What was the CPPA
What is the CPPA (Consumer Privacy Protection Act, Bill C-27)?
The CPPA (Consumer Privacy Protection Act) was Canada's proposed replacement for PIPEDA, the Personal Information Protection and Electronic Documents Act. It was Part 1 of Bill C-27, the Digital Charter Implementation Act, 2022. The bill died on 6 January 2025 and the CPPA never came into force. Its successor is the Protecting Privacy and Consumer Data Act (PPCDA) in Bill C-36.
Read about the PPCDA Compare the CPPA and the PPCDA
Bill C-27 · died 6 January 2025 · never in force · superseded by Bill C-36
Definition
The CPPA (Consumer Privacy Protection Act) was a proposed federal law that would have replaced the privacy part of PIPEDA. It would have governed how private-sector organizations in Canada collect, use, and disclose personal information in commercial activity, and given the Privacy Commissioner of Canada order-making powers and the ability to recommend large administrative monetary penalties.
Bill C-27, the Digital Charter Implementation Act, 2022, had three parts: the Consumer Privacy Protection Act, the Personal Information and Data Protection Tribunal Act, which would have created a tribunal to impose penalties and hear appeals, and the Artificial Intelligence and Data Act (AIDA).
Not to be confused with the California Privacy Protection Agency, also called the CPPA, which enforces the California Consumer Privacy Act.
What happened to it
| Date | Event |
|---|---|
| 16 June 2022 | Bill C-27 introduced in the House of Commons |
| April 2023 | Passed second reading and sent to the Standing Committee on Industry and Technology |
| 2023 to 2024 | Committee study and clause-by-clause review, which never finished |
| 6 January 2025 | Parliament prorogued; Bill C-27 died on the Order Paper |
| 15 June 2026 | Bill C-36 introduced, proposing the Protecting Privacy and Consumer Data Act in its place |
What the CPPA would have required
Privacy management program (s. 9)
A written program proportionate to the volume and sensitivity of the information, which the Commissioner could inspect.
Appropriate, recorded purposes (s. 12)
A five-factor test for whether a purpose is appropriate, and a duty to record each purpose before collection.
Plain-language, express consent (s. 15)
Consent informed in language the audience understands, express unless implied consent is appropriate.
Legitimate interest (s. 18)
Collection or use without consent for a legitimate interest that outweighs the adverse effects, with a recorded assessment.
Disposal on request (s. 55)
A right to have personal information deleted or anonymized, passed on to service providers.
Automated decisions (ss. 62-63)
A general account of automated decision systems and an explanation of a decision on request.
Minors (s. 2(2))
Minors' personal information treated as sensitive, without a defined age.
De-identification and mobility (ss. 72-75)
Rules for de-identified and anonymized information, and a data mobility right where a sector framework exists.
Penalties
Administrative monetary penalties up to the higher of $10 million and 3% of gross global revenue, and fines up to the higher of $25 million and 5%.
The CPPA and the PPCDA side by side
The Protecting Privacy and Consumer Data Act keeps the CPPA's structure, mostly with new section numbers. These are the differences worth planning for.
| Topic | CPPA (Bill C-27) | PPCDA (Bill C-36) |
|---|---|---|
| Status | Died 6 January 2025 | At second reading (October 2026), not in force |
| Regulator | Privacy Commissioner of Canada, with a separate Personal Information and Data Protection Tribunal | Privacy and Consumer Data Commissioner within the Digital Safety and Data Protection Commission; no Tribunal |
| Transfers outside Canada | Mention them in the privacy policy | Privacy impact assessment and mitigations before the transfer (s. 57) |
| Legitimate interest | Collection and use, with a recorded assessment | Collection, use, and disclosure, with a privacy impact assessment (s. 18) |
| Automated decisions | Explanation for decisions with a "significant impact" | Explanation for decisions with a "legal or similarly significant effect", plus review by an employee (s. 63) |
| Children | Minors' information sensitive; no age defined | A child is anyone under 18; a parent or guardian exercises the child's rights (ss. 2 and 4) |
| Sensitive information | Not defined | Defined, with a list of categories (s. 2) |
| Artificial intelligence | The Artificial Intelligence and Data Act in the same bill | No AI act in the bill |
| Maximum penalties | $10 million or 3%; fines $25 million or 5% | The same |
Why it still matters
The CPPA is the clearest record of where federal privacy law is heading. Its successor reuses most of it, so the work organizations did to prepare for the CPPA (a privacy program, a record of purposes, a disposal process, a de-identification standard, an account of automated decisions) is the same work the PPCDA asks for.
That work also pays off today. PIPEDA's accountability principle already expects a privacy management program, Quebec Law 25 already requires a privacy impact assessment before information leaves Quebec and a portability right, and the Privacy Commissioner already treats children's information as sensitive.
How Lavawall® handles the CPPA
Lavawall® keeps the CPPA as a draft framework, marked as not in force and superseded, for organizations that already assessed against it. New planning should use the PPCDA framework.
PIPEDA, the CPPA, and the PPCDA are mapped to one shared set of controls. A control you implement and evidence once counts toward each framework that maps it, so moving your planning from the CPPA to the PPCDA keeps every control you already put in place and adds only what Bill C-36 changed. There is no per-framework charge in the Complete tier.
Start your PPCDA readiness assessment →
This page summarizes legislation that never came into force. It is not legal advice.
Frequently asked
- Is the CPPA in force?
- No. The Consumer Privacy Protection Act was Part 1 of Bill C-27, which died on the Order Paper when Parliament was prorogued on 6 January 2025. It never received Royal Assent. PIPEDA is still the federal private-sector privacy law.
- What replaced the CPPA?
- Bill C-36, introduced on 15 June 2026, proposes the Protecting Privacy and Consumer Data Act (PPCDA). It keeps most of the CPPA's structure and adds privacy impact assessments before transfers outside Canada and before relying on legitimate interest, human review of automated decisions, and a definition of a child as anyone under 18. It is not in force either.
- Is the CPPA the same as the California Privacy Protection Agency?
- No. In Canada, CPPA usually means the Consumer Privacy Protection Act, the proposed federal privacy law in Bill C-27. In California, CPPA is the California Privacy Protection Agency, the regulator that enforces the California Consumer Privacy Act (CCPA) as amended by the CPRA.
- Was work done for the CPPA wasted?
- No. The PPCDA keeps almost every CPPA duty, renumbered: the privacy management program, recorded purposes, legitimate interest, disposal on request, automated decision explanations, de-identification, and data mobility. In Lavawall, the CPPA and the PPCDA are mapped to the same controls as PIPEDA, so control work already done carries straight across.
- Should I assess against the CPPA or the PPCDA?
- The PPCDA, for any new planning, because it is the bill before Parliament. Keep a CPPA assessment you already have for comparison; it shows how far your program had come against the earlier draft.