Skip to main content
CIPP/CCIPP/CPrivacyCanadaBill C-27

Privacy Enforcement After C-27: Commission Models, Order Powers, and the Safety Merge

Post-C-27, Canadian privacy reform still pushes order powers, AMPs, and commission models—plus a safety merge that overlaps digital harms duties.

5 min read
ShareLinkedIn

After the death of C-27, the vacuum filled with sharper tools

Bill C-27 — the Digital Charter Implementation Act, 2022 — died when Parliament was prorogued. With it went the Consumer Privacy Protection Act package many of us had already mapped to our control frameworks: stronger consent rules, tribunal machinery, and a path to meaningful financial consequences.

I did not mourn the bill line by line. I did mourn the delay. Canada stayed on PIPEDA-era enforcement while other jurisdictions normalized order powers and percentage-based fines. The recurring ask from the Commissioner’s office and the privacy community has been stable: binding orders, administrative monetary penalties, proactive audits, clearer rules for de-identification, and stronger individual control rights. Follow the Office of the Privacy Commissioner of Canada for official positions and findings under the law that is still in force.

Those themes did not die with C-27. They reappear in every serious reform sketch I see. Track new bill numbers on parl.ca and label them as proposed until they are in force.

What a “commission model” changes

Older Canadian privacy enforcement culture leaned ombudsman: investigate, report, recommend, persuade. That model built expertise and public education. It under-delivered when a well-resourced organization decided the reputational hit was cheaper than redesign.

A commission-style or strengthened regulator model — as discussed in emerging federal proposals, including research notes on restructuring private-sector privacy enforcement and related bill concepts sometimes discussed alongside digital safety files — aims at a different toolkit:

  • Order-making. Stop a collection practice. Require deletion. Mandate a change to safeguards. Not “please consider.”
  • Administrative monetary penalties. Money that scales with seriousness and, in modern drafts, sometimes with global revenue.
  • Audit and inquiry powers. Proactive review, not only complaint-driven firefighting.
  • Specialized divisions. Privacy expertise that can still move at regulatory speed.

I support order-making. I have spent too many years watching “non-binding recommendations” get filed under continuous improvement theatre.

Live law while institutions are redesigned

Until reform passes, commercial programs still run under PIPEDA. Provincial regimes continue to raise the floor — especially Quebec’s Law 25 through the CAI, which already pairs stronger rights with serious money. Ontario health custodians answer to PHIPA and the IPC. Do not let org-chart speculation become an excuse to under-invest in the regimes that can already investigate you.

The privacy + safety merger debate

Here is where I get uneasy, and I will say so plainly.

Digital safety institutions — especially the kind contemplated for online harms and social media duties under proposals such as Bill C-34 style frameworks — optimize for rapid content risk reduction, child protection, and platform accountability. Privacy institutions optimize for minimization, purpose limitation, and resistance to over-collection. Those goals align often. They collide when safety wants more identity, more logging, and longer retention, while privacy wants less of all three.

If reform places private-sector privacy inside or beside a digital safety commission architecture, governance teams must plan for:

  • Conflicting statutory purposes written into the same building.
  • One investigation spanning both “harmful content” and “unlawful processing.”
  • Shared evidence practices that could expand access to personal information beyond what a pure privacy regulator would seek.
  • Cultural capture risk either way — safety culture drowning privacy, or privacy formalism slowing urgent harm reduction.

Independence is not a slogan. Appointment design, mandate language, and firewalls between functions will decide whether Canadians get stronger protection or a confused super-agency.

What organizations should prepare for regardless of final org chart

Assume the next federal statute will not restore pure ombudsman mode. Build as if:

  1. An order can freeze a product feature.
  2. An AMP can follow systemic consent or safeguard failures.
  3. Auditors will ask for demonstrable accountability, not policy PDFs.
  4. Children’s data and large-scale profiling will be enforcement magnets.
  5. Cross-regulator information sharing will increase.

That means records of processing that match reality, DPIA-quality analysis for high-risk AI, vendor contracts with audit rights you can actually exercise, and incident files that show decisions, not just tickets.

I would also stop treating “we’ll wait for the final bill text” as a strategy. Between C-27’s death and ongoing 2026 reform debate, the direction has been stable even when the section numbers change: stronger orders, real money, less patience for paper compliance. Emerging commission-model proposals should be read against that baseline, not as a brand-new philosophy of enforcement.

A 30-day “order readiness” exercise

Pick your highest-risk processing activity and answer:

  • What would an order to stop the practice break in revenue and operations?
  • How fast could you delete or segregate the underlying personal information?
  • Which executives can authorize product freezes after hours?
  • What evidence proves you already tried to minimize and secure the activity?

If the answers are vague, you are not ready for a regulator with teeth. You are ready for a press release.

Actionable takeaway

C-27’s death delayed modernization. It did not settle the institutional question. The live debate is whether Canada gets a privacy regulator with real orders and penalties — and whether that function stays distinct or merges into a broader digital safety commission model. My bias: give privacy true enforcement teeth, and design any shared institution so minimization does not lose every fight with safety-driven collection. Prepare for orders first using today’s duties under PIPEDA and provincial law; argue about org charts in parallel while watching parl.ca for proposed reform text. If an order landed on your highest-risk processing activity tomorrow, could you comply in 30 days without rewriting the business from scratch?

Related services

Practical consulting aligned to this article’s focus—program design, controls, and operational delivery.

Browse all services