Can Law Easy

Made in Canada · For Canadians

Digital business, privacy and cyber risk

Canadian information technology law, explained by subject

A practical guide to Canadian privacy, software contracts, online business, cybersecurity, anti-spam rules, electronic records and AI governance.

Which law applies: Technology law combines federal and provincial rules. PIPEDA may apply to commercial personal information, while Alberta, British Columbia and Quebec have private-sector privacy statutes. Sector, location and cross-border activity can change the analysis.

Subject 1

Privacy programs and personal information

Organizations should know what personal information they hold, why they need it and who can access it.

  • Document purposes, authority or consent, collection sources, uses, disclosures, storage locations and retention periods.
  • Collect only what is reasonably needed and give people meaningful information about the privacy consequences.
  • Assign privacy responsibility and create processes for access requests, corrections, complaints and deletion where applicable.
  • Use the Office of the Privacy Commissioner's guidance to identify whether federal or provincial privacy law applies.

Official sources: PIPEDA compliance help · Privacy guide for businesses

Subject 2

Software development, SaaS and cloud contracts

Technology contracts should connect technical performance with ownership, privacy, security and business continuity.

  • Define specifications, milestones, testing, acceptance, support, service levels and change-control procedures.
  • State who owns custom code, configurations, data, documentation and improvements, and identify third-party licences.
  • Address data location, subcontractors, security controls, breach notice, backups, portability and deletion at termination.
  • Match warranties, indemnities and liability limits to the actual operational and regulatory risks.

Official sources: Privacy guide for businesses · Baseline cyber security controls

Subject 3

Cybersecurity and breach response

Security is both a governance issue and, in many situations, a legal obligation tied to the sensitivity of information.

  • Maintain an inventory, access controls, multi-factor authentication, secure configuration, backups, patching and staff training.
  • An incident plan should identify decision-makers, technical containment, evidence preservation, legal review and communications.
  • Privacy laws can require breach assessment, records, notice to individuals or reporting to a regulator.
  • Contracts with service providers should make incident cooperation, notification and responsibility clear.

Official sources: Privacy breaches · Cyber security for small and medium businesses · Baseline cyber security controls

Subject 4

Email, text marketing and CASL

Canada's anti-spam framework regulates many commercial electronic messages and certain software installation practices.

  • Before sending a commercial message, identify a valid form of consent or other legal basis and keep supporting records.
  • Messages generally need prescribed sender identification, contact information and a working unsubscribe mechanism.
  • Purchased lists, referral campaigns, social messages and automated outreach can still create compliance risk.
  • Use current CRTC guidance because exceptions and implied-consent periods depend on specific facts.

Official sources: Canada's anti-spam legislation

Subject 5

Websites, e-commerce and electronic agreements

Online terms should be presented so users receive notice and take a clear step showing agreement.

  • Coordinate terms of use, sales terms, privacy notices, cookie choices, refund rules and accessibility statements.
  • Keep reliable records of the version accepted, date, account, notice shown and action taken.
  • Consumer-protection, language, tax and electronic-commerce requirements can vary by province and customer location.
  • Electronic signatures can be valid, but identity, authority, consent, document integrity and evidence still matter.

Official sources: PIPEDA compliance help · Privacy guide for businesses

Subject 6

AI, automated decisions and workplace technology

Using AI does not remove existing duties involving privacy, discrimination, confidentiality, accuracy and accountability.

  • Identify training and input data, permitted uses, retention, output ownership, security and human-review expectations.
  • Do not enter client, employee or confidential business information into a tool without authority and appropriate safeguards.
  • Assess the impact of monitoring, profiling or automated decisions on privacy and human rights.
  • Record limitations and review important outputs rather than presenting generated material as verified fact or professional advice.

Official sources: Privacy guide for businesses · Baseline cyber security controls

Important

General information, not legal advice

This page provides general legal information, not legal advice. It does not create a solicitor-client relationship. Laws, forms and official guidance change, and the answer can depend on your province, industry, documents and facts. Check the linked official source and consult a licensed Canadian lawyer, Quebec notary, patent agent or trademark agent when advice is needed.