Canada Consumer Privacy Protection Act (Digital Charter)
Proposed Canadian federal privacy law replacing PIPEDA. Includes specific requirements for traceability of farm-to-table data and supply chain personal information.
What Bill C-27 CPPA draws on
This framework pulls on all three pillars — which is why running them as three separate tools means reconciling three sets of evidence at audit time.
Compliance
Security
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Security Safeguards
Organizations MUST implement appropriate physical, organizational, and technological security safeguards.
Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.
Breach Records
REQUIRES maintaining records of every breach of security safeguards involving personal information.
Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.
Access Rights
Individuals MUST be able to request and receive their personal information and processing details.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
Traceability
Organizations MUST be able to reconstruct the journey of personal data from ingestion to deletion.
Discovery locates every column holding a subject's data across every connected store, and the access history for that subject is reportable in minutes rather than reconstructed from tickets. The deletion or correction itself is executed by your application or your DBA — what the platform produces is the evidence of where the data was, who touched it, and that the change happened.
What Bill C-27 CPPA covers
This instrument defines no data category of its own. Not in force. Bill C-27 died on the Order Paper in January 2025, so PIPEDA’s definition of personal information still governs in Canada.
How Bill C-27 CPPA is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by None. There is no authority, because there is no statute.
Not in force. Nothing here is currently enforceable.
Bill C-27 would have replaced the commercial provisions of PIPEDA with the Consumer Privacy Protection Act, a new Tribunal, and the Artificial Intelligence and Data Act. It died on the Order Paper in January 2025 when Parliament was prorogued, before reaching a vote. Canada continues to run on PIPEDA, a statute written in 2000.
Any figure you see quoted for CPPA penalties describes a bill that never became law. Federal privacy reform has been signalled but no replacement has been enacted.
Uncapped exposure that sits outside this instrument
These come from company law rather than from Bill C-27 CPPA, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Directors’ duty of care
Canada, under s. 122(1)(b) of the Canada Business Corporations Act and its provincial equivalents.
Triggered by. Failing to exercise the care, diligence and skill a reasonably prudent person would exercise in comparable circumstances. Unlike the Delaware doctrine, the standard is objective.
Who. Directors and officers personally.
The CBCA permits indemnification only where the director acted honestly and in good faith, so the cases that matter most are the ones where indemnity is unavailable.
Peoples Department Stores Inc. v. Wise (SCC 2004); BCE Inc. v. 1976 Debentureholders (SCC 2008).
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for Bill C-27 CPPA,
not configured for it afterwards
Canadian Data Traceability
Track farm-to-table and supply chain PII with automated consent logging
CPPA Compliance Report
Breach record and data journey documentation
Canadian Industry Patterns
Identify agricultural, supply chain, and consumer data
Data Journey Alert
Track personal data across processing stages
Other Industrial frameworks
Walk into the Bill C-27 CPPA audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.