Governance, risk & compliance
Consumer Privacy Protection Act (CPPA) - Draft, not in force Bill C-27 first reading (died 6 January 2025)
DRAFT, NOT IN FORCE, AND SUPERSEDED FOR PLANNING.
The Consumer Privacy Protection Act was Part 1 of Bill C-27, the Digital Charter Implementation Act, 2022 (first reading 16 June 2022). It died on the Order Paper when Parliament was prorogued on 6 January 2025, after the Standing Committee on Industry and Technology had begun clause-by-clause review without finishing it.
It never received Royal Assent and never came into force; PIPEDA remains the federal private-sector privacy law. Its successor is Bill C-36, the proposed Protecting Privacy and Consumer Data Act (PPCDA), introduced on 15 June 2026 and at second reading as of 5 October 2026.
Lavawall carries the PPCDA as its own draft framework (CA_PPCDA) mapped to the same controls; plan against that one. This framework is kept for organizations that already assessed against the CPPA and for comparison.
Section numbers follow the C-27 first-reading text, which the committee never renumbered. The CPPA would have replaced PIPEDA's Schedule 1 principles with statutory duties: a privacy management program (s.
9), an appropriate-purposes test with recorded purposes (s. 12), express consent by default in plain language (s.
15), a legitimate-interest exception with a written assessment (s. 18), disposal on request (s.
55), explanations of automated decisions (ss. 62-63), data mobility (s.
72), de-identification rules (ss. 74-75), minors' information treated as sensitive (s.
2(2)), and administrative monetary penalties up to the higher of $10 million and 3% of gross global revenue, with fines for offences up to the higher of $25 million and 5%. The PPCDA keeps almost all of this, renumbered, and adds cross-border and legitimate-interest privacy impact assessments and human review of automated decisions.
It reuses every PIPEDA control, so answering this assessment shows how far a PIPEDA program already goes and where the gaps would be.
How Lavawall® helps you prepare for Consumer Privacy Protection Act (CPPA) - Draft, not in force
This is proposed legislation, not law in force. Lavawall® maps it to the same shared controls as the privacy law that applies today, so a control you already run and evidence counts toward both, and the readiness assessment shows only what you would need to add. Those controls run across Windows, macOS, Linux, and Microsoft 365 / Google Workspace from one console, and your posture is tracked continuously instead of once a year.
- Assess your current state against Consumer Privacy Protection Act (CPPA) - Draft, not in force in the Lavawall GRC module, with the questionnaire and control set built in.
- Remediate the gaps with the same platform — automated patching, configuration fixes, backups, and access review — not a separate project.
- Evidence everything with timestamped, exportable records auditors, insurers, and clients accept.
Related
Lavawall® supports Consumer Privacy Protection Act (CPPA) - Draft, not in force as part of a built-in catalogue of compliance frameworks. Framework requirements are summarized for planning purposes; always confirm the current official text before certifying.
At a glance
- Framework
- Consumer Privacy Protection Act (CPPA) - Draft, not in force Bill C-27 first reading (died 6 January 2025)
- Category
- Privacy
- Region
- Canada
Map this framework freeTalk to our team