policy, mandatory incident reporting, access and rectification rights. Quebec organizations compliant with Law 25 are well-positioned for Bill C-36 as well.
Bill C-27 impacts SMEs as much as large enterprises. SMEs collecting customer personal information, using behavioral analytics, or deploying recommendation tools are directly affected.
An AI system trained on historical data reflects the bias inherent in that data. If past decisions underrepresented certain groups, your AI system will replicate that pattern, and you will be held legally responsible under AIDA. Evaluating bias is a legal obligation for high-impact systems.
When an AI system makes a decision that significantly affects an individual (credit refusal, candidate elimination, insurance premium modification), that person will have the right to request an explanation and contest the decision. Fundamental rights of individuals facing automated systems are at the core of AIDA.
Before you can protect personal information, you must know where it is, who has access to it, why it was collected, and how long it is retained. Practical implementation steps include:
With Bill C-36 tabled on June 15, 2026 (the third reform attempt in six years), the direction is clear: Canadian private sector organizations will need to comply with heightened requirements regarding personal information protection. C-36 retains the core of C-27 while dropping AIDA. AI regulation is addressed through provisions on automated decision-making and impact assessments (Sources: Fasken, Norton Rose Fulbright, Canada.ca).
In the meantime, Law 25 in Quebec already mandates many of these obligations. Organizations that have complied possess a significant head start on future requirements under Bill C-36. Compliance is not merely a cost: it builds trust, protects reputation, and provides a sustainable competitive advantage in a market where AI ethics are increasingly scrutinized.
Organizations that anticipate by mapping their personal information, evaluating their generative AI systems, training their teams, and adopting privacy by design will be ready on day one and gain a genuine competitive edge.
At Baseline, our team supports SMEs and organizations in the responsible integration of AI and compliance implementation: compliance assessment, personal information mapping, design of explainable and auditable AI systems, generative AI policy drafting, and team training.
The questions below primarily address Bill C-27 and its provisions. Bill C-36, tabled on June 15, 2026, modifies several elements, notably the regulatory structure and AI oversight. Differences are highlighted throughout the answers.
No. Bill C-27 died on the Order Paper in January 2025. It has no legal effect. Federal PIPEDA and Quebec's Law 25 currently apply. On June 15, 2026, the government tabled Bill C-36 (Consumer Privacy and Data Protection Act, CPPA), a direct successor to C-27, currently at first reading at the time of publication of this article.
Bill C-36, tabled on June 15, 2026, is at first reading. Its adoption timeline remains uncertain: it must pass parliamentary stages, and its entry into force is tied to creating the new Canadian Digital Safety and Data Protection Commission, itself dependent on another bill (C-34). Following the model of Law 25, a transition period of 12 to 36 months is plausible once passed.
The CPPA will apply to private sector organizations that collect, use, or disclose personal information in the course of commercial activities, covering the vast majority of Canadian businesses, including SMEs. AIDA would apply to organizations that design, develop, or operate AI systems in the course of interprovincial or international commercial activities.
Compared to PIPEDA (the 2000 personal information protection law capped at $100,000 fines), Bill C-36 (successor to C-27) introduces: data disposal and portability rights, penalties up to $25M or 5% of global revenue, mandatory breach reporting, transparency on automated decisions, and a legal definition of "sensitive" information. Key difference vs C-27: C-36 does not contain a separate AI act. Sources: Fasken, Norton Rose Fulbright.
Under C-27, the precise definition was to be established by regulation. C-36 does not include AIDA, so the concept of high impact does not appear in that exact form. Regulation of automated decisions is handled through the CPPA. General indicators: does the system significantly affect a person's fundamental rights, health, or economic situation? Does it operate in a sensitive commercial sector (health, employment, credit, housing)? Can system errors cause harm that is difficult to repair? If yes to any, a thorough analysis is needed. Important: AIDA targets commercial activities; government activities are excluded.
Priority steps: (1) map personal information collected and processed, (2) evaluate deployed AI systems, (3) update privacy policies and vendor contracts, (4) draft a generative AI use policy, (5) train staff, (6) designate a Privacy Officer, (7) integrate privacy by design into new developments. Organizations already compliant with Law 25 have completed a large part of this work.
Serious offences under Bill C-27—unauthorized personal information use, failure to report a breach, or operating a high-impact AI system without required measures—can carry penalties up to $25M or 5% of global revenue. Less serious offences are punishable by penalties up to $20M or 4% of global turnover. These penalties are imposed by the Tribunal following Commissioner recommendations. This is a radical departure from current PIPEDA fines capped at $100,000.