Part Four In a Series The conclusion of the series on Canada's recently introduced Consumer Privacy Protection Act looks at hot button enforcement issues in the Act.
- November 01, 2022John Beardwood and Shan Arora
Security and privacy start with good information governance, and for many firms — trying to get their information governance policy implemented feels a lot like Groundhog Day. Yes, the one with Bill Murray. Let's take a closer look.
October 01, 2022Ben Schmidt and Nathan CurtisPart Three In a Series Part Three continues the analysis of new compliance requirements in Canada's new Consumer Privacy Protection Act, including the content of organizational privacy policies and anonymization of personal information policies, and business transaction policies contained in the Act.
October 01, 2022John Beardwood and Shan AroraThe European Union released its first attempt at a comprehensive cybersecurity legislation, the Cyber Resilience Act — and its impact on the technology market could be far-reaching.
October 01, 2022Cassandre CoyerThe Federal Trade Commission, under its current chairperson Lina Khan, has released a flurry of press releases and blogs in recent months signaling at a focused commercial surveillance "crackdown."
October 01, 2022Isha MarathePart Two In a Series Part One of this series introduced the history of Canada's recently introduced Consumer Privacy Protection Act and reviewed the similarities with GDPR, such as data portability, the right not be forgotten, codes of practice, and a safe harbor provision. Part Two analyzes the new compliance requirement of valid consent.
September 01, 2022John Beardwood and Shan AroraWhile the ADPPA represents compromises between Democratic and Republican leadership of the U.S. Senate and House of Representatives, particularly around the thorny issues of state law preemption and private rights of action, there are other legislative and big tech industry players pushing their own agendas for comprehensive national data privacy and security frameworks.
August 01, 2022Rita W. GarryPart One In a Series This article, which reviews the Canadian Consumer Privacy Protection Act, first seeks to identify the delta between the Act and PIPEDA in order to allow privacy officers of organizations that are already PIPEDA compliant to identify the net new compliance requirements under the Act and second, to highlight the provisions of the Act which, if breached, could lead to the imposition of significant fines.
August 01, 2022John Beardwood and Shan AroraIn light of the evolving legal and regulatory landscape, app developers and their counsel should examine developers' privacy and security practices and take steps to safeguard sensitive data related to reproductive health.
August 01, 2022Angela MatneyWhile the the California Privacy Protection Agency kicked some of the more difficult issues down the road for further consideration, its first draft of proposed Regs is quite comprehensive with respect to the issues addressed. The authority for some of what is proposed is questionable and will likely be challenged in comments, if not judicial action, if such provisions become final.
August 01, 2022Kyle Fath, Alan Friel, Shea Leitch and David J. Oberly








