Mandatory breach reporting and notification became federal law for all PIPEDA-regulated organizations on November 1, 2018, per the Order Fixing November 1, 2018 (SI/2018-32, Canada Gazette Part II). The Order activated specific sections of the 2015 Digital Privacy Act amendments to PIPEDA.
The OPC investigates complaints, issues findings and reports, and may apply to Federal Court for binding orders. The OPC has no authority to issue administrative monetary penalties under PIPEDA. This gap was the central rationale for Bill C-27's CPPA, which died at prorogation in January 2025.
Canada Gazette, Part II — SI/2018-32 · OPC breach reporting guidance
Bill 64 (formally An Act to modernize legislative provisions as regards the protection of personal information) was assented to in September 2021 and rolled out in three phases. Phase 1 took effect on September 22, 2022.
Phase 1 alone forced thousands of Quebec organizations, and any organization with Quebec residents in their data, to designate a named privacy officer for the first time. The CAI Quebec became operationally able to receive and investigate breach reports within months.
Administrative monetary penalty (s. 90.12): up to CA$10M or 2% of preceding-fiscal-year worldwide turnover, whichever is greater. Imposed by the CAI Quebec.
Penal fine (s. 91): up to CA$25M or 4% of preceding-fiscal-year worldwide turnover, whichever is greater. Minimum CA$15,000 for corporations; doubles on a subsequent offence. Five-year limitation period.
McCarthy Tétrault: Law 25 obligations September 2023 · Osler: Law 25 enforcement scheme
The right to data portability activated on September 22, 2024. Individuals may request that personal information collected from them be communicated to them or, where technically possible, transferred to another organization in a structured and commonly used format.
With the entire Law 25 framework in force, Quebec's penalty severity sits in the same tier as the EU's GDPR (Article 83(5): €20M or 4% of global turnover). The penal regime is structurally similar, and Canadian organizations operating in Quebec face penalty exposure that mirrors EU enforcement.
Parliament was prorogued on January 6, 2025. Bill C-27, the Digital Charter Implementation Act, 2022 — which contained the Consumer Privacy Protection Act (CPPA), the Personal Information and Data Protection Tribunal Act, and the Artificial Intelligence and Data Act (AIDA) — died on the Order Paper without ever reaching Report stage or any Senate proceeding. Last committee meeting was September 26, 2024.
The CPPA would have established Canada's first direct administrative monetary penalty regime for federal privacy law. Penalties of up to 3% of global revenue or $10M for AMPs (s. 95(4)) and 5% of global revenue or $25M for indictable offences (s. 128). Important nuance frequently misstated: AMPs would have been imposed by a new Personal Information and Data Protection Tribunal on the Privacy Commissioner's recommendation, not by the OPC directly.
A snap federal election was called for April 2025. As of May 2026, no successor bill has been confirmed under a numbered designation. The 2025 federal budget signalled a new privacy statute with a tribunal companion bill expected late 2025 or early 2026, but nothing has been formally introduced.
LEGISinfo, Bill C-27 (44-1) · Library of Parliament Legislative Summary, Bill C-27
For any organization holding personal information of Canadian residents, the federal floor is PIPEDA's reasonable-safeguards standard with no direct fining authority. The provincial floor in Quebec is Law 25's $25M / 4% penal ceiling. In practice, any breach affecting Quebec residents triggers the harder regime.
Most Canadian privacy lawyers and law firm analysts now advise designing privacy programs to Quebec Law 25 as the floor, not PIPEDA, for any organization with national operations. This is a meaningful shift in the centre of gravity of Canadian privacy compliance.
The 2025 federal budget signalled a new privacy statute and tribunal companion bill expected late 2025 / early 2026. As of May 2026, no successor bill has been formally introduced under a numbered designation. Any new federal bill would likely continue the C-27 architecture: a Commissioner who investigates and recommends, with penalties imposed by a separate tribunal.
Most Canadian privacy programs were designed against PIPEDA's reasonable-safeguards standard. With C-27 dead and Law 25 fully in force at GDPR severity, any organization with Quebec residents in its data faces a regime an order of magnitude harder than PIPEDA. The cost of designing for that regime up front is bounded. The cost of redesigning under enforcement is not.