<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:series="https://publishpress.com/"
	>

<channel>
	<title>CCCC BlogsA New Privacy Regime Proposed in Bill C-27 - CCCC Blogs</title>
	<atom:link href="https://www.cccc.org/news_blogs/legal/2022/07/29/a-new-privacy-regime-proposed-in-bill-c-27/feed/" rel="self" type="application/rss+xml" />
	<link>https://cccc.org/news_blogs/legal/2022/07/29/a-new-privacy-regime-proposed-in-bill-c-27/</link>
	<description>CCCC Blogs</description>
	<lastBuildDate>Thu, 02 Apr 2026 16:28:18 +0000</lastBuildDate>
	<language>en-CA</language>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<site xmlns="com-wordpress:feed-additions:1">44556325</site>	<item>
		<title>A New Privacy Regime Proposed in Bill C-27</title>
		<link>https://www.cccc.org/news_blogs/legal/2022/07/29/a-new-privacy-regime-proposed-in-bill-c-27/</link>
		<comments>https://www.cccc.org/news_blogs/legal/2022/07/29/a-new-privacy-regime-proposed-in-bill-c-27/#respond</comments>
		<pubDate>Fri, 29 Jul 2022 18:29:48 +0000</pubDate>
		<dc:creator><![CDATA[Deina Warren]]></dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Federal]]></category>

		<guid isPermaLink="false">https://www.cccc.org/news_blogs/?p=34613</guid>
		<description><![CDATA[<p>On June 16th, 2022, a new privacy regime was proposed in Bill C-27, the Digital Charter Implementation Act. This Act, which is still at first reading, would protect individuals’ personal information and regulate organizations’ privacy practices. It is intended to modernize Canada’s private sector privacy laws. New Acts Created by... <a href="https://www.cccc.org/news_blogs/legal/2022/07/29/a-new-privacy-regime-proposed-in-bill-c-27/" class="linkbutton">More</a></p>
<p>The post <a href="https://www.cccc.org/news_blogs/legal/2022/07/29/a-new-privacy-regime-proposed-in-bill-c-27/">A New Privacy Regime Proposed in Bill C-27</a> appeared first on <a href="https://www.cccc.org/news_blogs">CCCC Blogs</a>.</p>
]]></description>
				<content:encoded><![CDATA[
<p>On June 16th, 2022, a new privacy regime was proposed in Bill C-27, the <a href="https://www.parl.ca/DocumentViewer/en/44-1/bill/C-27/first-reading" target="_blank" rel="noreferrer noopener"><em>Digital Charter Implementation Act</em></a>. This Act, which is still at first reading, would protect individuals’ personal information and regulate organizations’ privacy practices. It is intended to modernize Canada’s private sector privacy laws.</p>



<h2 class="wp-block-heading">New Acts Created by Bill C-27</h2>



<p>This ambitious bill aims to implement numerous privacy changes. If enacted, Bill C-27 would:</p>



<ul class="wp-block-list"><li>Create the&nbsp;<em>Consumer Privacy Protection Act</em><em>&nbsp;</em>(CPPA)</li></ul>



<p>The CPPA would replace Part 1 of the<a href="https://canlii.ca/t/541b8" target="_blank" rel="noreferrer noopener">&nbsp;<em>Personal Information Protection and Electronic Documents Act</em></a>&nbsp;(PIPEDA), Canada’s current private sector privacy law. It proposes modern privacy protection similar to the EU’s <em><a href="https://gdpr-info.eu/" target="_blank" rel="noreferrer noopener">General Data Protection Regulation</a> </em>(GDPR) and provides more clarity for organizations than our current privacy regime.</p>



<ul class="wp-block-list"><li>Create the&nbsp;<em>Personal Information and Data Protection Tribunal Act</em>&nbsp;(PIDPTA)</li></ul>



<p>The PIDPTA would establish a tribunal that would hear the <a href="https://www.priv.gc.ca/en/" target="_blank" rel="noreferrer noopener">Office of the Privacy Commissioner of Canada</a>’s (OPC) recommendations on administrative monetary penalties and appeals from certain inquiry findings and specific orders of the OPC.</p>



<ul class="wp-block-list"><li>Enact the Artificial Intelligence and Data Act (AIDA)</li></ul>



<p>The AIDA would regulate “international and interprovincial trade and commerce in AI systems” and prohibit certain conduct that could seriously harm individuals and their interests.</p>



<h2 class="wp-block-heading">Bill C-27’s Impact on Canadian Charities</h2>



<p>If Bill C-27 is passed, it will set out legal requirements for those subject to its jurisdiction, and it will set expectations for best practices. Canadian charities should consider how Bill C-27 would impact the way they handle personal information. Given increased liability and penalties under the proposed CPPA, charities should vigorously review their existing data policies and management to protect themselves from legal liabilities and to protect the privacy of their stakeholders.</p>



<h3 class="wp-block-heading">Definition of Commercial Activities</h3>



<p>Bill C-27 uses PIPEDA’s definition of “<a href="https://www.canlii.org/en/ca/laws/stat/sc-2000-c-5/latest/sc-2000-c-5.html#sec2subsec1" target="_blank" rel="noreferrer noopener">commercial activities</a>” which includes selling, bartering, leasing donor, membership, or other fundraising lists. Therefore, <a href="https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/r_o_p/02_05_d_19/" target="_blank" rel="noreferrer noopener">federal privacy laws will still apply </a>to Canadian charities engaged in such activities.</p>



<p>Bill C-27&#8217;s failed predecessor, <a href="https://parl.ca/DocumentViewer/en/43-2/bill/C-11/first-reading" target="_blank" rel="noreferrer noopener">Bill C-11</a>, proposed a restricted definition of &#8220;commercial activities,&#8221; that could have led many charities and non-profits to believe they no longer had to comply with federal private sector privacy laws. By returning to PIPEDA’s definition of “commercial activities”, Bill C-27 will still capture elements of what charities may do, such as selling, bartering, leasing donor, membership, or other fundraising lists.</p>



<h2 class="wp-block-heading">Other Important Proposals</h2>



<p>This is only a partial list, and since the bill has only just begun its journey through Parliament it could see significant changes along the way. This partial list highlights notable changes that may interest Canadian charities.</p>



<h3 class="wp-block-heading">Valid consent</h3>



<p>Organizations must use plain language when seeking permission to collect, use or disclose an individual&#8217;s personal information.</p>



<p>Organizations must not use misleading practices to obtain consent.</p>



<p>Organizations can sometimes collect and use data without consent:</p>



<ul class="wp-block-list"><li>If its reasonable for security purposes</li><li>If its reasonable for safety reasons</li><li>In other prescribed situations</li><li>When there are “legitimate interests.’</li></ul>



<p>People can withdraw consent subject to similar limitations that currently exist in PIPEDA. However, unlike PIPEDA, under the CPPA, an individual can also require that an organization dispose of their information. Disposal includes deletion and rendering the data anonymous.</p>



<h3 class="wp-block-heading">Minors</h3>



<p>Minors’ data means any &#8220;sensitive personal information.&#8221; Accordingly, privacy practices may require changes to ensure this information is adequately protected.&nbsp;</p>



<h3 class="wp-block-heading">Private Actions</h3>



<p>Individuals can bring a direct action for damages if they are affected by an organization’s infringement of the CPPA. The Act will also allow aggrieved individuals to file such actions in the superior court of a province.</p>



<h3 class="wp-block-heading">Strengthened Enforcement Regime</h3>



<p>Bill C-27 implements significant penalties for non-compliance with the CPPA.</p>



<h3 class="wp-block-heading">Provincial Requirements</h3>



<p>Organizations with operations in Quebec, British Columbia and Alberta will have to comply with both (the substantially similar) provincial privacy laws and with the CPPA when moving data from one province to another.</p>



<h3 class="wp-block-heading">Automated Decisions</h3>



<p>Individuals will have the right to require an organization to explain how an automated decision-making system could significantly impact them.</p>



<h2 class="wp-block-heading">For more on privacy&#8230;</h2>



<p>Members can check out CCCC <a href="https://www.cccc.org/kbm/Content/communications/privacy/privacy-lp.htm">privacy resources</a> in our Knowledge Base.</p>

<div id='jp-relatedposts' class='jp-relatedposts' >
	<h3 class="jp-relatedposts-headline"><em>Related</em></h3>
</div><p>The post <a href="https://www.cccc.org/news_blogs/legal/2022/07/29/a-new-privacy-regime-proposed-in-bill-c-27/">A New Privacy Regime Proposed in Bill C-27</a> appeared first on <a href="https://www.cccc.org/news_blogs">CCCC Blogs</a>.</p>
]]></content:encoded>
			<wfw:commentRss>https://www.cccc.org/news_blogs/legal/2022/07/29/a-new-privacy-regime-proposed-in-bill-c-27/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<post-id xmlns="com-wordpress:feed-additions:1">34613</post-id>	</item>
	</channel>
</rss>
