Bill C-27 CPPAIndustrialCanadaAll Industries / Agriculture

Canada Consumer Privacy Protection Act (Digital Charter)

Proposed Canadian federal privacy law replacing PIPEDA. Includes specific requirements for traceability of farm-to-table data and supply chain personal information.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

Bill C-27 CPPASection 57Patching, hardening, and exposureA record of access

Security Safeguards

Organizations MUST implement appropriate physical, organizational, and technological security safeguards.

Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.

Bill C-27 CPPASection 72Detecting it in time to notify

Breach Records

REQUIRES maintaining records of every breach of security safeguards involving personal information.

Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.

Bill C-27 CPPASection 63A record of access

Access Rights

Individuals MUST be able to request and receive their personal information and processing details.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

Bill C-27 CPPASection 59Answering for an individual

Traceability

Organizations MUST be able to reconstruct the journey of personal data from ingestion to deletion.

Discovery locates every column holding a subject's data across every connected store, and the access history for that subject is reportable in minutes rather than reconstructed from tickets. The deletion or correction itself is executed by your application or your DBA — what the platform produces is the evidence of where the data was, who touched it, and that the change happened.

What Bill C-27 CPPA covers

This instrument defines no data category of its own. Not in force. Bill C-27 died on the Order Paper in January 2025, so PIPEDA’s definition of personal information still governs in Canada.

How Bill C-27 CPPA is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by None. There is no authority, because there is no statute.

Not in force. Nothing here is currently enforceable.

Bill C-27 would have replaced the commercial provisions of PIPEDA with the Consumer Privacy Protection Act, a new Tribunal, and the Artificial Intelligence and Data Act. It died on the Order Paper in January 2025 when Parliament was prorogued, before reaching a vote. Canada continues to run on PIPEDA, a statute written in 2000.

Any figure you see quoted for CPPA penalties describes a bill that never became law. Federal privacy reform has been signalled but no replacement has been enacted.

Uncapped exposure that sits outside this instrument

These come from company law rather than from Bill C-27 CPPA, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Directors’ duty of care

Canada, under s. 122(1)(b) of the Canada Business Corporations Act and its provincial equivalents.

Triggered by. Failing to exercise the care, diligence and skill a reasonably prudent person would exercise in comparable circumstances. Unlike the Delaware doctrine, the standard is objective.

Who. Directors and officers personally.

The CBCA permits indemnification only where the director acted honestly and in good faith, so the cases that matter most are the ones where indemnity is unavailable.

Peoples Department Stores Inc. v. Wise (SCC 2004); BCE Inc. v. 1976 Debentureholders (SCC 2008).

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for Bill C-27 CPPA,
not configured for it afterwards

Policy Template

Canadian Data Traceability

Track farm-to-table and supply chain PII with automated consent logging

Report

CPPA Compliance Report

Breach record and data journey documentation

Classification

Canadian Industry Patterns

Identify agricultural, supply chain, and consumer data

Alert

Data Journey Alert

Track personal data across processing stages

Walk into the Bill C-27 CPPA audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment