Executive Summaries Sep 16, 2022

Bill C-26: The Federal Government Takes a Closer Look at Cybersecurity and Privacy

On June 14 and 16, 2022, the federal government tabled Bills C-26 and C-27 aimed at protecting the privacy and cybersecurity of citizens in addition to regulating artificial intelligence in Canada.

More specifically, Bill C-26An Act respecting cyber security, amending the Telecommunications Act and making consequential amendments to other Acts (the “Bill”) provides new cybersecurity obligations of which businesses under federal jurisdiction should be aware.

Telecommunications: Securing the System Against External Threats

On the one hand, the Bill modifies the Telecommunications Act to further protect the Canadian telecommunications system and prevent interference from threats. The Canadian Telecommunications Policy is amended to “promote the security of the Canadian telecommunications system.”

In practice, this results in the granting of various powers to the Governor in Council when of the view that it is necessary to secure the Canadian telecommunications system against threats of interference, manipulation, or disruption. More specifically, the Governor in Council could issue various orders to:

  • prohibit telecommunications service providers from using in or in connection with all or any part of their telecommunications networks or facilities any products and services provided by any person it specifies;
  • order such suppliers to remove from all or part of their telecommunications networks or facilities all products supplied by any person it specifies;
  • prohibit or order the suspension of the provision of the Services to any person it specifies;
  • impose different terms of use;
  • prohibit or require the termination of certain service agreements;
  • require the development of security plans; and
  • require assessments to identify vulnerabilities in networks or facilities and take action to mitigate any vulnerabilities.

The foregoing is over and above the general obligation to provide information. As for the Minister of Industry, he or she may require any relevant information concerning the issuance of an order or its modification or revocation.

Administrative and pecuniary sanctions are included to ensure compliance with the various decrees that may be adopted by the Governor in Council. They range from $25,000 to $50,000 for a repeat offence for a natural person, but they are much larger in other cases, ranging from $10 million to $15 million for a subsequent offence.

Cybersecurity: Complying with New Obligations 

The Bill also enacts the Critical Cyber Systems Protection Act (hereinafter “CCSPA”) which aims to ensure the security and resilience of critical cyber systems under the federally regulated private sector. "Cybersystem” means a technological infrastructure system used to receive, transmit, process, or collect data.

The CCSPA essentially has the following four objectives:

  • identify and manage risks to the cybersecurity of critical cyber systems, including risks associated with supply chains and the use of third-party products and services;
  • protect critical cyber systems from compromise;
  • detect cyber security incidents that affect or could affect critical cyber systems; and
  • minimize the consequences of cyber security incidents that affect critical cyber systems.

According to the CCPSA, a “critical cyber system” is “a cyber system that, if its confidentiality, integrity or availability were compromised, could affect the continuity or security of a vital service or vital system.” The various services and systems currently considered to be critical are:

  • telecommunications;
  • interprovincial or international pipeline and power line;
  • nuclear energy;
  • transportation systems under the legislative jurisdiction of the Federal Parliament;
  • banking; and
  • clearing and settlement

To achieve its goals, the CCPSA requires the categories of operators listed in Schedule II to comply with the provisions of the law through four main obligations and to keep records concerning their implementation.

Setting Up of a Cybersecurity Program

First, within 90 days of becoming a member of a designated operator category, the operator will be required to set up a cybersecurity program for its critical cyber systems.

This cybersecurity program will have to meet the various regulatory requirements that will eventually be adopted, but especially in connection with the four main objectives of the statute mentioned above. This cybersecurity program must be submitted to the competent regulatory body, determined according to the category of designated operator. The program will be subject to notification in the event of a change in ownership or control of the designated operator or a material change to the supply chain.

Protect Supply Chains

Second, the CCPSA aims to protect the supply chains of critical services and systems. Consequently, designated operators must take all reasonable measures, including those provided for by regulation as soon as risks to the supply chain are identified.

Note that the Communications Security Establishment (the “CSE”) could help any designated operator to mitigate the risks associated with a supply chain by providing various advice.

Report Any Security Incident 

Third, designated operators will be required to promptly report any security incident involving one of its critical cyber systems to the CSE to obtain assistance. The designated operator must also notify its competent regulatory body and provide it with a copy of the incident report.

Recall that a cybersecurity incident is defined as an incident that could harm the continuity or security of the system or its confidentiality and integrity.

Comply with Governor in Council’s Directives

Finally, the Governor in Council may, to protect a critical cyber system, issue various cyber security directives that require the compliance of a designated operator.

The federal government advocates a robust approach to the application of the CCSPA by providing for monetary administrative penalties that are capped at $1 million in the case of a natural person and $15 million in other cases.

At present, there are no categories of operators that are provided for in Schedule II, but we can expect them to fall under the legislative jurisdiction of the federal Parliament and affect the various critical services mentioned above.

The BCF team remains on the lookout for developments affecting the Bill. We will keep you informed of any changes, clarifications, or regulations made by the legislator, if applicable.

If you have any questions about the impacts the Bill could have on your business, do not hesitate to contact our team, who will be happy to advise you.

Stay on the lookout!

Subscribe to our communications and benefit from our market knowledge to identify new business opportunities, learn about innovative best practices and receive the latest developments. Discover our exclusive thought leadership and events.

Subscribe

You would also like

Propriété intellectuelle

BCF Professionals Recognized Among the World’s Leading IP Experts

IAM Patent 1000: Seven partners recognized among the most prestigious patent professionals

Laboratoire

Epitopea and MSD join forces to advance immuno-oncology research

BCF is recognized in the 2025 edition of the Chambers Global directory

Data-Privacy

Bill 82: One Step Closer to a National Digital Identity (and Modifications to Other Provisions!)

Entrepreneurship forum

Entrepreneurship Forum: Vision 2025

BCF Stands Out in Legal 500 Canada

Athlete

Protecting Privacy in Sports – Don’t Wait to be Caught Flat-Footed!

data-protection

Obligation to Report Information Security Incidents: The Autorité des Marchés Financiers Catches the Wave and Publishes a New Regulation

Right to Data Portability: Is your Organization Ready?

Tech Forum 360

Tech 360 Forum: Growth and Inflection Points

IAM Strategy 300: Our Partner Ilya Kalnish Is Recognized as One of the World’s Top IP Strategists

IAM Patent 1000: Six Partners Rank Among the Most Prestigious Patent Professionals

Prospera: Québec’s Economic Barometer

Canada's Best Managed Companies: BCF Recognized for 17th Consecutive Year

paul et misha

BCF Strengthens its Expertise in Artificial Intelligence

Three Partners Ranked Among the Top Trademark Professionals in the World Trademark Review 1000

new-partners-2024

BCF Has Appointed Three New Partners

Who’s Who Legal : 5 BCF Professionals Stand Out

BCF extends its Partnership with the Canadian Association of Black Lawyers to a Third Year

Demystifying Privacy Impact Assessments (PIAs)

The Data Processing Agreement: An Essential Resource to Implement

camera-on-a-wall

The Incident Response Plan: the Cornerstone of Effective Crisis Management

forum-privacy-en

Strategic Forum on Enterprise Data Protection

IP_Stars

Managing IP: 5 of our professionals recognized as IP stars

co-branding-stones

Co-branding : Beneficial – Under Certain Conditions

Chambers Canada Ranking: Five of our Lawyers Recognized

Photo of Julie Doré

Julie Doré Takes Over Management of The BCF Business Law Firm

Prospera – Quebec Economic Barometer

IAM Patent 1000: Five Partners Ranked Among the Most Prestigious Patent Professionals

Julien Tricart, Member of the Meritas Sports Law Group

Pride Month: Let’s Create an Inclusive Future

Canada’s Best Managed Companies: BCF Recognized for 16th Consecutive Year

New Privacy Requirements: Is Your Business Compliant?

Every Woman Counts

Strategic Forum on the Role Played by Businesses in the Fight Against Climate Change

BCF Partners with the Canadian Association of Black Lawyers to Promote Diversity in Québec Law Faculties

BCF's More Inclusive Approach: Improved Parental Leave

From Renowned Athlete to Prestigious Lawyer: Focus on a Non-Traditional Legal Career Path

Shaun E. Finn Appointed to the Superior Court of Québec

How to Ensure a Business Succession?

Business black folders on table

Adoption of Bill 78 on Transparency Business: Are You Ready?

Strategic Forum on Market Consolidation and Business Succession

BCF Partners with the Clinique Juridique de Saint-Michel to Promote Access to Legal Studies for Young People from Diverse Communities

BCF Welcomes Two New Lawyers

What Are the Best Practices for Managing Privacy Incidents?

Shaun E. Finn, Co-Author of In the Public Eye: Privacy, Personal Information, and High Stakes Litigation in the Canadian Public Sector

Should Using Personal Information Obtained Without Consent Be Grounds for Class Action Authorization?

Five of our Lawyers Stand out in the 2023 Edition of the Chambers Canada Ranking

Cybersecurity and Privacy in Canada: What You Need to Know About Bill C-27

Is the Loss of Personal Information Sufficient to Justify the Success of a Class Action on the Merits?

Jocelyn Poirier, BCF’s Chief Privacy Officer

Master Classes in Intellectual Property

43 BCF Professionals Stand Out with 78 Nominations in the 2023 Editions of Best Lawyers in Canada and Ones to Watch

Seven New Lawyers Join BCF

Adoption of Bill 96: Be Ready

Pride Month: The Value of Diversity

BCF, the 3rd Largest Law Firm in Québec

Canada’s Best Managed Companies: BCF Recognized for 15th Consecutive Year

BCF Recognized by the Globe and Mail as one of Canada’s top Law Firms

UEAT Technologies Inc. Becomes a Wholly Owned Subsidiary of Moneris Solutions Corporation

Snipcart Inc. Joins Forces with Duda Inc. to Stay Ahead of E-Commerce Trends

Almost Half of the Canadian Businesses Have Little Knowledge of Intellectual Property: Be in the Other Half!

Chambers Canada 2022: BCF Earned Band 1 Ranking in Québec for Corporate and Commercial Law

IAM Strategy 300: Our Partner Ilya Kalnish Is Recognized As One of the World's Top IP Strategists

Rihanna Billionaire: Cosmetics, Licences and Trademarks

Cannabis Industry Still Growing Strong

Seven New Lawyers Join BCF

A Lipstick Like No Other: Guerlain Obtains Registration of a Three-Dimensional Trademark

What is the process for getting a patent?

Free and Open Source Software: opportunities and challenges

What You Should Know About the COVID-19 IP Waiver and Compulsory Licences in Canada

The Official and Common Language of Québec Act: How Will it Affect Your Trademarks and Public Signage?

You Just Invented Something, Now What?

Intellectual Property Issues in the Aerospace Industrie

Halston: The Man Who Sold His Name... and His Mark

3 Reasons Why you Should Develop a Patent Portfolio as an SME

Privacy and Data Protection Class Actions: Trends, Challenges and Best Practices

A First in Canada: Privacy Class Action Dismissed on the Merits

escalier

BCF Welcomes Seven New Lawyers

Collaboration in the Time of COVID-19: Legal Considerations for Successful AI and Healthcare Partnerships

5 Reasons for Startups to Invest in a Patent Portfolio

5 Reasons You Should Care About Patents

Shaun E. Finn and Danielle Miller Olofsson Publish a Unique Practical Handbook on Privacy and Data-Protection Class Actions

What You Need to Know About Patents: How, Why, and Where

Intellectual Property: An Incentive to Create and Invent

What Are the Implications of the End of EU-U.S. Privacy Shield Framework for Your Business?

Investigation on Tim Hortons’ Application

Québec’s Bill 64 to Amend Data Protection Legislation: A Bill with Teeth?

Does the Use of Thermal Imaging Cameras in Stores Comply with Privacy Laws?

COVID-19: Solutions to Address this Situation

COVID-19: Finally a Toolbox for Developers of Geolocalisation Applications

Tracking the COVID-19 Pandemic with Cellphones

COVID-19: Don’t Forget Data Protection When Designing a Response Strategy

Terranova Security Partners with Microsoft

BCF once again ranks as one of Montreal's Top Employers

BCF Names 16 New Partners for Its 25th Anniversary

Joint Controllership or the Risks of using Website Plugins

Are You a Leader or a Follower?Results of the Innovation Survey

Chambers Canada 2020: BCF Recognised in Corporate and Commercial Law

Strategic Forum on Innovation

Different Legislative Approaches to 5G

Innovating to Survive: Are You a Leader or a Follower?

BCF Appointed Canada’s Exclusive Representative to the Unifab College of Experts

Tech Trends of the Past and of the Future

Innovation Needs Protection

Is Your Company Implementing a New Technology System? Remember to Protect Your Data

Investment and Patenting Trends in Artificial Intelligence

5G Technology Is Coming: Legal Questions Abound

Legal Issues Surrounding the Industrial Revolution 4.0

Where Does Québec Stand in Terms of Privacy Class Actions?

De-fogging the Cloud Act

bcf-ilya-kalnish-client-choice

Partner Ilya Kalnish Wins the Prestigious Customer Choice Awards 2019

operating-room

What It Takes for a MedTech Startup to Succeed? The Model and The System

fenetres

Google and CNIL: a Case of Inappropriately Obtained Consent

Best Practices for Québec Companies Receiving European Data

Anonymization? Think Again

The Deep Web and Dark Web Demystified for Businesses

The GDPR is Coming: How to Get Ready

Protection of Personal Data: New Measures Put in Place by the European Union

Is Your Organisation Collecting Too Much Data and Is It Well Protected?

Get the latest thought leadership