MT Cybersecurity Blog

Digital Security and data protection. Conceptual illustration with advanced technology digital display

Miller Thomson Blogs put a more conversational lens on Canadian law. See the diverse perspectives of our lawyers here.

Displaying 1-10 of 51

IIROC issues Notice regarding cybersecurity in cloud services and application programming interfaces

July 6, 2020 | David Krebs

On June 24, 2020, the Investment Industry Regulatory Organization of Canada (“IIROC”) released an Education Notice to members (“Cybersecurity – Cloud Services and Application Programming Interfaces”) outlining key elements of cybersecurity strategies pertaining to adoption and implementation of cloud services...


British Columbia Information and Privacy Commissioner calls for changes to Personal Information Protection Act

June 15, 2020 | David Krebs

As we’ve reported in past blog posts, Canada’s privacy regulators have been vocal about the need for change to the privacy and data protection laws that apply to the private, public and health sectors in Canada. Most recently, the British...


COVID-19 contact tracing debate highlights need for privacy law reform: Lessons for developers and users

June 11, 2020 | David Krebs

We have been following the COVID-19 crisis and its impact on privacy law over the course of the past few months. It has become apparent during that time that the requirements of the pandemic and the contact tracing debate highlight...


Privacy Commissioners: Privacy laws not a barrier to effective COVID-19 response, emphasize compliance when using contact tracing apps

May 12, 2020 | David Krebs, Danny Alcorn

The COVID-19 pandemic has created an unprecedented challenge for federal and provincial governments and other public health organizations in Canada. To respond in a timely and effective manner, government organizations require greater access to, and an enhanced ability to use,...


Privacy and cybersecurity during COVID-19 – Tips for Canadian organizations

March 24, 2020 | Eliott Cheeseman, David Krebs, Kathryn M. Frelick

With the emergence of COVID-19 in Canada, organizations are faced with many additional concerns and considerations in their daily operations and strategic planning. Remote work has become the norm, and the health of employees, customers and suppliers is a key...


Privacy Commissioner consultation on AI

February 4, 2020 | Kelly Harris, Eliott Cheeseman

Continuing to highlight the need for reform, the Office of the Privacy Commissioner of Canada (“OPC”) has initiated a consultation on recommendations they have presented to adapt the private sector privacy statute Personal Information Protection and Electronic Documents Act (“PIPEDA”) to address...


Canadian Privacy Commissioner Tables Annual Report, Calling for Human Rights-Based Overhaul of Privacy Laws

January 10, 2020 | David Krebs

On December 10, 2019, Commissioner Therrien presented his office’s 2019 annual report to Parliament, which was later followed by a press release highlighting key aspects of and views expressed in this latest report. Unsurprisingly, the need for privacy law reform...


“Once More Unto the (Data) Breach”…Looking back at Twelve Months of Mandatory Breach Notifications

November 26, 2019 | David Krebs, Hasith Andrahennadi

As described in numerous previous articles over the course of 2019, the past year saw an unprecedented number of breach notifications in Canada. In Europe, under the scrutiny of the General Data Protection Regulations (“GDPR”), there were a whopping 89,200...


Implementing Privacy by Design

November 26, 2019 | David Krebs

“Privacy by design” (“PbD”) is not a new concept but one that has been receiving increasing attention and legal clout in Canada, Europe, and around the world. Broadly speaking, it requires designing a system or process in a manner that...


Practical Strategies for Responding to a Cyber-Attack

November 1, 2019 | David Krebs

The author would like to thank the co-author of this article, Claudiu Popa[1], for his contributions and expertise in this area. Organizations across industry sectors are learning to recognize just what cyber-attacks look like, as Canadian companies are experiencing dozens...


Displaying 1-10 of 51


The blog sets out a variety of materials relating to the law to be used for educational and non-commercial purposes only; the author(s) of the blog do not intend the blog to be a source of legal advice. Please retain and seek the advice of a lawyer and use your own good judgement before choosing to act on any information included in the blog. If you choose to rely on the materials, you do so entirely at your own risk.