Ghiles Helli Lawyer

Ghiles Helli Lawyer

Office

  • Montréal

Phone number

514 397-2108

Bar Admission

  • Québec, 2022

Languages

  • Arabic
  • English
  • French

Profile

Associate

Ghiles Helli joined the Lavery team as a student in 2021. He holds a bachelor's degree in law from Université de Montréal, as well as a master's degree in business law with a concentration in Technology Law. Prior to his legal studies, Ghiles completed a bachelor's degree in biochemistry with a specialization in molecular medicine in 2015.

Ghiles served as a Political Advisor for the Quebec Cabinet of the Deputy Minister for Government Digital Transformation between 2019 and 2021. He was responsible for overlooking numerous files concerning cybersecurity, artificial intelligence, digital identity and privacy.

Education

  • LLM, Université de Montréal, 2022
  • LLB, Université de Montréal, 2020
  • B. (Sc.), Université de Montréal, 2015

Boards and Professional Affiliations

  • Departmental Cyber Security Advisory Committee
  • Departmental Advisory Committee on Artificial Intelligence
  1. Bill C-8: A new federal cyber security framework for telecommunications and critical cyber systems

    Bill C-8 received royal assent on June 15, 2026. It deserves special attention. The bill marks a shift in our approach to cyber security, giving the federal government the means to respond quickly when a threat is identified. It also requires certain parties to comply with higher standards, and imposes real penalties for noncompliance. The legislation is structured around two main areas. The first strengthens the Telecommunications Act by empowering the Governor in Council and the Minister of Industry to impose specific measures through Orders in Council and Ministerial Orders. The second establishes the Critical Cyber Systems Protection Act (the “CCSPA”), targeting vital systems and services. With these legislative changes, cyber security is emerging from the shadows—it is becoming a matter of governance and compliance. And with the adoption of this Act, technology decisions, supplier management, and responses to cyber security incidents will need to be more robust, better regulated, and duly documented. We believe that organizations that are proactive in preparing their governance and evidence practices, as well as their contingency plans, will be more agile and more credible in the eyes of their clients and partners. That said, an important distinction must be made from the outset: the amendments to the Telecommunications Act set forth in Part 1 are now in force, whereas the CCSPA, as provided for in Part 2, will come into force following one or more Orders in Council. To date, Schedule 2 of the CCSPA, which is meant to identify the classes of designated operators and their corresponding regulatory bodies, remains blank. Key takeaways at a glance - Bill C-8 introduces: (i) the authority to issue telecommunications orders (that is, Orders in Council and Ministerial Orders); (ii) guidelines for a mandatory program for certain critical cyber systems, subject to the CCSPA coming into force and future designations; and (iii) strengthened enforcement in terms of information exchange, audits, administrative monetary penalties, and violations. Part 1 of the Act – Telecommunications: Security becomes the driving force for action Bill C-8 explicitly enshrines security in Canada’s telecommunications policy by adding the objective of “the promotion of the security of the Canadian telecommunications system.” It provides the legal basis for measures that are now designed to be direct, swift, and enforceable. An important element of the Act, both for its application and for defining the nature of the threats it addresses, is the clarification that “interference with or manipulation, disruption or degradation of a telecommunications system include actions of a technical nature that impede the operation of the telecommunications system but do not include the e?ect of lawful expression, persuasion or political debate.” The text thus expressly provides room for freedom of expression and lawful public debate. Part 1 of the Act includes a two-tier enforcement mechanism: Orders in Council and Ministerial Orders (issued by the Minister of Industry). Orders in Council The Governor in Council may issue an Order in Council if they have reasonable grounds to believe that the measure is necessary to secure the system against a threat, and that it is reasonable in relation to the gravity of that threat. Specifically, the order may: Prohibit telecommunications service providers (”TSPs”) from using the products and services provided by a specified person in, or in relation to, their networks or facilities; or Order the removal of products supplied by a specified person. Bill C-8 imposes a proportionality requirement: the scope and content must be necessary and reasonable in view of the gravity of the threat. The Order in Council takes precedence over any conflicting decisions, orders, or authorizations, including those under the Radiocommunication Act. Furthermore, the government does not bear the economic cost—no compensation is payable for financial losses attributable to the Order in Council. This is, in a sense, the “heavy artillery” of the Act. The Order in Council may also include a prohibition against disclosing its existence or all or part of its content. Before imposing such a prohibition, the Governor in Council must, in particular, consider the extent to which disclosure could undermine the objective of the order, the necessity of the prohibition in light of the nature of the threat, the possibility of limiting its scope, its impact on the transparency and accountability of the Government of Canada, and any representations made by the affected TSPs. Before issuing the order, the Governor in Council must also consider the measure’s operational impact on the affected TSPs, its financial implications, its effect on the provision of telecommunications services in Canada—including the confidentiality and security of telecommunications—as well as its potential impacts on Canadians’ privacy. Ministerial Orders The Minister of Industry may, by Ministerial Order, impose highly operational measures when they are necessary and reasonable in view of a threat. The order may, in particular: Prohibit the use of specific products or services, order the disposal of personal information, and impose conditions on the use and provision of services; Prohibit or force TSPs to terminate service agreements; Require review processes for networks, facilities, and procurement plans; Require security plans, vulnerability assessments, and mitigation measures; Require the implementation of standards; Require a backup system; Prohibit TSPs from providing services to a specified person; Order the suspension of the provision of services to a specified person for a specified period; Prohibit certain upgrades; or Order TSPs to do or refrain from doing any specified act, subject to the limitations provided for by the Act. As with Orders in Council, the minister must consider the operational and financial impacts, the effect on the provision of services—including the confidentiality and security of telecommunications—and the potential implications for the privacy of Canadians. The minister may not order the interception of a private communication or a radio-based telephone communication, nor the decryption of an encrypted private communication. The Ministerial Order also comes with a provision stating that no compensation will be paid. The Act also sets forth a specific limitation: the suspension of service to an individual may be ordered only if the order is necessary to secure the Canadian telecommunications system against a threat of a technical nature specified in the order. Like an Order in Council, a Ministerial Order may include a prohibition on disclosure. Before imposing such a prohibition, the minister must consider comparable factors, including the impact of non-disclosure on the principles of transparency and accountability of the Government of Canada. Specifics regarding the publication of orders In principle, Orders in Council and Ministerial Orders must be published in the Canada Gazette within 90 days of their issuance, but the minister making the order may specify in the text itself that it need not be published. In addition, incorporation by reference facilitates the integration of technical documents that are subject to change. We can therefore expect this process to adopt international technical standards. Collection of information by the minister Bill C-8 provides that the minister may require the disclosure of information if they have reasonable grounds to believe that it is both reasonable for the information to be provided in view of the gravity of the threat and that it is necessary. However, a confidentiality framework is in place for the information provided, particularly when it involves trade secrets or financial, commercial, scientific, or technical information. Personal information and de-identified information are also subject to protective measures. The text also provides for the exchange of information among various federal authorities, as well as with the provinces, foreign countries, or certain international organizations under written agreements. The scope and content of personal or de-identified information must be reasonable in view of the gravity of the threat. The Act also provides for the disposal of personal or de-identified information when it is no longer needed. It should also be noted that personal and de-identified information are deemed to be confidential information for the purposes of Part 1, even if they have not been expressly designated as such. Part 2 of the Act – The Critical Cyber Systems Protection Act (CCSPA) It is important to note that this part of the Act will not take effect until the date or dates set by Order in Council. Furthermore, its actual applicability will depend on future designations, since Schedule 2 is currently blank. The framework has therefore been adopted, but it has yet to be implemented. Key concepts: What the Act actually aims to achieve The CCSPA applies to critical cyber systems as strictly defined by the text, that is, a cyber system that, if its confidentiality, integrity or availability were compromised, could affect the continuity or security of a vital service or vital system. The definition of “cyber system” is intentionally broad. In practice, the Act is therefore not limited to a “network” in the traditional sense; it can encompass platforms, cloud environments, control systems, digital services, and interconnected technical assets, provided that if they were compromised, it could affect a vital service or system. The version of the text that has been assented to also adds the definition of “internal audit”, which is an independent and objective review conducted in accordance with internationally recognized guidance on professional internal auditing practices. This reinforces the idea that the expected compliance goes beyond simply adopting internal policies and, where necessary, requires structured assurance mechanisms. How organizations are designated A “designated” operator that controls, operates, or owns a critical cyber system is required to comply with the provisions of the CCSPA and its regulations pertaining to that cyber system. How are operators designated? First, “vital services” and “vital systems” are those listed in Schedule 1, namely: telecommunications services, interprovincial or international pipeline and power line systems, nuclear energy systems, transportation systems that are within the legislative authority of Parliament, banking systems, and clearing and settlement systems. By Order in Council, items may be modified, or added to or removed from this schedule within the scope of authority provided for by the Act. Second, the Act includes a schedule—which is currently blank—that allows for the establishment of classes of operators and regulatory bodies responsible for these vital services or systems. In practice, compliance depends on both the vital service or system in question (Schedule 1) and the operator class in which the organization is classified (Schedule 2). Cyber security programs: The foundational requirement At the heart of the CCSPA is the requirement to develop a cyber security program. After being designated through an amendment to Schedule 2, an operator must establish, within 90 days, a program relating to its critical cyber systems. This program must include measures, in accordance with the regulations, to identify and manage organizational risks (including supply chains and the use of third-party products and services), protect critical cyber systems, detect incidents and minimize their consequences, as well as any other measures required by the regulations. The program is therefore not merely a policy—it must cover the entire risk management cycle and be amenable to a “compliance” review. This will force organizations and companies to respond quickly when such a designation is made. The Act also imposes a monitoring mechanism: once the program is established, the operator must notify the relevant regulatory body in writing. The Act also requires that any such program be updated periodically. Lastly, reporting requirements apply when significant changes occur, including changes to ownership or control, supply chains, and the use of third parties. This approach transforms cyber security into a governance and maintenance requirement, rather than a one-time project. Supply chains and third parties: From assessment to mitigation The CCSPA explicitly emphasizes supply chains. Once the risks related to supply chains and third parties have been identified in the program (paragraph 9(1)(a)), the designated operator is required to mitigate them (section 15). The verb is important: it is not enough simply to “observe” or “monitor”; the law requires an active mitigation effort, which must be demonstrable. The Communications Security Establishment (the “CSE”) may develop guidelines on mitigating risks associated with supply chains and the use of third-party products and services, drawing on internationally recognized frameworks. The appropriate regulator may also provide the CSE with information—including confidential information—regarding the program or the measures taken, so that the CSE can provide advice, guidance, and services in accordance with its mandate. For organizations, this signals a convergence between regulatory requirements and technical expectations: managing suppliers, access, updates, software dependencies, and subcontractors is becoming a core component of compliance. Incident reporting: A requirement for speed and coordination The CCSPA establishes a requirement to report cyber security incidents to the CSE. Every designated operator must report any cyber security incident involving one of its critical cyber security systems within the prescribed time limits, which may not exceed 72 hours. The definition of “cyber security incident” covers an incident (including an act, omission, or circumstance) that interferes or may interfere with the continuity or security of a vital service or system, or the confidentiality, integrity, or availability of a critical cyber system. After filing a report with the CSE, the operator must, without delay, notify the appropriate regulatory body and provide it with a copy of the incident report. The text specifies that these obligations do not diminish the obligations arising from the Personal Information Protection and Electronic Documents Act. Cyber security guidelines: The mandatory response tool The CCSPA provides for a particularly intrusive measure: cyber security directions. By Order in Council, the government may direct any designated operator or class of operators to comply with any measure set out in the direction for the purpose of protecting a critical cyber system, but only if it has reasonable grounds to believe that the direction is necessary. Before issuing the order, the government must consider the operational impacts, public safety, privacy protection, financial impacts, and the impacts on the provision of vital services and systems. The scope and content must be reasonable in relation to the protection objective, and the operator in question is required to comply. The law also sets out two explicit limitations: the Governor in Council may not order the decryption of an encrypted private communication or the interception of a private communication or a radio-based telephone communication. In addition, a safeguard related to awareness has been put in place: an operator cannot be found guilty of contravening the direction unless they were notified of it or reasonable steps were taken to inform them of it. However, it will be important for an operator not to ignore the notifications received, even if they sometimes seem minor. The operator in question may not disclose the existence or content of a direction except to the extent necessary to comply with it. This requirement has a significant practical impact: it mandates the implementation of a “need-to-know” policy both internally and with respect to suppliers, subcontractors, insurers, and other partners. Information: Confidentiality, sharing, and removal of personal information The CCSPA establishes a comprehensive information-sharing framework, in particular to support the making, amending or revoking of directions. For purposes related to the making, amending or revoking of a direction, certain entities may collect and share information—including confidential information—with one another. The law also regulates the disclosure and use of confidential information and provides for exceptions, particularly when disclosure is required by law or necessary to protect vital services, systems, or cyber systems. “Provable” compliance The CCSPA requires the maintenance of records covering program implementation, reported incidents, steps taken to mitigate third-party risks, compliance with directions, and any other matters specified by the regulations. These documents must be kept in Canada in accordance with the terms and conditions prescribed by the regulations or, in the absence thereof, by the appropriate regulator. This requirement is central: it transforms compliance into a burden of proof. The regulatory framework provides for broad audit and enforcement powers, which are exercised by different authorities—the Superintendent of Financial Institutions, the Minister of Industry through inspectors, the Bank of Canada, the Canadian Nuclear Safety Commission, the Canadian Energy Regulator, and the Minister of Transport—depending on the sector. The provisions governing access to premises, the examination of cyber security systems, and the reproduction and temporary seizure of documents and systems are detailed in the CCSPA. Mechanisms for internal audits and compliance orders are in place, depending on the authority. The law prohibits obstruction and the provision of false or misleading information, which underscores the importance of the quality of the information provided. The version of the text that has been assented to also adds an explicit provision: the CCSPA does not infringe upon solicitor-client privilege or the professional secrecy of lawyers or notaries. Watch out for penalties! It should be noted that the law provides for substantial administrative penalties, as well as criminal offences (including imprisonment). Executives and directors may be considered co-perpetrators of a violation or offence, as the case may be. Ongoing violations can be counted on a day-by-day basis. Under Part 2 of the Act, administrative penalties may reach $500,000 for an individual and $15,000,000 in other cases. Furthermore, certain violations constitute criminal offences that are punishable, in some cases, either through charges or summary proceedings. Depending on the nature of the violation and whether the offender is an individual, imprisonment may be possible. How we can assist you in implementing Bill C-8 In particular, we can assist you with the following: Regulatory positioning Mapping your exposure (in terms of telecommunications, vital services or systems, and your current or anticipated designation) and establishing a realistic roadmap, prioritized by risk Responding to the imposed measures Supporting the receipt, analysis, and implementation of Orders in Council, Ministerial Orders, or directions Compliance Establishing or strengthening governance, record-keeping, and internal processes (including requests for information, audits and inspections, and the traceability of decisions) Third parties and procurement Reviewing and negotiating contracts and security requirements (including incident reporting, cooperation, audits, subcontracting, corrections, and withdrawal/replacement) and documenting mitigation measures Incidents and enforcement Supporting incident response (including triage, notifications, and the preservation of evidence) and managing the risk of penalties and criminal liability, including for executives and directors Conclusion In practice, organizations that may be affected would be wise to start preparing now, even though Part 2 of the law is not yet in force. The practical scope of the Act will depend on the CCSPA coming into force, the adoption of implementation regulations, and the inclusion in Schedule 2 of the classes of operators concerned and their corresponding regulators. In the meantime, organizations that begin structuring their governance, documentation, and third-party management now will be better positioned to adapt quickly once the sector-specific requirements are clarified.

    Read more
  2. Behind the Scenes of Sports, Data Never Takes a Break

    The World Anti Doping Agency suffered a data breach in 2016­—a vivid illustration that even the most prominent sporting institutions are not immune to cyber incidents. The authorities have now formalized what was previously just an observation: In a bulletin published in 2024, the Canadian Centre for Cyber Security warned that the entire sports ecosystem—spectators, athletes, organizations and government representatives—is the target of cyberattack campaigns.  Malicious actors will attempt extortion through business email compromise, ransomware attacks, phishing, malicious websites and search engine poisoning, among others. Take heed, as when an incident occurs that is serious enough to require a report to the authorities, it is often too late to establish sound governance and engage in due diligence. The sporting competitions of today are producing massive amounts of data. The quantity is staggering, and the data itself almost Orwellian. Check the tables below to see for yourself. Data collected on athletes  League Information collected NFL Performance data (statistics, position and movement metrics, speed, and passing, rushing and receiving yards) Medical and/or health data (examinations, injuries, concussion protocols) Substance screening data Data on disciplinary actions and investigations Professional and contractual data Travel, logistics and security data NHL Performance data Medical and/or health data (examinations, injuries, concussion protocols) Substance screening data Data on disciplinary actions and investigations Professional and contractual data Travel, logistics and security data MLB Performance data Medical and/or health data (examinations, injuries, concussion protocols) Substance screening data Data on disciplinary actions and investigations Professional and contractual data Travel, logistics and security data   Collection of customer information online  League Information collected NFL  Information provided by individuals  Identifiers: name, email, address, telephone number, date of birth; unique identifiers (username, password, SSN and other government identifiers if required, e.g. for awards) Demographic data and other protected categories: gender, race, ethnicity, sexual orientation Financial and commercial information: payment data, purchase history Real-time geolocation; precise geolocation Communication and marketing preferences Favorite team and inferences about preferences Audio, electronic and visual information (e.g., photos provided) Biometric data, if you opt for biometric authentication at the stadium; with consent and additional notice if required Information about your contacts (name, email) that you share; if authorized, access to your contacts, calendars and photos Search queries Content posted (comments, forums) Professional and employment information Education information Information that may be health-related (e.g., accessible seating) Correspondence, waivers, consents and other information sent Automatic collection  Device and network identifiers and technical data: IP address, MAC address, advertising identifiers, device type, browser, OS Usage: page views, links clicked, browsing journeys, application usage data Tracking and emails: cookies, pixels, tags, interaction with emails (opened emails, clicks) Social media (if linked): data received according to your settings and the platform’s policy Logs and traffic: server logs, stadium Wi-Fi traffic Video and audio recordings: CCTV and pictures taken or video recorded during events   NHL  Information provided by individuals Identifiers and contact information (name, email, telephone number, address, date of birth) Commercial information (payments, purchases, services) Demographic data (language, age, gender, race, ethnicity, household composition and income) Preferences (favourite team, favourite players) Photos and/or videos Content, feedback (comments, surveys) Contact information of friends Application data (resume, references, checks permitted) Automatic collection Activity and interactions (content viewed, bids, purchases, time spent, cookies, tags), access methods (browser, OS, IP address, browsing history before and after) Device information and identifiers (type, unique identifiers, local content if allowed) Location (GPS, Bluetooth, Wi-Fi, cells) Inferences about preferences Commercial information about transactions (e.g., timestamps) Collection from third parties Member clubs (ticketing, login credential, usage logs) Fanatics, NHL Shop, NHL Auctions (name, email, items purchased; marketing engagement statistics) Other business partners, public sources, commercial sources (data brokers) Connected social media (according to the platform’s settings and policies) NHL teams* Contact information: name, email address, home address, gender, date of birth, telephone number (e.g., ticket purchase, ticket transfer, account creation, inquiries, contests, promotions) Demographic data and preferences (age group, race, gender; preferred events, preferred products, e.g., surveys) Health data related to accessibility needs Video surveillance in venues (security; sharing limited by law) Anonymous traffic analysis and device counting (cameras, technological devices; Wi-Fi); statistics that can be shared with partners Depersonalized web analytics (Google Analytics); opt-out option Online advertising and/or remarketing (Google, Facebook, LinkedIn, etc.) through cookies; opt-out mechanisms (platform settings; DAAC) Geolocation through applications if enabled Social media: profile data and authorized interactions Technical data (IP, browser, OS, resolution, location, language, origin, keywords, pages viewed, data entered, ads viewed), identifiers (IDFA, AAID), connection information (operator, ISP, Wi-Fi); ability to recognize a device) MLB Information provided by individuals Identifiers and contact information: full name, email address, home address, telephone numbers, date of birth Security and authentication: password Payments: payment details Demographic data: demographic characteristics Content and recordings: voice recordings, audiovisual recordings Preferences and interests: information about your interests and preferences Activity and event related data: information requested for an activity or event (e.g., emergency contact) Sensitive personal information: as defined by applicable laws (e.g., racial or ethnic origin; health information such as disabilities or allergies) Automatic collection  Technical and usage data: IP addresses, device data, usage data Location and contacts: location data; contacts saved on your mobile device Collection from third parties Data from third parties and integrations: information provided by other companies if individuals connect their services * This data is collected about website users, people who visit venues, people who apply for jobs or participate in contests, people who submit drafts.   How leagues are structured Regarding privacy and personal information, we must look at how sports leagues are organized to understand who does what. In most cases, sports leagues are non-profit organizations or corporations. An entire framework of rules is built around these structures, defining both how governance is done and what business model is used. First, there are the articles of association and by-laws, which dictate governance, team admissions, voting rights, and the powers of the commissioner or board of directors. There are also the sporting and competition regulations regarding eligibility, game schedules, transfers, drafts, salary caps and cost control mechanisms. The leagues also adopt integrity and security policies against doping, betting and manipulation, harassment and abuse, as well as commercial agreements covering broadcasting, sponsorships, ticketing and data leveraging, among others. There can also be collective agreements with players’ associations and formal dispute resolution mechanisms. In this environment, the league plays a central role. It generally has the power to adopt, interpret and amend its rules; admit teams; manage expansion and relocation projects and changes of control; as well as the power to impose sanctions such as fines, point deductions, suspensions or exclusions. It also centralizes strategic commercial rights, media rights, trademarks and data, and it implements revenue-sharing policies designed to maintain a competitive balance between teams. Personal information: the roles of each Teams In day-to-day relations with athletes and customers, teams are generally the main point of contact. They sign contracts with players, sell tickets, manage subscriptions and operate online stores and loyalty programs. In practice, teams are often the ones that collect personal information, that explain what the information is used for, that decide what information needs to be collected and that put in place security and incident management measures. Teams must therefore be able to clearly inform athletes and customers about the purposes for which personal information is collected, the means by which it is collected, the categories of information collected, who receives the information, and the rights that  athletes and customers have. Teams must limit collection to what is necessary. They must ensure that information is accurate; they must obtain valid, manifest, free, informed and explicit consent for sensitive information such as health or biometric data; they must implement security measures adapted to risks; they must manage and report confidentiality incidents likely to cause serious harm; they must respond to requests for access and rectification; and they must stringently govern the sharing of information with service providers and mandataries. Athletes and customers often see the team as the true holder of their data. Leagues The role leagues play regarding personal information is more difficult to understand, as it varies depending on activities. When a league directly collects information from an individual, for example through an official application, a broadcasting platform or a transactional site for its own purposes, it must assume responsibilities comparable to those a team has. This is what MLB Advanced Media does, for example, defining itself as a “data controller” with respect to its customers’ data. But in many cases, the league acts behind the scenes. In some respects, it acts as a mandatary for the teams, negotiating and signing technology contracts, broadcasting agreements and other commercial agreements that will be used by the teams. In other respects, it acts as a service provider, offering centralized technology platforms, ticketing systems, data infrastructure and shared administrative services. Under Quebec law, these two roles—mandatary and service provider—are treated the same: The team can transmit to the league the information it needs to perform the mandate or service contract without having to ask for the consent of each person again, provided that a written agreement imposes clear measures to protect privacy, limits the use of data to the sole purposes of the mandate or service and governs data retention. The league must also promptly inform a team’s privacy officer of any privacy breach or attempted privacy breach and allow the officer to conduct checks. Also, teams and the league can always choose to base certain exchanges of information on the explicit consent of athletes or customers. However, such consent must be genuinely explicit, free, informed, given for specific purposes and presented separately when asked to be given in writing. Conclusion Although professional leagues are the ones in the spotlight, the same logic applies to amateur or non-professional sports organizations. In all cases, the relationship between the league, the team and the athlete or customer must be clearly governed from a privacy standpoint. Sports organizations should map the flow of personal information, harmonize the information messages they give to the those concerned, establish a standard agreement governing the sharing of information between teams and the league, provide simple mechanisms for access and rectification, and have key employees trained in privacy matters. Incorporating these points into articles of association, by-laws and team and league agreements will reduce risks and strengthen the confidence of athletes, parents, fans and business partners. Yet, a fundamental question still remains: Given that by law, data can only be collected for serious and legitimate reasons (necessity criterion), is the mass of information currently collected in the sports ecosystem really warranted? Sports organizations will have no choice but to delve into this strategic issue. 

    Read more
  3. Webinar: Understanding the Legal Framework for User-Generated Content (UGC) (In French only)

    We invite you to our upcoming webinar: “Understanding the Legal Framework for User-Generated Content (UGC).” Learn directly from Sylvain Pierrard and Ghiles Helli as they reveal their best practices and winning strategies. Moderator France Camille De Mers will facilitate this panel discussion, ensuring a rich and dynamic dialogue.  Together, we’ll explore how to legally frame your UGC strategy. We’ll tackle the complex issues of intellectual property and the critical challenges of personal data protection, illustrating every concept with concrete, real-world examples.  The right legal framework for user-generated content (UGC) is your essential defence in the current digital landscape, protecting your business and users while building transparency and trust online. This framework covers aspects such as the use of content protected by intellectual property rights and compliance with applicable privacy laws. Understanding the legal implications of using Terms of Use is crucial to effectively navigating this evolving environment.  When: November 26th, 2025, From 10 A.M. to 11 P.M. In order to receive an attestation of attendance for continuing education purposes, please use your professional email address for registration and be sure to attend the entire webinar. Register

    Read more
  4. Data Anonymization: Not as Simple as It Seems

    Blind spots to watch for when anonymizing data Anonymization has become a crucial step in unlocking the value of data for innovation, particularly in artificial intelligence. But without a properly executed anonymization process, organizations risk financial penalties, legal action and serious reputational harm, with potentially significant consequences for their operations. Understanding the anonymization process What the law says Under Quebec’s Act respecting the protection of personal information in the private sector (the “Private Sector Act”) and the Act respecting Access to documents held by public bodies and the Protection of personal information (the “Access Act”), information concerning a natural person is considered anonymized if it irreversibly no longer allows the person to be identified directly or indirectly. Since anonymized information no longer qualifies as personal information, this distinction is of crucial importance. However, beyond this definition, neither Act provides details on how anonymization should actually be performed. To fill this gap, the government adopted the Regulation respecting the anonymization of personal information (the “Regulation”), which sets out the criteria and framework for anonymization, grounded in high standards of privacy protection. What organizations need to know before starting Under the Regulation, before beginning any anonymization process, organizations must clearly define the “serious and legitimate purposes” for which the data will be used. These purposes must comply with either the Private Sector Act or the Access Act, as applicable, and any new purpose must meet the same requirement. The process must also be supervised by a qualified professional with the expertise to select and apply appropriate anonymization techniques. This supervision ensures both the proper implementation of the chosen methods and the ongoing validation of technological choices and security measures. The four key steps of data anonymization   DepersonalizationThe first step is to remove or replace all personal identifiers, such as names, addresses and phone numbers, with pseudonyms. It is essential to anticipate how different data sets might interact, in order to minimize the risk of re-identifying individuals through cross-referencing. Preliminary risk assessmentNext comes a preliminary analysis of re-identification risks. This step relies on three main criteria: individualization (inability to isolate a person within a dataset), correlation (inability to connect datasets concerning the same person) and inference (inability to infer personal information from other available information). Common anonymization techniques include aggregation, deletion, generalization and data perturbation. Organizations should also apply strong protective measures, such as advanced encryption and restrictive access controls, to minimize the likelihood of re-identification. In-depth risk analysisAfter the preliminary phase, a deeper risk analysis must be conducted. While no anonymization process can eliminate all risk, that risk must be reduced to the lowest possible level, taking into account factors such as data sensitivity, the availability of public datasets and the effort required to attempt re-identification. To sustain this low level of risk, organizations should perform periodic reassessments that account for technological advances that could make re-identification easier over time. Documentation and record-keepingFinally, organizations must keep a detailed record describing the anonymized information, its intended purposes, the techniques and security measures used, and the dates of any analyses or updates. This documentation strengthens transparency and demonstrates that the organization has fulfilled its legal obligations regarding anonymization.

    Read more
  1. Lavery assists Agendrix in obtaining two ISO certifications for data security and privacy

    On February 6, 2023, Agendrix, a workforce management software company, announced that it had achieved certification in two globally recognized data security and privacy standards, ISO/IEC 27001:2013 and ISO/IEC 27701:2019. This made it one of the first staff scheduling and time clock software providers in Canada to obtain these certifications. The company is proactively engaging in all matters related to the security and confidentiality of the data processed by its web and mobile applications. The ISO/IEC 27001:2013 standard is aimed at improving information security systems. For Agendrix’s customers, that means its products comply with the highest information security standards. ISO/IEC 27701:2019 provides a framework for the management and handling of personal information and sensitive data. This certification confirms that Agendrix follows best practices and complies with applicable laws. A Lavery team composed of Eric Lavallée, Dave Bouchard, Ghiles Helli and Catherine Voyer supported Agendrix in obtaining these two certifications. More specifically, our professionals assisted Agendrix in the review of their standard contract with their customers, as well as in the implementation of policies and various internal documents essential to the management of personal information and information security. Agendrix was founded in 2015, and the Sherbrooke-based company now has over 150,000 users in some 13,000 workplaces. Its personnel management software is a leader in Quebec in the field of work schedule management for small and medium-sized businesses. Agendrix’s mission is to make management more human-centred by developing software that simplifies the lives of front-line employees. Today, the company employs more than 45 people.

    Read more
  2. Six new members join Lavery’s ranks

    Chanel CalabroChanel is a member of the Business Law group. She works primarily in corporate finance, mergers and acquisitions, and corporate law."Lavery is at the centre of developing companies in Quebec. It is for me an excellent opportunity to work with inspiring professionals in a work environment that encourages development and initiative. I am very enthusiastic about working in a practice that offers me the opportunity to use my past experiences to provide added value to our clients." Simon Gagné-CarrierSimon is joining our Labour and Employment Law group. He also practices in Municipal Law. He joined the Lavery team as a student in 2022. He completed his bachelor's degree in civil law and a master's degree in business administration at the Université de Sherbrooke. "The team of professionals who make up the firm and who have guided me are committed to strong and important values such as mentoring, professional development and collaboration between peers. It is an ideal environment for a young lawyer." Ghiles HelliGhiles is joining our Business Law Group. He is a member of our mergers and acquisitions team. He assists our partners in advising clients on the legal impacts of the implementation of new technologies and on cybersecurity. "I chose to do my internship at Lavery because of their expertise in technology law and in mergers and acquisitions law, my two legal passions. It is also a great opportunity for me to pursue my professional development with mentoring that is second to none." Kabrina PéronKabrina is joining our Labor and Employment Law group. She joined the Lavery team as a student in the winter of 2021. "Throughout my experience at Lavery, I have had the opportunity to collaborate with passionate and highly experienced professionals on various cases, who were especially committed to ensuring my professional development. It is ideal guidance at the beginning of my career." Daphné Pomerleau-NormandinDaphné is a member of the Litigation and Conflict Resolution group and focuses her practice on commercial and civil litigation. "Joining Lavery involves being part of an environment that is an ideal combination of autonomy and team spirit." Jean-Vincent Prévost-BérubéJean-Vincent is joining our Business Law Group and practises mainly in transactional and commercial law. He has joined the Lavery team for his articling term in the winter of 2022. "Team collaboration and unity are definitely the firm’s strengths. For me, Lavery was the choice of a firm, but above all of a team. I appreciate being able to collaborate on challenging cases as well as the trust and confidence that we are quickly given in the management of these cases."  

    Read more