What happened to Bill C-27

Bill C-27 was the federal government's big privacy modernisation package. It bundled three things together: the Consumer Privacy Protection Act, which would have replaced the core of our current privacy law; a new tribunal to hear appeals and levy penalties; and the Artificial Intelligence and Data Act, Canada's first serious attempt to regulate AI. It spent a long time in committee, generated an enormous amount of debate, and then ran straight into Canadian parliamentary reality.

When Parliament was prorogued on 6 January 2025, every bill still in progress died on the order paper. That is simply how prorogation works — unfinished legislation does not pause, it ends, and has to be reintroduced from scratch in a new session. C-27 was one of the casualties. A federal election followed, and for well over a year Canada had no active federal privacy reform bill at all. All that work, gone.

I mention the mechanics because they matter for how you should think about any bill in the news. A bill is not a law. It is a proposal, and until it clears the full process it can vanish overnight for reasons that have nothing to do with its merits. That is the lesson of C-27, and it is worth remembering as C-36 makes its way through the same gauntlet.

What actually governs your website today

Here is the reassuring part, and the part too many breathless articles skip: while the reform bills came and went, the actual law never disappeared. The Personal Information Protection and Electronic Documents Act — PIPEDA — has been Canada's federal private-sector privacy law the entire time, and it still is. Nothing about C-27 dying reduced your obligations. If your business collects personal information from customers across provincial or national borders, PIPEDA applies to you today exactly as it did in 2023.

That means the fundamentals I have written about elsewhere are unchanged: you need a genuine reason to collect personal information, you need meaningful consent, you need to tell people what you are doing through an honest privacy policy, you need to protect the data you hold, and you need to report serious breaches. None of that is on hold pending reform.

And if you deal with anyone in Quebec, the stricter law has been in force the whole time regardless of what Ottawa does. Quebec's Law 25 is fully in effect, it is the toughest privacy regime in the country, and it applies to any business that handles the personal information of Quebec residents — not just businesses located in Quebec. For a lot of Canadian websites, Law 25 is already the real compliance bar, and the federal drama is a sideshow to it. I have covered Law 25 in its own article, and it deserves your attention more than any bill that has not passed.

Bill C-36: the new attempt

On 15 June 2026, the government tabled Bill C-36, the Protecting Privacy and Consumer Data Act. It is the third serious run at replacing PIPEDA, and it is the government's answer to everything that went wrong with C-27. If it passes, it would replace the core privacy part of PIPEDA with a modernised framework that borrows heavily from Europe's GDPR and from Quebec's Law 25 — which is to say, it pulls federal law toward the stricter standard rather than away from it.

C-36 learned two clear lessons from C-27's collapse. The first is about structure. C-27 tried to create a separate tribunal to sit between the Privacy Commissioner and the courts, which critics found clunky. C-36 instead sets up a single integrated regulator — a Digital Safety and Data Protection Commission of Canada — to oversee privacy directly. One body, clearer lines of authority.

The second lesson is about scope. C-27's biggest political problem was that it welded AI regulation onto privacy reform, and the AI piece was contentious enough to bog down the whole bill. C-36 deliberately leaves AI out of the privacy law. Artificial intelligence is being handled through separate legislation rather than bundled in. Whatever you think of that on the merits, it is a smart tactical move: it stops the most divisive part from sinking the rest.

The crucial caveat: as of this writing, C-36 is at first reading only. That is the very beginning of the process. It still has to pass second reading, survive committee study where it will likely be amended, pass third reading, clear the Senate, and receive royal assent. Any of those stages can change it or stall it. So C-36 tells you the direction of travel with real confidence — but it does not yet tell you the final rules, and it is not something you comply with today.

What is genuinely new in C-36

Even in draft form, C-36 signals where Canadian privacy law is heading, and the direction is worth internalising because these ideas are not going away even if this particular bill does.

Stronger individual rights. The bill introduces a right for people to request deletion of their personal information, and data mobility rights that let individuals move their data to another organisation. These are GDPR-style rights that Canadians increasingly expect to have, whether or not the statute grants them yet.

Inferred data counts as personal information. This is a meaningful modernisation. The bill makes clear that information a business infers about someone — the output of profiling, analytics, or AI systems — is personal information, not some lesser category. If you build a profile of a customer from their behaviour, that profile is their data.

Rules around automated decisions. Where a business uses automated systems to make significant decisions about people, the bill gives individuals a right to an explanation and a right to make written representations to an actual human. As more small businesses lean on automated tools, this becomes relevant to more of them.

Stronger protection for children and sensitive data. C-36 builds in enhanced safeguards for the personal information of people under 18 and for sensitive categories of information, echoing a global trend toward treating children's data as deserving special care.

Assessments before sending data across the border. The bill would require privacy impact assessments before transferring personal information outside Canada — which touches a lot of small businesses without them realising, because using an American cloud service or email provider is a cross-border transfer.

Underpinning all of these is a shift in the basic test. Rather than leaning on long consent forms nobody reads, the bill measures collection and use against what a reasonable person would consider appropriate in the circumstances — a standard borrowed from Quebec and Europe. It asks whether what you are doing with someone's data is actually reasonable, not merely whether they clicked a box that said "I agree." Paired with a single regulator that has real investigatory power and the penalties below, that is a meaningful change in posture. Privacy stops being a paperwork exercise you can satisfy with a dense policy nobody reads, and becomes a question of whether your data practices could survive being looked at by someone whose job is to look at them. For most small businesses that is a healthier way to think about it anyway.

The penalties are the headline

The reason this reform gets attention in boardrooms is the money. PIPEDA today has famously weak enforcement — the Privacy Commissioner can investigate and make recommendations, but the direct financial consequences for most businesses are minimal. C-36 changes that dramatically. It proposes administrative penalties of up to the greater of ten million dollars or three percent of a company's global gross revenue, and for the most serious offences, criminal penalties reaching the greater of twenty-five million dollars or five percent of global revenue.

Those numbers are deliberately modelled on the GDPR, and they change the calculation completely. Under the old regime, some businesses treated privacy as a low-risk area to cut corners on because the downside was a stern letter. Under a law with GDPR-scale fines, privacy becomes a genuine financial risk that a prudent owner has to manage. I would not lose sleep over the maximums — those are reserved for egregious cases — but the existence of real penalties is what will finally make Canadian privacy compliance something businesses take as seriously as their EU counterparts do.

What to do while the law is still moving

The trap here is to do one of two unhelpful things: panic about a bill that is not law, or shrug and wait to see if it passes. Neither is right. The productive move is to recognise that C-36, Law 25, the GDPR, and even C-27 before it all point in the same direction, and to get your house in order along that shared direction. Almost nothing you would do to prepare is wasted even if C-36 changes or dies.

Practically, that means a handful of things. Make sure your privacy policy is honest and specific rather than a copied template — that is already a PIPEDA requirement, not a future one. Know what personal information you collect and why, and stop collecting what you do not need. Map where your data goes, especially across the border into US-based services, because cross-border transfers are getting more scrutiny, not less. If you use any automated or AI-driven tools to make decisions about customers, start being able to explain them. And if you touch Quebec residents at all, meet Law 25 now, because it is the real, in-force, strict standard and it is the best proxy available for where the whole country is heading.

This is the kind of unglamorous groundwork I help clients with, and the pitch is simple: doing it steadily now, along the direction every one of these laws agrees on, is far cheaper and calmer than scrambling to comply the month a bill finally receives royal assent. You are not chasing a moving target. You are building toward a destination that all the signposts point to.

The bottom line

Canadian privacy law in 2026 looks chaotic if you watch the bills, and stable if you watch the obligations. C-27 died; C-36 arrived; C-36 is not law yet and may change. Meanwhile PIPEDA still governs your website, Quebec's Law 25 still binds anyone who touches Quebec data, and the direction of every serious reform — stronger individual rights, transparency about automated decisions, real penalties, a stricter European-style standard — has been consistent for years.

So do not build your compliance around whichever bill is currently in the headlines. Build it around the destination they all share. Be honest about what you collect, protect it properly, tell people the truth about it, and treat the strictest standard that applies to you as the baseline. Do that, and it will not matter much whether the bill this year is called C-27, C-36, or something else entirely the next time Parliament restarts the clock.