For a 2021 version of "Cybersecurity Laws & Regulations in Canada", click here.
Do Canadians and Americans approach cyber security the same way? The answer is a clear and definite no. The resulting differences might surprise you. Although Canada has made significant progress in the cybersecurity laws and regulations since the Digital Privacy Act went into effect in 2018, there is still room for improvement.
The Digital Privacy Act is an amendment to the Personal Information Protection and Electronic Documents Act (PIPEDA), which governs the storage and protection of personal data. While not as restrictive as the European Union’s General Data Protection Regulation (GDPR), regulations under the Digital Privacy Act open Canadian businesses up to significant penalties if they do not safeguard personal data and properly report any breaches that occur to the affected individuals.
Recently, A Centrify study found that 65 percent of data breach victims lost trust in an organization as a result of a security breach. Furthermore, IDC found that 80 percent of consumers in developed nations will defect from a business if their information is compromised in a security breach. These financial and reputational repercussions are one of the many reasons why these laws and regulations are in place, to protect consumers and businesses with sensitive data.
Compared to 51 regions requiring mandatory disclosure in the US, Canada has three provinces that have similar legislative requirements (Alberta, British Columbia, and Quebec) with various levels of security requirements. In Canada, data protection and cybersecurity are governed by a complex legal and regulatory framework. Failure to understand this framework and take active steps to reduce risks (or the impact of such risks when they materialize) can have serious legal and financial consequences for any organization working within Canada. Therefore, it is crucial for organizations that operate or work within Canada to understand this rapidly evolving area of law and governance. These sources of law and governance would impact Canadian organizational decision-making with respect to the development of a plan to address cybersecurity risks.
Within Canada, there are three general (and broad) forms of law that regulate security and privacy in Canada:
2. The provincial variation of PIPEDA in Alberta.
3. Various health information acts, such as the Health Information Protection Act.
Below are the three different forms of legal regulations that are summarized in point form.
Health Information Protection Act
PCI and Ecommerce
Aside from legal obligations, businesses need to also focus on industry regulations that affect privacy and data security requirements. The most common and well known of these regulations are the standards set by Payment Card Industry Data Security Standard (PCI DSS). This PCI compliance standard applies to all merchants that processes, stores, or transmits credit card information, and sets a security standard for businesses and their virtual environment.
There are four distinct levels, with each level having progressively more stringent requirements. For each successful data breach, the compromised merchant is escalated to a higher validation standard and will be required to adhere to the new minimum requirement.
Organizations should regularly conduct an audit of their existing cybersecurity status, including an evaluation of the following:
Cybersecurity in Canada is an area that requires a multi-disciplinary approach, with input from a variety of experts. Although this will require an initial investment of time and resources, organizations that fail to actively address cyber risk may be exposed to serious reputational, financial and legal repercussions if and when a data breach occurs.
That being said, the main difference that arises between the US and Canada, when it comes to cybersecurity, is the proactive stance on consumer protection and information security. Although Canada has made immense strides in recent years, there are other countries that are more proactive, like the US and European Union’s General Data Protection Regulation (GDPR).