TL;DR: Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) is being replaced by the Consumer Privacy Protection Act (CPPA) — Part 1 of Bill C-27 (Digital Charter Implementation Act, 2022). The CPPA gives Canadians stronger rights over their personal data and imposes new obligations on businesses, including explicit consent rules, mandatory privacy management programs, and fines of up to $25 million CAD or 5% of global annual revenue. Every private-sector organization that collects or uses personal information in Canada must prepare now.
From PIPEDA to CPPA: Why Canada's Privacy Law Needed an Overhaul
Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) came into force in 2001 — before smartphones, social media, or cloud computing defined how businesses collect data. For over two decades, it served as the foundation of private-sector privacy law, but its principles-based, flexible approach left enforcement toothless and compliance expectations vague.
Bill C-27, tabled in June 2022, responds to two urgent pressures. The European Union's General Data Protection Regulation (GDPR) raised global expectations for privacy rights, and Canadians repeatedly ranked data privacy as a top public concern in Office of the Privacy Commissioner of Canada (OPC) surveys. The Consumer Privacy Protection Act (CPPA) — Part 1 of Bill C-27 — is not a patch on PIPEDA; it is a structural replacement.
The CPPA applies to private-sector organizations subject to federal jurisdiction that collect, use, or disclose personal information in the course of commercial activity. Provincial privacy laws (Alberta PIPA, British Columbia PIPA, Québec Law 25) remain in force where substantially similar, but the CPPA creates a national floor for every business operating across provinces.
New Individual Rights Canadians Will Hold Under the CPPA
The CPPA introduces a set of individual rights that PIPEDA either lacked entirely or treated as aspirational guidance. Businesses need to build systems capable of honouring these rights within defined response timelines.
Right to erasure (disposal of personal information): Under proposed section 55 of the CPPA, individuals can request that an organization delete or de-identify their personal data once the original purpose for collection has expired. PIPEDA contained no equivalent provision. Organizations must have a documented deletion workflow before the CPPA comes into force.
Explanation of automated decisions: Where an organization makes a prediction, recommendation, or decision about an individual using an automated system — credit scoring, insurance pricing, hiring algorithms — the CPPA requires businesses to explain, upon request, how that decision was made and what data was used (proposed s. 63). This aligns with similar provisions in Québec's Law 25 (Act 25), which has been in force since September 2023.
Data portability: Canadians will be able to request a machine-readable copy of their personal information and have it transmitted to another organization. This right enables competitive switching between service providers — a direct parallel to GDPR Article 20 — and requires businesses to invest in standardized data export formats.
Right to withdraw consent: Consent withdrawal under PIPEDA was implicit and often buried in privacy policies. The CPPA makes withdrawal explicit: individuals must be able to withdraw at any time without penalty, and withdrawal must be straightforward and prominently disclosed.
Consent Under the CPPA: Explicit, Granular, and Harder to Bypass
PIPEDA's consent model was notoriously flexible. Organizations could rely on implied consent for routine data collection and bury the details in multi-page privacy policies that most users never read. The CPPA closes these gaps.
Express consent is the new default for sensitive data. The CPPA requires express (opt-in) consent for the collection, use, or disclosure of sensitive personal information — defined broadly to include health, financial, biometric, and location data. Implied consent remains permissible only in narrow circumstances where the purpose is obvious and the individual would reasonably expect it.
Plain-language requirement: Consent must be sought in plain language that an ordinary person can understand. The OPC has consistently found that legalese-heavy privacy policies do not constitute meaningful consent. Under the CPPA, this becomes a compliance requirement, not a recommendation.
No bundled consent: Businesses can no longer bundle consent for multiple purposes into a single checkbox. Each distinct purpose — analytics, marketing, profiling, third-party sharing — must be consented to separately. This mirrors the approach mandated under Québec Law 25, which regulators have begun actively enforcing since September 2023.
"Organizations that have treated consent as a checkbox exercise are going to find the CPPA unforgiving. The law is designed to require genuine choices, not manufactured ones." — Privacy counsel specializing in Canadian technology law [paraphrased from OPC compliance guidance, 2024]
À retenir: Under the CPPA, collecting personal data without valid, purpose-specific consent is not a technical breach — it is an offense subject to the Act's highest penalty tier.

New Organizational Obligations: Privacy Management Programs
The CPPA shifts accountability from reactive (respond to complaints) to proactive (demonstrate compliance before problems arise). Every organization subject to the Act must implement a Privacy Management Program (PMP) — a written, operational framework covering policies, training, controls, and risk assessment.
What a Privacy Management Program Must Include
A compliant PMP under the CPPA must address at minimum:
- Data inventory and mapping: A documented record of every category of personal information collected, its purpose, retention period, and the third parties it is shared with.
- Privacy risk assessment: A formal Privacy Impact Assessment (PIA) for any new product, service, or system involving high-risk processing — automated decision-making, large-scale profiling, cross-border transfers.
- Employee training: Documented training for all staff who handle personal information, with records of completion.
- Breach response plan: A defined incident response procedure specifying internal escalation, OPC notification (within the prescribed period), and individual notification where there is a real risk of significant harm.
- Accountability officer: Designation of an individual responsible for compliance — equivalent to a Data Protection Officer (DPO) under the GDPR.
Scenario: A mid-size Toronto e-commerce retailer currently collects email, shipping addresses, and browsing behaviour for "marketing purposes." Under PIPEDA, a single privacy policy covering all three was sufficient. Under the CPPA, the retailer must separate the consents, produce a PIA for its behavioural profiling, document its data retention schedule, and name a privacy officer — before the Act comes into force.
Enforcement and Penalties: What Non-Compliance Actually Costs
The CPPA creates a two-tier enforcement architecture that gives the Office of the Privacy Commissioner of Canada (OPC) teeth it has never had under PIPEDA.
The OPC's Expanded Powers
Under PIPEDA, the Commissioner could only make non-binding recommendations. Enforcement required the Commissioner to take organizations to Federal Court — a slow, expensive process that deterred most investigations. The CPPA changes this fundamentally:
- Order-making power: The Commissioner can issue binding orders requiring organizations to stop or change processing practices.
- Recommendation to the Privacy Tribunal: For serious violations, the Commissioner refers cases to a newly created Personal Information and Data Protection Tribunal, which has authority to impose Administrative Monetary Penalties (AMPs).
- Public interest investigations: The OPC can initiate investigations without a complaint if it has reasonable grounds to believe the Act has been violated.
The Financial Stakes
The CPPA creates two penalty tiers:
| Violation tier | Maximum penalty |
|---|---|
| Serious offences (e.g., failure to implement PMP, wilful non-compliance) | Lesser of $25M CAD or 5% of global annual gross revenue |
| Less serious offences (e.g., procedural, record-keeping) | Lesser of $10M CAD or 3% of global annual gross revenue |
These numbers place the CPPA in the same league as the GDPR and significantly above what Québec Law 25 currently imposes. For a Canadian business with $200M in global revenue, a serious violation could cost $10M CAD — and reputational damage from a publicized Privacy Tribunal ruling would compound the financial impact.
Additionally, the CPPA introduces a private right of action: individuals who suffer harm as a result of a violation of the Act — after the Tribunal finds against an organization — can sue for damages in Federal Court. This creates a class-action exposure that PIPEDA entirely lacked.

Cross-Border Data Transfers and Third-Party Obligations
Many Canadian businesses transfer personal data to vendors, cloud providers, or parent companies outside Canada. The CPPA tightens the rules for these transfers without prohibiting them outright.
Under proposed section 62 of the CPPA, an organization that transfers personal information to a third party for processing — including offshore processors — remains accountable for the protection of that information. This means:
- Contractual safeguards are mandatory. Transfer agreements must require the processor to provide equivalent privacy protection, notify the transferring organization of any breach, and permit audits.
- Individuals must be informed. Privacy notices must disclose that personal information may be transferred to processors in other countries, and specify the jurisdictions involved where known.
- De-identification before transfer. Where the purpose permits, organizations should de-identify data before transferring it to third parties. The CPPA treats de-identified information as outside the scope of the Act as long as re-identification safeguards are maintained.
Canadian cloud-dependent businesses — particularly those using US-based SaaS providers for CRM, HR, or payroll — will need to review and update their data processing agreements before the CPPA comes into force.
A Practical CPPA Compliance Roadmap for Canadian Businesses
The legislative timeline for Bill C-27 has moved through Senate committee study. Organizations should not wait for Royal Assent — the compliance gap between current PIPEDA practices and CPPA requirements is significant, and experienced privacy counsel in Canada consistently recommend beginning preparation now.
Phase 1 (Months 1-3): Audit and Map
- Conduct a data inventory. Identify every category of personal information collected, the legal basis for collection, storage location, retention period, and third-party recipients.
- Assess consent mechanisms. Review all consent flows — website cookies, account registration, marketing opt-ins — against the CPPA's express consent and plain-language requirements.
- Identify high-risk processing. Flag any automated decision-making, profiling, or sensitive data processing that will require a Privacy Impact Assessment.
Phase 2 (Months 4-6): Build the Program
- Draft your Privacy Management Program. Use the OPC's Privacy Management Program guidance as a template.
- Update your privacy policy and consent language. Separate purposes, use plain language, and ensure withdrawal mechanisms are visible.
- Appoint or designate a privacy officer. This person must have authority to make compliance decisions and escalate to senior leadership.
Phase 3 (Months 7-12): Test and Train
- Run tabletop breach simulations. Test your incident response plan before a real breach forces you to improvise.
- Train all staff who handle personal data. Document training completion — the OPC will ask for records during investigations.
- Audit third-party data processors. Update contracts with cloud vendors, analytics providers, and offshore processors to meet CPPA accountability requirements.
À retenir: Québec organizations that achieved Law 25 compliance by September 2023 have a head start — the CPPA is broadly aligned with Québec's framework, and much of the infrastructure built for Law 25 (consent banners, PIAs, privacy officers) carries over directly.
Frequently Asked Questions About the CPPA and PIPEDA Replacement
What is the main difference between PIPEDA and the CPPA? The CPPA replaces PIPEDA's flexible, principles-based framework with specific, binding obligations — mandatory Privacy Management Programs, express consent for sensitive data, explicit individual rights (erasure, portability, automated decision explanation), and real enforcement powers including fines up to $25M CAD or 5% of global revenue.
When does the CPPA come into force? Bill C-27 is advancing through Parliament as of 2026. The CPPA does not have a fixed in-force date yet — it comes into force on a date set by the Governor in Council following Royal Assent. Organizations should treat implementation as imminent and begin compliance work now. Monitor the Office of the Privacy Commissioner of Canada (OPC) website (priv.gc.ca) for updates.
Does the CPPA apply to small businesses? Yes. Unlike the GDPR, which has limited exemptions for small enterprises, the CPPA applies to any private-sector organization that collects, uses, or discloses personal information in the course of commercial activity — regardless of size. The OPC has discretion in prioritizing enforcement, but small businesses that suffer a data breach will not be insulated from the Act's requirements.
How does the CPPA interact with Québec's Law 25? Québec Law 25 (Act respecting the protection of personal information in the private sector) has been progressively enforced since September 2022. The CPPA is broadly aligned with Law 25's approach — both require privacy officers, Privacy Impact Assessments, data portability, and express consent for sensitive data. Organizations that achieved Law 25 compliance are well-positioned for CPPA compliance, though legal review of the specific differences is recommended.
What is the private right of action under the CPPA? After the Privacy Tribunal makes a finding of violation against an organization, affected individuals can bring a civil action in Federal Court for damages. This creates potential class-action exposure — a major departure from PIPEDA, under which individuals had no direct right to sue.
Disclaimer: The information on this page is provided for general informational purposes and does not constitute legal advice. The CPPA is subject to legislative amendment before and after Royal Assent. Consult a qualified Canadian privacy lawyer for advice specific to your organization's situation.

Clara Dubois
