Asking the right questions within your organization is key to effectively managing cyber risk. Here are 10 questions that you should ask your team...more
4/4/2025
/ Canada ,
Cyber Attacks ,
Cybersecurity ,
Data Privacy ,
Data Security ,
Incident Response Plans ,
Policies and Procedures ,
Regulatory Requirements ,
Risk Assessment ,
Risk Management ,
Third-Party Risk
Regulatory scrutiny is increasing concerning information of minors. Canadian privacy commissioners have identified minor's rights as a clear priority, and US regulators are setting strict parameters around what organizations...more
On September 26, 2023, the House of Common's Standing Committee on Industry and Technology (the Standing Committee) embarked on a comprehensive examination of Bill C-27, the Digital Charter Implementation Act. If passed, this...more
On July 13, 2023, the Supreme Court of Canada (SCC) denied leave to appeal from three Ontario Court of Appeal (ONCA) decisions declining to apply the tort of intrusion upon seclusion to database defendants—i.e., organizations...more
The Federal Court of Canada released a decision on April 14, 2023 in OPC v Facebook Inc.,2023 FCC 533 [Facebook], dismissing the Privacy Commissioner's application against Facebook (now Meta Platforms, Inc.) stemming from...more
The Ontario Court of Appeal recently released a trilogy of decisions (Winder v. Marriott International, Inc., 2022 ONCA 815; Obodo v. Trans Union of Canada, Inc., 2022 ONCA 814; Owsianik v. Equifax Canada Co., 2022 ONCA 813)...more
On June 14, 2022, federal Public Safety Minister Marco Mendicino introduced Bill C-26, An Act Respecting Cyber Security (ARCS). Intended to strengthen cybersecurity of vital services and vital systems, this proposed...more
Understanding the Draft of the Consumer Privacy Protection Act and Artificial Intelligence and Data Act -
On June 16, 2022, the Digital Charter Implementation Act, 2022 (DCIA) was introduced as Bill C-27. The DCIA will...more
6/20/2022
/ Artificial Intelligence ,
Canada ,
Consumer Privacy Rights ,
Corporate Counsel ,
Cybersecurity ,
Data Collection ,
Data Privacy ,
Data Protection ,
Data Security ,
New Legislation ,
Personal Information
Ransomware continues to present an increasing risk to all organizations. Ransomware attacks can involve the installation of malicious software designed to block access to computer systems and/or steal data, and a...more
3/15/2022
/ Canada ,
Cybersecurity ,
Data Breach ,
Data Privacy ,
Data Protection ,
Data Security ,
Financial Crimes ,
Financial Institutions ,
Financial Reporting ,
Popular ,
Ransomware
Organizations operating in Ontario may soon be subject to an entirely new provincial privacy regime that could impose substantial compliance obligations, and establish significant penalties for contravention of those...more
6/28/2021
/ Canada ,
Data Collection ,
Data Privacy ,
Data Protection ,
Data Security ,
Electronically Stored Information ,
Information Governance ,
Information Management ,
Personal Information ,
Privacy Laws ,
Privacy Policy
On April 30, 2021, the Government of Ontario introduced Building a Digital Ontario, the province's new digital and data strategy, which lays the foundation for Ontario to become "the world's leading digital jurisdiction."...more
The use of a facial recognition tool by Clearview AI, Inc. was the subject of an investigation by the privacy commissioners of Alberta, British Columbia and Quebec and their federal counterpart. In their jointly published...more
The long-awaited comprehensive reform to Canada's private sector privacy legislation is now finally underway. On November 17, 2020, the Digital Charter Implementation Act, 2020 (DCIA) was introduced. The DCIA will enact the...more
Comprehensive reform to Canada's privacy legislation—which privacy experts have long anticipated—is now imminent. Today, the Minister of Innovation, Science and Industry, the Honourable Navdeep Bains, tabled the Digital...more
Guidance from the Cadillac Fairview Decision -
The use of facial recognition software by Cadillac Fairview Corporation Limited (CFCL) in its shopping malls was the subject of a joint investigation by the Office of the...more
In its Annual Report to Parliament on the Privacy Act and Personal Information Protection and Electronic Documents Act (PIPEDA), the Office of the Privacy Commissioner (OPC) has repeated its previous calls for reform to...more
Facebook has agreed to pay a fine of $9 million under the federal Competition Act stemming from the Cambridge Analytica matter and to reimburse the cost of the inquiry of $500,000 (without any acknowledgment of wrongdoing)....more
The Canadian Internet Registration Authority (CIRA) launched a domain name system (DNS) service on April 23, 2020. CIRA is the entity responsible for overseeing Canada's .ca country-code top-level domain (ccTLD). CIRA is...more
Seeking input from interested third parties, the Office of the Privacy Commissioner of Canada (OPC) announced a revision to its policy position on transborder data flow under the federal Personal Information Protection and...more
Forget you ever read this -
The Office of the Privacy Commissioner of Canada (OPC) declared last Friday that existing privacy laws allow consumers to ask search engines to remove inaccurate search results and to request...more