Digital Charter Implementation Act (DCIA)

The Digital Charter Implementation Act (DCIA) never became law: Bill C-11 died at the 2021 election and Bill C-27 on prorogation in January 2025. Its successor, Bill C-36, the Protecting Privacy and Consumer Data Act, was tabled on 15 June 2026. What still applies today — PIPEDA, Quebec's Law 25, Ontario's FIPPA amendments, CASL — and how we help organizations get consent, retention and assessments right.

PIPEDA · 2000federal · the law todayC-11 · 2020died · 2021 electionC-27 · 2022died · prorogation 2025C-36 · June 20261st reading · fall 2026Ontario · Bill 194PIAs · breaches · 2025Québec · Law 25consent · PIAs · in forceOntario · PHIPAhealth custodiansCASL · 2014email consent · in forceWhat we do · with your counselnot legal advice · engineeringMapwhat you collect · whyConsent · retentionfixed · written downAssessmentsPIAs · cross-borderThe siteconsent that works · AAtime · the workdied on the order paperin forcebefore Parliament
Three federal bills since 2020, none yet law. What applies today is PIPEDA, the provinces and the sectors — and the site has to get consent right regardless.
since 2020 — none yet law
3 bills since 2020 — none yet law
Bill C-36 tabled, at first reading
15 June 2026 Bill C-36 tabled, at first reading
Ontario's FIPPA amendments in force
1 July 2025 Ontario's FIPPA amendments in force

Three bills, one law still standing

The Digital Charter Implementation Act was the federal government’s plan to replace PIPEDA, the private-sector privacy law Canada has had since 2000, with a Consumer Privacy Protection Act modelled partly on Europe’s GDPR: consent by purpose, data mobility, a right to disposal, transparency for algorithms, and penalties in the tens of millions. It was tabled as Bill C-11 in November 2020 and died at the 2021 election; tabled again as Bill C-27 in June 2022, studied in committee for two years, and died on the order paper when Parliament was prorogued on 6 January 2025. On 15 June 2026 the government tabled its third attempt under a new name — Bill C-36, the Protecting Privacy and Consumer Data Act — and Parliament rose three days later. Second reading is expected this fall.

So, as of September 2026, PIPEDA is still the law, and the obligations that have actually changed in the past two years are provincial and sectoral: Quebec’s Law 25, fully in force; Ontario’s Bill 194, which made privacy impact assessments and breach reporting mandatory for public-sector institutions on 1 July 2025; PHIPA for health custodians; CASL for anyone sending commercial email.

What to do now

Prepare for C-36 the way you should already be complying with PIPEDA and Law 25: know what you collect and why, ask for consent by purpose in language people understand, keep information only as long as the purpose needs, write the assessments before the data moves, and make every consent mechanism accessible — because for Ontario organizations the accessibility obligation is already law. When C-36 passes, the organizations that did this will change some documents; the ones that did not will change everything.

We are engineers, not lawyers. We keep this page current as the bills move, we build the technical side of compliance, and we work with your counsel on the rest.

What applies today

As of September 2026 the federal reform is a bill; these are the laws

PIPEDA — still the federal law

Canada’s private-sector privacy law since 2000: meaningful consent, purposes limited to what a reasonable person would expect, safeguards, access, and mandatory breach reporting since 2018. Every bill since 2020 has proposed to replace its Part 1; none has yet, so it governs your organization today.

Quebec's Law 25 — in force

Phased in from 2022 to 2024: a designated privacy officer, privacy impact assessments before information leaves the province, consent by purpose in clear language, and penalties that reach into the millions. If you have customers in Quebec, it applies now.

Ontario public sector — Bill 194

FIPPA institutions have had mandatory privacy impact assessments and breach reporting to the Information and Privacy Commissioner, at the real-risk-of-significant-harm threshold, since 1 July 2025, with whistleblower protections since January 2025. The Commissioner can now review practices and order corrections.

Health and marketing — PHIPA and CASL

Ontario’s health custodians answer to PHIPA; anyone sending commercial email answers to CASL, in force since 2014 and enforced. Both predate the federal reform and are unaffected by it.

Bill C-36 — what would change

Tabled 15 June 2026 as the Protecting Privacy and Consumer Data Act: a new Digital Safety and Data Protection Commission replacing the Privacy Commissioner, a legitimate-interest exception to consent, a line between de-identified and anonymized data, explanations for automated decisions with significant effects, assessments before data leaves Canada, administrative penalties up to the greater of $10 million or 3 per cent of global revenue, offences up to $25 million or 5 per cent, and a private right of action. Second reading is expected in the fall.

Cookie consent, in practice

Analytics that do not profile or influence people have sat inside a business-activities exception in every draft; advertising that does has not. We wrote about it when C-11 was tabled — Accept cookies? Does the DCIA mean nagging for Canadians? — and the direction has held through three bills.

How we help

The engineering side of privacy — with your counsel, not instead of them

  1. Map what you collect

    Every form, cookie, analytics tag, integration and export, with its purpose, its legal basis and where it goes. Most organizations discover collection they did not know they had.

  2. Fix consent and retention

    Consent asked for the purpose, in plain language, accessible to everyone; retention and disposal written down and automated rather than remembered.

  3. Prepare the assessments

    Privacy impact assessments in the form your regulator expects — mandatory for Ontario institutions since July 2025, for Quebec transfers under Law 25, and for cross-border disclosure under C-36 if it passes.

  4. Build it into the site

    Consent mechanics that actually work in your stack, tested with assistive technology, and a record of what was shown and when. This site runs no client-side analytics at all — a choice we can make for you too.

Who this is for

Ontario public-sector institutions

Ministries, agencies, municipalities, universities, hospitals and boards under FIPPA and MFIPPA, now with mandatory assessments and breach reporting — and an obligation to build accessibly at the same time.

Businesses under PIPEDA

Organizations that collect personal information in commercial activity, with customers in Quebec or across borders, who need to be right under today’s law and ready for C-36.

Health custodians

Clinics, family health teams and research organizations under PHIPA, whose websites, portals and forms carry the most sensitive information of all.

Questions we're asked

Is the DCIA law?

No. The Digital Charter Implementation Act was tabled twice — as Bill C-11 in November 2020, which died when the 2021 election was called, and as Bill C-27 in June 2022, which died when Parliament was prorogued on 6 January 2025. It was never reintroduced under that name.

What does DCIA mean?

Digital Charter Implementation Act — the name of the omnibus federal bills meant to implement Canada’s Digital Charter by replacing PIPEDA with a Consumer Privacy Protection Act, creating a tribunal and, in C-27, regulating artificial intelligence. Its successor has a different name: Bill C-36, the Protecting Privacy and Consumer Data Act.

What is Bill C-36?

The government’s third attempt at private-sector privacy reform, tabled on 15 June 2026 by the Minister of Artificial Intelligence and Digital Innovation. It would replace Part 1 of PIPEDA, create a new regulator, add a legitimate-interest exception, require explanations for consequential automated decisions and assessments before data leaves Canada, and raise penalties sharply. It is at first reading; second reading is expected when Parliament returns on 21 September 2026, and it must still pass committee, third reading and the Senate. Artificial intelligence is being handled separately.

Do Canadian websites need a cookie banner?

Under today’s law meaningful consent applies, and the Privacy Commissioner’s guidance has long distinguished analytics from tracking that profiles or targets people. Every federal draft has kept a business-activities exception for collection a reasonable person would expect and that does not influence their decisions — which is where privacy-respecting analytics sit — and none has exempted advertising. Quebec’s Law 25 is stricter. If you need a banner, it has to be accessible and it has to work; we test both.

What should an Ontario public-sector institution do now?

Treat Bill 194 as the deadline that has already passed: a privacy impact assessment for every new or changed collection of personal information, a breach process that assesses the real risk of significant harm and reports to the Commissioner and to affected people, and the safeguards the Commissioner can now review. We build the assessments and the technical controls with your privacy office.

Are you a law firm?

No. This page is informational, kept current as the bills move, and not legal advice. We build the technical side — the inventory, the consent mechanics, the retention automation, the assessments’ technical annexes — and we work with your counsel or privacy officer on the rest.
Contact us

Have a hard problem and a budget?

Tell us what's driving it. You'll talk to the people who do the work.

A sentence or two is plenty: the problem, the system, the deadline.