PRIVACY · CANADA · NOT IN FORCE

Consumer Privacy Protection Act (CPPA)
Bill C-27, and What Replaced It

The Consumer Privacy Protection Act (CPPA) was Canada's proposed replacement for PIPEDA in Bill C-27. It died in January 2025 and never came into force. Its successor, the PPCDA in Bill C-36, keeps most of it. ThreeShield helps you carry CPPA preparation into PPCDA readiness.

What the Consumer Privacy Protection Act (CPPA) Was

The Consumer Privacy Protection Act (CPPA) was Part 1 of Bill C-27, the Digital Charter Implementation Act, 2022, introduced on 16 June 2022. It would have replaced the privacy part of PIPEDA with statutory duties, a privacy tribunal, administrative monetary penalties of up to $10 million or 3% of global revenue, and fines of up to $25 million or 5%.

Bill C-27 died on the Order Paper when Parliament was prorogued on 6 January 2025. The CPPA never came into force. PIPEDA is still the law.

Its successor is the Protecting Privacy and Consumer Data Act (PPCDA) in Bill C-36, introduced in June 2026, which keeps most of the CPPA and adds to it.

Not to be confused with the California Privacy Protection Agency, also abbreviated CPPA, which enforces the California Consumer Privacy Act (see CCPA/CPRA).

The CPPA and the PPCDA Side by Side

TopicCPPA (Bill C-27)PPCDA (Bill C-36)
StatusDied 6 January 2025At second reading, not in force
RegulatorPrivacy Commissioner, plus a separate Personal Information and Data Protection TribunalPrivacy and Consumer Data Commissioner within the Digital Safety and Data Protection Commission; no Tribunal
Transfers outside CanadaMention them in the privacy policyPrivacy impact assessment and mitigations first
Legitimate interestCollection and use, with a recorded assessmentCollection, use, and disclosure, with a privacy impact assessment
Automated decisionsExplanation for a "significant impact"Explanation for a "legal or similarly significant effect", plus review by an employee
ChildrenMinors' information sensitive; no age definedAnyone under 18; a parent or guardian exercises the child's rights
Artificial intelligenceThe Artificial Intelligence and Data Act in the same billNo AI act in the bill
Maximum penalties$10 million or 3%; fines $25 million or 5%The same

Was the CPPA Work Wasted?

No. A privacy management program, a record of purposes, a disposal process, a de-identification standard, and an account of automated decisions are the same work the PPCDA asks for, and most of it is good practice under PIPEDA now. In Lavawall®, PIPEDA, the CPPA, and the PPCDA sit on one shared control set, so every control already in place carries across and ThreeShield only scopes what Bill C-36 changed.

Most compliance platforms reuse a control across the frameworks they ship. The question for a Canadian organization is whether PIPEDA and the PPCDA are among them. If either has to be built as a custom framework, mapping it to your existing controls is your work, and it has to be redone as the bill changes in committee. If the platform charges per framework, planning for a bill that is not law yet costs extra. Lavawall® ships PIPEDA, the CPPA, and the PPCDA pre-built on one shared control set, and ThreeShield keeps them current as Bill C-36 moves.

Related: PPCDA (Bill C-36) · PIPEDA compliance · Quebec Law 25

Official source: https://www.parl.ca/legisinfo/en/bill/44-1/c-27

Frequently Asked Questions

No. Bill C-27 died when Parliament was prorogued on 6 January 2025. The CPPA never received Royal Assent, and PIPEDA remains the federal private-sector privacy law.

Bill C-36, introduced on 15 June 2026, proposes the Protecting Privacy and Consumer Data Act (PPCDA). It keeps most of the CPPA and adds privacy impact assessments before transfers outside Canada and before relying on legitimate interest, human review of automated decisions, and a definition of a child as anyone under 18.

No. In Canada, CPPA means the Consumer Privacy Protection Act in Bill C-27. In California, CPPA is the California Privacy Protection Agency, the regulator for the CCPA and CPRA.

Three Ways to Engage, from DIY to Done-for-You

ThreeShield meets you at your current privacy maturity. Every level includes Lavawall®.

Self-Serve

DIY via Lavawall®

For lean IT teams and cost-conscious organizations with internal capacity

  • Lavawall® GRC with PIPEDA, the CPPA, and the PPCDA on one control set
  • PPCDA readiness assessment
  • Templates for the new requirements
  • Continuous safeguards evidence
Start with Lavawall®
Recommended for MSPs & Lean IT

Supported

Expert guidance alongside your team, ideal for MSPs and organizations with some internal IT capacity

  • Everything in the DIY tier
  • CISSP/CISA-led gap assessment
  • Prioritized remediation roadmap
  • Policy and procedure development
  • Quarterly compliance review calls
  • MSP white-label available
Get Supported Engagement
Fully Managed

Done-for-You

The privacy program delivered and kept current by ThreeShield

  • Everything in the Supported tier
  • Full privacy program management
  • CISSP/CISA-executed formal assessment
  • Detailed findings methodology
  • Complete documentation package
  • Annual reassessment included
Book Done-for-You

Turn CPPA Preparation into PPCDA Readiness

Keep what you built for the CPPA. ThreeShield maps it to Bill C-36 and closes the gaps, and Lavawall® keeps the evidence current.

Book a Scoping Call

DIY · Supported · Done-for-You