Canadian Privacy

Bill C-27 and AIDA: What Canada Proposed for AI Regulation, and Why It Died

Bill C-27 and AIDA died on the Order Paper in January 2025 and never became law. What they proposed, what governs AI today, and where Bill C-36 stands.

Canada Compliance AI• Compliance Team
April 1, 2026
Updated September 15, 2026
4 min read
Bill C-27
AIDA Canada
CPPA Canada
AI Regulation Canada
Canadian Privacy Reform

Bill C-27 proposed a new federal private-sector privacy law and the Artificial Intelligence and Data Act (AIDA). Bill C-27 never became law. Here's what Canadian businesses need to understand.

Last updated: September 2026

What Bill C-27 Proposed

Bill C-27, the Digital Charter Implementation Act, 2022, was a government bill in the 44th Parliament. According to the summary in the bill text, it had three parts:

  • Part 1 would have enacted the Consumer Privacy Protection Act (CPPA) to govern the protection of personal information in the course of commercial activities. It would have repealed Part 1 of PIPEDA and changed that Act's short title to the Electronic Documents Act.
  • Part 2 would have enacted the Personal Information and Data Protection Tribunal Act, establishing an administrative tribunal to hear appeals of certain Privacy Commissioner decisions under the CPPA and to impose penalties for contraventions of certain CPPA provisions.
  • Part 3 would have enacted the Artificial Intelligence and Data Act (AIDA) to regulate international and interprovincial trade and commerce in artificial intelligence systems, by requiring certain persons to adopt measures to mitigate risks of harm and biased output related to high-impact AI systems.

According to the same summary, AIDA would also have provided for public reporting, authorized the Minister to order the production of records related to artificial intelligence systems, and established prohibitions related to the use of illegally obtained personal information for artificial intelligence systems and to making available AI systems whose use causes serious harm to individuals.

Legislative History

From LEGISinfo, Bill C-27 (44-1):

  • June 16, 2022: First reading in the House of Commons
  • April 24, 2023: Second reading and referral to committee
  • Consideration in committee: Not completed
  • January 6, 2025: The session ended. Parliament was prorogued, Bill C-27 died on the Order Paper, and it never became law.

AIDA is not law and is not pending. It died with Bill C-27.

What Comes Next: Bill C-36

Federal privacy reform was re-introduced as Bill C-36, An Act to enact the Protecting Privacy and Consumer Data Act, to amend the Personal Information Protection and Electronic Documents Act and to make amendments to other Acts. It was introduced and read a first time in the House of Commons on June 15, 2026, and is at second reading. Its content could change before passage, and it is not yet law. Track it on LEGISinfo, Bill C-36 (45-1).

What Applies Today

PIPEDA remains in force. Under PIPEDA, knowingly contravening certain provisions — including the breach reporting requirement in section 10.1 — or obstructing the Commissioner is an offence (s. 28), punishable on indictment by a fine of up to $100,000. Separately, after receiving the Commissioner's report, a complainant may apply to the Federal Court for a hearing (s. 14), and the Court may award damages, including damages for humiliation (s. 16); the Act sets no cap on those damages. Source: PIPEDA on the Justice Laws website.

Practical Steps That Don't Depend on Any Bill

None of these is a CPPA or AIDA obligation:

  1. Conduct a data inventory — understand what personal information you hold, why, and for how long
  2. Review automated decision-making — identify any systems making automated decisions about individuals
  3. Update breach response — PIPEDA already requires reporting breaches that create a real risk of significant harm "as soon as feasible" after you determine the breach occurred
  4. Document AI governance — record AI system purposes, training data sources, and human oversight mechanisms

Frequently Asked Questions

Q: Should we comply with C-27 now? A: No — Bill C-27 died on the Order Paper in January 2025 and is not law. You must comply with current law (PIPEDA, and Law 25 for Quebec).

Q: Will AIDA affect small businesses? A: No. AIDA was never enacted, so it imposes no obligations on anyone.

Q: What has happened since Bill C-27 died? A: Federal privacy reform was re-introduced as Bill C-36, introduced on June 15, 2026 and currently at second reading. It is not yet law, and its content could change before passage. See LEGISinfo, Bill C-36 (45-1).


Build Your Privacy Programme on Current Law

Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.

Start your free trial today — compliance that grows with Canada's evolving privacy law.

Related reading: CPPA vs PIPEDA | Quebec Law 25 Guide | Law 25 vs PIPEDA

Found this article helpful?

Share it with your team or save it for later reference.

Related compliance guides

Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.