|
Written by Thao Nguyen
JD Candidate 2026 Early investment into building a strong cybersecurity framework will be beneficial for SMEs in the long run. In Canada, small and medium organizations (SMEs) have been found to be the likeliest target of cyber threat activity in the form of cybercrime for data theft and ransom.[1] Canadian privacy laws require private businesses, including SMEs, to install proper cyber security safeguards to protect the personal data that they collect from their users under the regulatory privacy frameworks imposed by the provincial and federal governments.[2] Most prominently, the Canadian Personal Information and Protection of Electronic Documents Act (“PIPEDA”) requires businesses to safeguard collected personal data to protect against loss, theft, unauthorized access, copying, use or modification (Principle 4.7).[3] PIPEDA gives the Privacy Commissioner the power to investigate any complaints against a business and issue reports which a complaint could use to apply to a Canadian court for a hearing.[4] The court may issue orders to the SME to correct its practices, publish notice about the correction, and pay damages to the complainant.[5] Therefore, data breaches can incur enormous financial costs for SMEs including ransom payment or court-awarded damages paid to victims. To help support SMEs with improving their cybersecurity capability, the Government of Canada provides SMEs with resources for education and training, certifications, grants and tax incentives. Education and Training One of those agencies is the Canadian Centre for Cyber Security (the “Cyber Centre”), an entity under the Communications Security Establishment Canada, which provides expert advice, guidance, services and support on cyber security for Canadians and acts as a hub for voluntary reporting of cyber incidents.[6] The Cyber Centre publishes the Baseline Cyber Security Controls for Small and Medium Organizations (the “Guide”) that lays out the recommended baseline controls with the goal to help SMEs achieve 80% of benefit from 20% effort or get the most out of their cyber security investments. The baseline controls are composed of 13 different recommendations for cyber security investments:
Certifications Beside the resources offered by the Cyber Centre, the Government of Canada issues a Cyber Security Assessment and Certification for Small and Medium-Sized Enterprises for those that implement the baseline controls.[8] Certified organizations will receive the permission to display the CyberSecure Certification Mark on their websites or at their physical locations to demonstrate the achievement of meeting the baseline controls.[9] The designation is valid for two years after it is awarded.[10] SMEs can also obtain other certification including the Digital Governance Council’s CyberReady Validation Program. The Digital Governance Council is a not-for-profit organization that plays a critical role in setting Canadian standards through its Digital Governance Standards Institute. Its new CyberReady Validation Program launched in February 2025 allows an organization to validate or verify the organization’s cybersecurity plans and practices with an independent review or audit. This program aims at strengthening stakeholder and public trust and confidence in an organization’s digital practices. The program costs $250 to $750 depending on the requested service.[11] Grants and Tax Incentives The Accelerated Investment Incentive provides SMEs with tax incentives for capital investments including investments into cyber technologies.[12] The Accelerated Investment Incentive, in a nutshell, provides an enhanced first-year allowance for eligible property subject to the capital cost allowance rules which gives the tax payers up to three times the normal first-year deduction.[13] Cyber eligible property may include cyber equipment and assets such as computers, software, and infrastructures. Research and experimental projects for cyber initiatives receive grants and tax incentives. First, the Cyber Security Innovation Network funds high-impact cyber technology projects encompassing research, development, product and service commercialization, and talent development. Second, the Scientific Research and Experimental Development (SR&ED) tax incentive program allows a business to claim a deduction against income or provides an investment tax incentive for eligible expenses for basic, applied research, experimental development, or support work.[14] SMEs can take advantage of these programs and resources from the Government of Canada and other non-profit organizations to bolster their cybersecurity capability. This can save SMEs money in their initial cyber investment and set up a strong foundation for their cyber systems which will establish trust with the SMEs’ customers and partners and reduce risks of future cyber incidents. Note: The above information does not constitute legal advice. No guarantees are made as to accuracy, completeness, or applicability to individual situations. [1] Government of Canada, Baseline Cyber Security Controls Small and Medium Organizations, online: <https://www.cyber.gc.ca/en/guidance/baseline-cyber-security-controls-small-and-medium-organizations>. [2] PIPEDA, SC 2000, c5; PIPA. [3] Ibid, Principle 4.7. [4] Ibid, s. 14(1). [5] Ibid, s. 16. [6] Government of Canada, Canadian Centre for Cyber Security, online: <https://www.cyber.gc.ca/en>; Government of Canada, Report a cyber incident, online: <https://www.cyber.gc.ca/en/incident-management>. [7] Cyber Canada, Learning Hub’s Cyber Security Small Medium Organizations, online: <https://www.cyber.gc.ca/en/education-community/learning-hub/courses/cyber-security-small-medium-organizations>. [8] Government of Canada, CyberSecure, online: <https://ised-isde.canada.ca/site/cybersecure-canada/en>. [9] Government of Canada, CyberSecure Canada’s Display Requirements, online: <https://ised-isde.canada.ca/site/cybersecure-canada/en/display-requirements>. [10] ibid. [11] Osler, https://www.osler.com/en/insights/updates/practical-approach-cybersecurity-trust-standards-validation-programs/; Digital Governance Council, Home page, online: <https://dgc-cgn.org/>. [12]Government of Canada, Accelerated investment incentive, online: <https://www.canada.ca/en/revenue-agency/services/tax/businesses/topics/sole-proprietorships-partnerships/report-business-income-expenses/claiming-capital-cost-allowance/accelerated-investment-incentive.html>. [13] Ibid. [14] Government of Canada, Scientific Research and Experimental Development Tax Incentive Program, online: <https://www.canada.ca/en/revenue-agency/services/scientific-research-experimental-development-tax-incentive-program.html>.
0 Comments
Written by Calder Newson
JD Candidate 2026 You just incorporated your start-up and named yourself and your co-founders as directors, now what? As a founder, you might wear many hats, one being director, but also others, such as shareholder and/or officer. Understanding your obligations as a director from the outset is important. In Alberta, serving as a director carries statutory obligations. The Statutory Framework Section 101(1) of Alberta’s Business Corporations Act, RSA 2000, c B-9 (“ABCA”) provides that the directors shall manage or supervise the management of the business and affairs of a corporation.[i] Section 122(1) of ABCA provides that every director and officer shall:
Fiduciary Duty/Duty of Loyalty In Peoples Department Stores Inc. (Trustee of) v. Wise, 2004 SCC 68 (“Peoples”), the court clarified that the fiduciary duty is owed to the corporation, not just to the shareholders.[iii] If not just the shareholders, then who is included in the corporation's best interests? Well, in BCE Inc. v. 1976 Debtentureholders, 2008 SCC 69 (“BCE”), the court explained that in determining the corporations best interest, it may be legitimate, given the circumstances in each case, for the directors to consider the interests of, among others, shareholders, employees, creditors, consumers, governments and the environment to inform their decisions.[iv] For founders who wear many hats, it is important to remember that decisions made as directors must be made to advance the corporation’s best interests. The Duty of Care The duty of care requires directors to exercise the care, diligence, and skill that a reasonably prudent person would exercise in comparable circumstances.[v] What does that entail? The duty of care does not require directors to make perfect decisions.[vi] Rather, in Peoples, the court explained that the duty of care requires directors to make reasonable business decisions in light of all the circumstances they knew or ought to have known.[vii] The Business Judgment Rule For many directors, especially in a start-up environment, there can be concern about whether a difficult or uncertain decision might later be judged harshly if the outcome is unsuccessful. Courts recognize that directors may have more business expertise than the courts. In turn, courts apply a rule called the “business judgment rule,” which limits their ability to second-guess business decisions when directors exercise appropriate prudence and diligence.[viii] With that said, the business judgment rule does not insulate directors from liability simply because they are directors. Rather, it means that the court will not substitute its own view for the directors’ when the business decision falls within a range of reasonable alternatives.[ix] Evidencing the Exercise of Director Duties As noted in Peoples, directors must make reasonable business decisions in light of all the circumstances they knew or ought to have known.[x] Indicators that directors exercised their duties may include evidence that the directors, among other things:
Holding regular board of directors meetings and maintaining meeting minutes could be evidence that directors met their duties. Minutes can reflect that the directors turned their minds to relevant issues, considered risks and alternatives, and deliberated in good faith. Conclusion Serving as a director or on a start-up’s board can be both exciting and demanding. Along with the opportunity to shape the direction of a growing business comes the statutory obligations under ABCA. Directors are trusted to manage and supervise management, and must act honestly and in good faith, and with the care, diligence, and skill required by s. 122(1) ABCA. For founders stepping into the role of director, understanding these duties from the outset provides important context for how corporate decisions are assessed. Courts evaluate not only outcomes, but whether directors acted on a reasonably informed basis and within a range of reasonable alternatives. This blog provides general legal information about directors’ duties under ABCA. Note: The above information does not constitute legal advice. No guarantees are made as to accuracy, completeness, or applicability to individual situations. [i] Business Corporations Act, RSA 2000, c B-9 (“ABCA”) at s.101(1). [ii] ABCA at s.122(1)(a)(b). [iii] Peoples Department Stores Inc. (Trustee of) v. Wise, 2004 SCC 68 (“Peoples”) at para 42. [iv] BCE Inc. v. 1976 Debtentureholders, 2008 SCC 69 (“BCE”) at para 40. [v] ABCA at s.122(1)(b). [vi] Peoples at para 67. [vii]Peoples at para 67. [viii] Peoples at paras 64-65. [ix] BCE at para 40. [x] Peoples at paras 64-65. Written by Austin Minnings
JD Candidate 2026 Introduction The rapid adoption of AI systems has brought significant advancements across various industries, raising unique privacy and compliance concerns. This post explores key considerations for organizations operating AI systems in Canada including, among other things, anonymization and data thresholds, the proposed AIDA and recent updates to relevant privacy legislation. By understanding and adhering to the applicable Canadian privacy laws, organizations can ensure compliance in the new age of AI. Anonymization Thresholds & Data Storage Rules Anonymization of data has been a crucial consideration in protecting information. The Personal Information Protection and Electronic Documents Act [1](“PIPEDA”) and Alberta’s Personal Information Protection Act[2](“PIPA”) require organizations to ensure that personal information gathered is de-identified in a manner that protects re-identification. Organizations operating in Alberta must also adhere to PIPA’s standard of reasonableness in their data storage policies and practices.[3] PIPA does not specify a retention period that is considered reasonable but best practices suggest deleting or disposing of personal data once it is no longer required for its original purpose. The proposed Artificial Intelligence and Data Act (“AIDA) On June 16, 2022, Bill C-27; the Digital Charter Implementation Act was tabled by the Federal Government. As it was proposed, the AIDA would regulate activity of persons involved in the design, development and use of “high-impact” AI systems, the determination of “high-impact” was deferred to future regulations.[4] Compliance obligations under the AIDA for persons responsible for high impact systems would have been related to risk management, transparency, record keeping and notification.[5] However, with the prorogation of Parliament in January 2026, Bill C-27, including the new proposed AIDA and privacy reforms it contained essentially “died”.[6] As such, the relevant compliance legislation remains PIPEDA and PIPA, among others. Demographic Protection Information and data may be used regarding demographics are often utilized in AI models. Passive demographic protection, such as identifying age, gender or mood may pose risks under the Office of the Information and Privacy Commissioner (OIPC) guidelines. In the event that such detection results in the collection of identifiable personal information or may contribute to systemic biases, there is a risk of non-compliance. Recent Updates The Freedom of Information and Protection of Privacy Act[7] (“FIPPA”) was recently reformed with the enactment of Bill 33.[8] Bill 33 included strengthened privacy protections and new rules with respect to data use and sharing and increased penalty of up to $750,000 for an organization.[9] Additionally, the PIPA is still currently under review. Conclusion The privacy and AI landscape continues to evolve, even without Bill C-27 and the accompanying proposed AIDA. Businesses should continue to monitor this landscape, especially given the pace of change. It is clear that AI will continue to intersect with privacy and compliance, necessitating further compliance requirements that organizations must stay up to date with. Note: The above information does not constitute legal advice. No guarantees are made as to accuracy, completeness, or applicability to individual situations. [1] SC 2000, c 5, [PIPEDA]. [2] SA 2003, c P-6.5, [PIPA]. [3] Section 2, PIPA. [4] Luca Lacarini, Part 2: Canada’s evolving artificial intelligence and privacy regime (April 12, 2023), online: https://www.dentons.com/en/insights/articles/2023/april/12/part-2-canadas-evolving-artificial-intelligence. [5] Ibid. [6] Nic Wall, Molly Reynolds & Rosalie Jetté et al, Looking ahead: the Canadian privacy and AI landscape without Bill C-27 (January 16, 2025), online: https://www.torys.com/our-latest-thinking/publications/2025/01/the-canadian-privacy-and-ai-landscape-without-bill-c-27. [7] RSA 2000, c F-25. [8] Supra note 4. [9] Ibid. Written by Cassidy Peterson
JD Candidate 2026 For start-ups and new businesses, intellectual property is often one of your most valuable assets. Whether you are building software, designing a logo, producing marketing materials, or creating online content, copyright law plays a central role in protecting what you create. Understanding what rights you have and how they arise is critical to protecting and monetizing your work. How Copyright Arises: Automatic Protection In Canada, copyright is governed by the federal Copyright Act.[1] Unlike patents or trademarks, copyright protection arises automatically. This means you do not need to register your work or file an application to benefit from this protection. Copyright arises as soon as a created work is original, and the work is fixed in a material form.[2] The Supreme Court of Canada has deemed a work to be “original” if it involves an exercise of skill and judgment to create.[3] This means it cannot simply be copied from another source but it does not have to be novel or groundbreaking; all that is required is that the work must reflect some intellectual effort.[4] Since copyright protects expression, not the ideas themselves, an idea in your head is not protected. Rather, it is protected once it is fixed in a material form:
If this fixation requirement is met, copyright arises immediately. What Can Be Protected? Copyright reflects a balance between rewarding creators and promoting public dissemination.[5] Under the Copyright Act, copyright protects “works” and certain other subject matter. Works fall into four main categories: 1. Literary Works
The Act also protects specific forms of other subject matter:
For example, if your business produces a podcast, there may be copyright in the script (literary work), copyright in the performance, and copyright in the sound recording itself. What Rights Does Copyright Give You? Section 3 of the Copyright Act sets out the rights available to copyright holders.[8] If you own copyright in a work, you have the exclusive right to: 1. Produce or Reproduce the Work
What Copyright Does NOT Protect Copyright protects the original EXPRESSION of ideas, not the ideas themselves.[10] It also does not protect facts, concepts, general themes, or stock elements.[11] This means you cannot stop others from using your business idea, however, you can protect specific written business plans, branding materials, or software codes. Who Owns Copyright in a Start-Up? This is where many early-stage businesses make mistakes. Default Rule: the author is the first owner of copyright.[12] Employment Exception: If a work is created by an employee in the course of their employment, the employer is the first owner unless there is an agreement to the contrary.[13] Independent Contractors: If, for example you hire a freelance developer or a marketing consultant acting as an independent contractor, they own the copyright unless there is a written assignment. Such assignment would need to be in writing and signed by the contractor.[14] Without such assignment, you may not legally own your logo, website, or branding materials. This can become a serious issue during future financing rounds or acquisitions. Conclusion Copyright protection is automatic with no registration required if a work is both original and fixed. Copyright awards a bundle of exclusive rights, including reproduction, communication, adaptation, and authorization. However, ideas themselves are not protected under, only their expression. If your business depends on content, software, branding, or media, ensuring you are aware of your copyright entitlements is essential to protecting these assets in the future. Note: The above information does not constitute legal advice. No guarantees are made as to accuracy, completeness, or applicability to individual situations. [1] Copyright Act, RSC 1985, c C-42 [Copyright Act]. [2] Ibid, s 3(1). [3] CCH Canadian Ltd. v. Law Society of Upper Canada, [2004] 1 S.C.R. 339, 2004 SCC 13 at para 24. [4] Ibid, para 18. [5] Théberge v. Galerie d'Art du Petit Champlain inc., 2002 SCC 34, [2002] 2 SCR 336 at para 30. [6] Copyright Act, supra note 1, s 5(1). [7] Ibid, s 2. [8] Ibid, s 3. [9] Rogers Communications Inc. v. Society of Composers, Authors and Music Publishers of Canada, 2012 SCC 35 at para 56. [10] Anne of Green Gables Licensing Authority Inc v Avonlea Traditions Inc., 2000 CanLII 22663, 4 CPR (4th) 289 (ONSC) at para 100. [11] In Cinar Corporation v Robinson, the Supreme Court emphasized that [12] Copyright Act, supra note 1, s 13(1). [13] Ibid, s 13(3). [14] Ibid, s 13(4). |
BVC BlogsBlog posts are by students at the Business Venture Clinic. Student bios appear under each post. Categories
All
Archives
April 2026
|
RSS Feed