Blog

News

G-7 Guidelines for Cybersecurity Assessment

On October 13, 2017, the Group of Seven countries, including Canada, the United Kingdom and the United States (the “G-7”), issued a report titled G-7 Fundamental Elements for Effective Assessment of Cybersecurity in the Financial Sector (the “G7FEA”) to provide guidance for effective cybersecurity assessments by financial sector organizations. The G7FEA supplements the G-7’s 2016 report titled G7 […] Read more

Legal News

Cybersecurity Guidance from Canadian Securities Administrators

On October 19, 2017, the Canadian Securities Administrators (“CSA”) published Staff Notice 33-321 Cyber Security and Social Media to report on a survey of cybersecurity and social media practices by firms registered to trade securities or to advise clients regarding securities, and to provide guidance regarding cybersecurity and social media practices. The Staff Notice supplements the CSA’s […] Read more

News

Demers v. Yahoo Inc: Québec Court Confirms that Québec Consumer Law Applies to Free Online Services

In a September 19, 2017 decision in Demers v Yahoo! Inc., the Québec Superior Court rejected Yahoo! Inc. and Yahoo! Canada Co.’s (collectively, “Yahoo”) motion to dismiss a motion for authorization of a class action resulting from two highly publicized data security incidents that occurred in 2013 and 2014. This decision has important implications for […] Read more

Legal News

The European Union General Data Protection Regulation – A Primer for Canadian Organizations

The European Union General Data Protection Regulation (the “GDPR”), which will come into force in May 2018, is a significant evolution in personal data protection laws, and is materially different in important respects from the Canadian Personal Information Protection and Electronic Documents Act and similar provincial laws. The GDPR is complicated and nuanced, with permitted variances among European Union […] Read more

News

IAPP – Privacy. Security. Risk. 2017 (San Diego October 16-18)

I will be attending the IAPP PSR 2017 annual event in San Diego (October 16-18) and presenting on the following topic “Learn From my Fail: Avoiding Privacy Program Snafus & Screw-Ups” with the following co-panelists: Lael Bellamy, CIPP/US, CPO, The Weather Channel Peggy Eisenhauer, CIPP/US, Founder, Privacy & Information Management Services Eloïse Gratton, Partner and National Co-leader, Privacy and Data Protection Jules […] Read more

News

The OPC Publishes its Report on Consent

In May 2016, the Office of the Privacy Commissioner of Canada (OPC) published a discussion paper and launched a consultation on consent under the Personal Information Protection and Electronic Documents Act (PIPEDA) with the objective of identifying potential enhancements to the consent model and better defining the roles and responsibilities of the actors who could […] Read more