Privacy and Data Protection

We help clients navigate evolving privacy laws and safeguard sensitive data, providing strategic counsel to manage risk, ensure compliance and protect reputation.
Key Contacts
Burns StephenPoirier CarolinePromislow Ruth
Servers

Overview

Ongoing changes in the accumulation, storage and use of personal data � whether by government, employers, financial institutions, health care providers or the data subjects themselves � have given rise to new and more serious privacy concerns. Recent changes to privacy laws, varying standards internationally and one reported crisis after another have forced business, government and the public to seek guidance on managing the precarious balance between safeguarding personal privacy and third-party interests in acquiring and using personal information.

Bennett Jones performs groundbreaking work with governments, employers, institutions, device providers and public and private information-gatherers, advising on the far-reaching legal implications of privacy regulation, data protection and data dissemination.

Offering both compliance and enforcement advice, we can provide internal compliance procedures and policies for clients ranging from public and private industrial businesses to retail operations, Universities, charities, health regions and ISPs and other entities operating traditional and new media businesses. We train privacy officers on their rights and obligations under the law, and provide opinions and direction on specific incidents involving employees, customers, patients, Internet users, network providers and data miners whose activities involve the handling of sensitive information.

In regard to corporate transactions, we counsel purchasers on the privacy standards governing employee records, customer files and transaction lists as well as the unique due diligence issues involved when key assets of the target include important databases.

We help clients with privacy issues applicable to employee recruitment and the ongoing management of employment relationships.

In a world of cyber breaches, hacking, credit card and ATM fraud, Internet-based file sharing disputes, and acknowledged institutional surveillance of Internet and email usage, we advise on proactive data protection efforts to mitigate risk in advance of a breach or attack and counsel clients who have faced a breach or have been hacked. We assist with all manner of computer-related privacy and data protection matters, including electronic communications regulation (anti-spam).

We also aid clients with the protection and enforcement of electronic-based privacy rights both domestically and internationally.

The scope of our experience is broad and includes:

  • Data Protection / Privacy and Security Policies and Governance
  • Health Information Privacy and Security Policies and Governance
  • Data Protection / Privacy Compliance Policies and Procedures including integration with electronic communication regulation
  • Review of Data Protection / Privacy and Security insurance coverage
  • Guidance for boards of directors and senior management on Data Protection / Privacy and Security obligations
  • Data Protection / Privacy Investigations
  • Data Protection / Privacy Litigation and Regulatory Enforcement
  • Liaison with regulatory, law enforcement authorities, and Privacy Commissioners
  • Data Protection / Privacy and Security Assessment and Preparedness
  • Data Breach Preparedness
  • Data Breach Investigation and Response
  • Data Breach Litigation and Regulatory Enforcement
  • Defense of class action proceedings relating to data breach or privacy incidents
  • Cross-Border Data Transfers and Data Protection / Privacy
  • Employee Privacy considerations
  • M&A Due Diligence Involving Data Protection / Privacy and Security
  • Advising on the interaction of Data Protection / Privacy compliance and the regulation of commercial electronic messages
  • Licensing and web-contract terms with respect of privacy / data protection, software updates, internet of things and related matters

Client Work

ATCO
in respect of the privacy, data governance, technology, licensing and intellectual property mandates
BetterHelp
in two proposed class actions in Ontario and BC concerning its alleged disclosure of its clients' personal and health information to third-party advertisers
Canadian Medical Protective Association
routinely retained to address privacy issues arising from the unauthorized collection, use, disclosure, access or destruction of medical information
Cenovus
in respect of numerous and complex retainers, often participating in strategic discussions on the use of technology
Gateway Casinos
advising on its privacy, data governance and technology (including, artificial intelligence and compliance) in Canada
Government of Canada
retained by the Government of Canada through its entity - the Sport Dispute Centre of Canada
LG
in connection with a privacy class action involving allegations that Facebook secretly gave major device manufacturers access to users' personal information
Marriott
in its defence of a consumer class action relating to a data breach of Marriott's guest reservation database
Mastercard Emerging Leaders Cyber Initiative
program designed to advance the cyber expertise of female and non-binary executives in cybersecurity positions
Northback Holdings
in connection with its process to obtain all necessary development permits, we assisted Benga manage among one of the most complicated government access to information requests currently in Canada
Shein
overseeing the client's Canadian privacy and data management program
UNI Financial Cooperation
overseeing UNI's privacy and cybersecurity management program, which involves complex issues of privacy, data governance, outsourcing and cybersecurity
United Farmers of Alberta
as privacy and technology counsel, supporting its cyber, data, privacy and technology matters, including breach preparedness and response
Volkswagen
retained to assist with a broad range of technology, licensing and commercialization matters as well as intellectual property identification, protection and prosecution
Calgary Police Service
with their Freedom of Information and Protection of Privacy Act matters
Marriott
in privacy class action litigation
Regulatory compliance advice on Canadian privacy and health information laws for a leading medical device manufacturer with global operations
Regulatory compliance advice across a broad spectrum of industries, including technology, financial services, oil and gas production, health, mining, utilities, e-commerce, and hospitality
Breach counsel, involving overseeing forensic investigations, regulatory and litigation risk management, reporting to regulators and handling regulatory inquiries/investigations
Breach coach, development of policy and compliance programs for one of the largest cannabis companies in the world on cybersecurity preparedness and incident response
Breach coach for association of insurance and reinsurance companies with global operations
Data security, privacy advice and breach coach to a supplier of information management systems to oil and gas companies around the world
Sole legal counsel on technology, licensing and IP mandates to ATCO and Canadian Utilities
Counsel to provincial physician organization on Health Information Act matters, including appearing before regulators and the courts
Regulatory compliance advice on Canadian privacy laws and the collection, storage and use of personal information for one of the world’s largest life sciences companies
Counsel to major Canadian city police service, mandates routinely include Freedom of Information and Protection of Privacy Act matters
Privacy, IP and regulatory advice to help healthcare technology solutions provider navigate its entry into the Canadian market

Recognitions

Who's Who Legal: Data
Bennett Jones lawyers recognized globally for data information technology

Burns Stephen

Stephen D. Burns

Partner, Trademark Agent  •   Co-Head of Innovation, Technology & Branding Practice

Blog

Alberta OIPC Issues Report Regarding Responsible AI Governance

August 28, 2025
Stephen D. BurnsJ. Sébastien A. GittensDavid Wainer
Stephen D. Burns, J. Sébastien A. Gittens & David Wainer
Blog

Right to Have Your Information De-Listed? The Federal Privacy Commissioner Issues Decision

August 28, 2025
Ruth E. PromislowCaroline PoirierSuzie Suliman
Ruth E. Promislow, Caroline Poirier & Suzie Suliman
Blog

23andMe's Data Breach: Key Takeaways

June 26, 2025
Stephen D. BurnsRuth E. PromislowJ. Sébastien A. Gittens
& 7 more
Blog

Alberta's New Privacy Laws Are Now in Effect: What Public Bodies Need to Know

June 20, 2025
Stephen D. BurnsJ. Sébastien A. GittensDavid Wainer
Stephen D. Burns, J. Sébastien A. Gittens & David Wainer

At the centre of market-shaping deals and high-stakes disputes, Bennett Jones delivers clarity, strategy and results. Our cross-border teams turn complexity into progress, always focused on what drives your success.

Your Guide to Legal Solutions: Privacy and Data Protection

All the details you need, right at your fingertips. Download our brochure and explore our services.

The Bennett Jones Story

At Bennett Jones, legal solutions are our starting point. What drives us forward is knowing our clients inside and out—their ambitions, obstacles and success metrics.

For more than a century, we have shaped outcomes that matter in business, in law and in the broader Canadian landscape. And our commitment extends beyond legal matters: we invest deeply in the communities in which we live and work.