Technology and Entertainment

Overview

We offer clients the legal support they need, particularly with regard to drafting and negotiating contracts, commercializing research results, as well as representation before the courts in disputes involving the violation of intellectual property rights.

Our services cover many different sectors including technology, health, biotechnology, cinema, television, software, e-commerce, and music.

Services

  • Preparing and filing applications to register copyrights, trademarks, and domain names in Canada and other jurisdictions
  • Drafting and negotiating confidentiality, non-competition, and sponsorship agreements
  • Advice on corporate and project financing, including start-up companies
  • Negotiations on behalf of or with financial institutions, venture capital funds, and financial backers for start-up capital
  • Applying for tax credits and grants
  • Advice regarding the Charter of the French Language
  • Audits, management, and strategic planning of intellectual property

Technology, health, and biotechnology

  • R&D contracts, material transfers, technology transfers, licenses, distribution and agency agreements, alliances, franchising, clinical and basic research, financing, R&D credits, and assignment of intellectual property rights

Cinema and television

  • Production and co-production agreements, bank financing of tax credits and pre-sales, performance bonds, distribution, licenses, agencies, hiring of artists, purchase of screenplays, revenue insurance, merchandising, escrow agreements, access letters, laboratory services, and assignment of intellectual property rights

Software and e-commerce

  • Software development agreements, acquisitions of systems or software, assignment of copyright, licenses, strategic alliances, hosting of websites, domain name transfers, and computer services, including electronic signatures

Music

  • Recording and tour production agreements, recordings, licenses, assignment of copyright, artist management, and merchandising

 

  1. Bill C-8: A new federal cyber security framework for telecommunications and critical cyber systems

    Bill C-8 received royal assent on June 15, 2026. It deserves special attention. The bill marks a shift in our approach to cyber security, giving the federal government the means to respond quickly when a threat is identified. It also requires certain parties to comply with higher standards, and imposes real penalties for noncompliance. The legislation is structured around two main areas. The first strengthens the Telecommunications Act by empowering the Governor in Council and the Minister of Industry to impose specific measures through Orders in Council and Ministerial Orders. The second establishes the Critical Cyber Systems Protection Act (the “CCSPA”), targeting vital systems and services. With these legislative changes, cyber security is emerging from the shadows—it is becoming a matter of governance and compliance. And with the adoption of this Act, technology decisions, supplier management, and responses to cyber security incidents will need to be more robust, better regulated, and duly documented. We believe that organizations that are proactive in preparing their governance and evidence practices, as well as their contingency plans, will be more agile and more credible in the eyes of their clients and partners. That said, an important distinction must be made from the outset: the amendments to the Telecommunications Act set forth in Part 1 are now in force, whereas the CCSPA, as provided for in Part 2, will come into force following one or more Orders in Council. To date, Schedule 2 of the CCSPA, which is meant to identify the classes of designated operators and their corresponding regulatory bodies, remains blank. Key takeaways at a glance - Bill C-8 introduces: (i) the authority to issue telecommunications orders (that is, Orders in Council and Ministerial Orders); (ii) guidelines for a mandatory program for certain critical cyber systems, subject to the CCSPA coming into force and future designations; and (iii) strengthened enforcement in terms of information exchange, audits, administrative monetary penalties, and violations. Part 1 of the Act – Telecommunications: Security becomes the driving force for action Bill C-8 explicitly enshrines security in Canada’s telecommunications policy by adding the objective of “the promotion of the security of the Canadian telecommunications system.” It provides the legal basis for measures that are now designed to be direct, swift, and enforceable. An important element of the Act, both for its application and for defining the nature of the threats it addresses, is the clarification that “interference with or manipulation, disruption or degradation of a telecommunications system include actions of a technical nature that impede the operation of the telecommunications system but do not include the e?ect of lawful expression, persuasion or political debate.” The text thus expressly provides room for freedom of expression and lawful public debate. Part 1 of the Act includes a two-tier enforcement mechanism: Orders in Council and Ministerial Orders (issued by the Minister of Industry). Orders in Council The Governor in Council may issue an Order in Council if they have reasonable grounds to believe that the measure is necessary to secure the system against a threat, and that it is reasonable in relation to the gravity of that threat. Specifically, the order may: Prohibit telecommunications service providers (”TSPs”) from using the products and services provided by a specified person in, or in relation to, their networks or facilities; or Order the removal of products supplied by a specified person. Bill C-8 imposes a proportionality requirement: the scope and content must be necessary and reasonable in view of the gravity of the threat. The Order in Council takes precedence over any conflicting decisions, orders, or authorizations, including those under the Radiocommunication Act. Furthermore, the government does not bear the economic cost—no compensation is payable for financial losses attributable to the Order in Council. This is, in a sense, the “heavy artillery” of the Act. The Order in Council may also include a prohibition against disclosing its existence or all or part of its content. Before imposing such a prohibition, the Governor in Council must, in particular, consider the extent to which disclosure could undermine the objective of the order, the necessity of the prohibition in light of the nature of the threat, the possibility of limiting its scope, its impact on the transparency and accountability of the Government of Canada, and any representations made by the affected TSPs. Before issuing the order, the Governor in Council must also consider the measure’s operational impact on the affected TSPs, its financial implications, its effect on the provision of telecommunications services in Canada—including the confidentiality and security of telecommunications—as well as its potential impacts on Canadians’ privacy. Ministerial Orders The Minister of Industry may, by Ministerial Order, impose highly operational measures when they are necessary and reasonable in view of a threat. The order may, in particular: Prohibit the use of specific products or services, order the disposal of personal information, and impose conditions on the use and provision of services; Prohibit or force TSPs to terminate service agreements; Require review processes for networks, facilities, and procurement plans; Require security plans, vulnerability assessments, and mitigation measures; Require the implementation of standards; Require a backup system; Prohibit TSPs from providing services to a specified person; Order the suspension of the provision of services to a specified person for a specified period; Prohibit certain upgrades; or Order TSPs to do or refrain from doing any specified act, subject to the limitations provided for by the Act. As with Orders in Council, the minister must consider the operational and financial impacts, the effect on the provision of services—including the confidentiality and security of telecommunications—and the potential implications for the privacy of Canadians. The minister may not order the interception of a private communication or a radio-based telephone communication, nor the decryption of an encrypted private communication. The Ministerial Order also comes with a provision stating that no compensation will be paid. The Act also sets forth a specific limitation: the suspension of service to an individual may be ordered only if the order is necessary to secure the Canadian telecommunications system against a threat of a technical nature specified in the order. Like an Order in Council, a Ministerial Order may include a prohibition on disclosure. Before imposing such a prohibition, the minister must consider comparable factors, including the impact of non-disclosure on the principles of transparency and accountability of the Government of Canada. Specifics regarding the publication of orders In principle, Orders in Council and Ministerial Orders must be published in the Canada Gazette within 90 days of their issuance, but the minister making the order may specify in the text itself that it need not be published. In addition, incorporation by reference facilitates the integration of technical documents that are subject to change. We can therefore expect this process to adopt international technical standards. Collection of information by the minister Bill C-8 provides that the minister may require the disclosure of information if they have reasonable grounds to believe that it is both reasonable for the information to be provided in view of the gravity of the threat and that it is necessary. However, a confidentiality framework is in place for the information provided, particularly when it involves trade secrets or financial, commercial, scientific, or technical information. Personal information and de-identified information are also subject to protective measures. The text also provides for the exchange of information among various federal authorities, as well as with the provinces, foreign countries, or certain international organizations under written agreements. The scope and content of personal or de-identified information must be reasonable in view of the gravity of the threat. The Act also provides for the disposal of personal or de-identified information when it is no longer needed. It should also be noted that personal and de-identified information are deemed to be confidential information for the purposes of Part 1, even if they have not been expressly designated as such. Part 2 of the Act – The Critical Cyber Systems Protection Act (CCSPA) It is important to note that this part of the Act will not take effect until the date or dates set by Order in Council. Furthermore, its actual applicability will depend on future designations, since Schedule 2 is currently blank. The framework has therefore been adopted, but it has yet to be implemented. Key concepts: What the Act actually aims to achieve The CCSPA applies to critical cyber systems as strictly defined by the text, that is, a cyber system that, if its confidentiality, integrity or availability were compromised, could affect the continuity or security of a vital service or vital system. The definition of “cyber system” is intentionally broad. In practice, the Act is therefore not limited to a “network” in the traditional sense; it can encompass platforms, cloud environments, control systems, digital services, and interconnected technical assets, provided that if they were compromised, it could affect a vital service or system. The version of the text that has been assented to also adds the definition of “internal audit”, which is an independent and objective review conducted in accordance with internationally recognized guidance on professional internal auditing practices. This reinforces the idea that the expected compliance goes beyond simply adopting internal policies and, where necessary, requires structured assurance mechanisms. How organizations are designated A “designated” operator that controls, operates, or owns a critical cyber system is required to comply with the provisions of the CCSPA and its regulations pertaining to that cyber system. How are operators designated? First, “vital services” and “vital systems” are those listed in Schedule 1, namely: telecommunications services, interprovincial or international pipeline and power line systems, nuclear energy systems, transportation systems that are within the legislative authority of Parliament, banking systems, and clearing and settlement systems. By Order in Council, items may be modified, or added to or removed from this schedule within the scope of authority provided for by the Act. Second, the Act includes a schedule—which is currently blank—that allows for the establishment of classes of operators and regulatory bodies responsible for these vital services or systems. In practice, compliance depends on both the vital service or system in question (Schedule 1) and the operator class in which the organization is classified (Schedule 2). Cyber security programs: The foundational requirement At the heart of the CCSPA is the requirement to develop a cyber security program. After being designated through an amendment to Schedule 2, an operator must establish, within 90 days, a program relating to its critical cyber systems. This program must include measures, in accordance with the regulations, to identify and manage organizational risks (including supply chains and the use of third-party products and services), protect critical cyber systems, detect incidents and minimize their consequences, as well as any other measures required by the regulations. The program is therefore not merely a policy—it must cover the entire risk management cycle and be amenable to a “compliance” review. This will force organizations and companies to respond quickly when such a designation is made. The Act also imposes a monitoring mechanism: once the program is established, the operator must notify the relevant regulatory body in writing. The Act also requires that any such program be updated periodically. Lastly, reporting requirements apply when significant changes occur, including changes to ownership or control, supply chains, and the use of third parties. This approach transforms cyber security into a governance and maintenance requirement, rather than a one-time project. Supply chains and third parties: From assessment to mitigation The CCSPA explicitly emphasizes supply chains. Once the risks related to supply chains and third parties have been identified in the program (paragraph 9(1)(a)), the designated operator is required to mitigate them (section 15). The verb is important: it is not enough simply to “observe” or “monitor”; the law requires an active mitigation effort, which must be demonstrable. The Communications Security Establishment (the “CSE”) may develop guidelines on mitigating risks associated with supply chains and the use of third-party products and services, drawing on internationally recognized frameworks. The appropriate regulator may also provide the CSE with information—including confidential information—regarding the program or the measures taken, so that the CSE can provide advice, guidance, and services in accordance with its mandate. For organizations, this signals a convergence between regulatory requirements and technical expectations: managing suppliers, access, updates, software dependencies, and subcontractors is becoming a core component of compliance. Incident reporting: A requirement for speed and coordination The CCSPA establishes a requirement to report cyber security incidents to the CSE. Every designated operator must report any cyber security incident involving one of its critical cyber security systems within the prescribed time limits, which may not exceed 72 hours. The definition of “cyber security incident” covers an incident (including an act, omission, or circumstance) that interferes or may interfere with the continuity or security of a vital service or system, or the confidentiality, integrity, or availability of a critical cyber system. After filing a report with the CSE, the operator must, without delay, notify the appropriate regulatory body and provide it with a copy of the incident report. The text specifies that these obligations do not diminish the obligations arising from the Personal Information Protection and Electronic Documents Act. Cyber security guidelines: The mandatory response tool The CCSPA provides for a particularly intrusive measure: cyber security directions. By Order in Council, the government may direct any designated operator or class of operators to comply with any measure set out in the direction for the purpose of protecting a critical cyber system, but only if it has reasonable grounds to believe that the direction is necessary. Before issuing the order, the government must consider the operational impacts, public safety, privacy protection, financial impacts, and the impacts on the provision of vital services and systems. The scope and content must be reasonable in relation to the protection objective, and the operator in question is required to comply. The law also sets out two explicit limitations: the Governor in Council may not order the decryption of an encrypted private communication or the interception of a private communication or a radio-based telephone communication. In addition, a safeguard related to awareness has been put in place: an operator cannot be found guilty of contravening the direction unless they were notified of it or reasonable steps were taken to inform them of it. However, it will be important for an operator not to ignore the notifications received, even if they sometimes seem minor. The operator in question may not disclose the existence or content of a direction except to the extent necessary to comply with it. This requirement has a significant practical impact: it mandates the implementation of a “need-to-know” policy both internally and with respect to suppliers, subcontractors, insurers, and other partners. Information: Confidentiality, sharing, and removal of personal information The CCSPA establishes a comprehensive information-sharing framework, in particular to support the making, amending or revoking of directions. For purposes related to the making, amending or revoking of a direction, certain entities may collect and share information—including confidential information—with one another. The law also regulates the disclosure and use of confidential information and provides for exceptions, particularly when disclosure is required by law or necessary to protect vital services, systems, or cyber systems. “Provable” compliance The CCSPA requires the maintenance of records covering program implementation, reported incidents, steps taken to mitigate third-party risks, compliance with directions, and any other matters specified by the regulations. These documents must be kept in Canada in accordance with the terms and conditions prescribed by the regulations or, in the absence thereof, by the appropriate regulator. This requirement is central: it transforms compliance into a burden of proof. The regulatory framework provides for broad audit and enforcement powers, which are exercised by different authorities—the Superintendent of Financial Institutions, the Minister of Industry through inspectors, the Bank of Canada, the Canadian Nuclear Safety Commission, the Canadian Energy Regulator, and the Minister of Transport—depending on the sector. The provisions governing access to premises, the examination of cyber security systems, and the reproduction and temporary seizure of documents and systems are detailed in the CCSPA. Mechanisms for internal audits and compliance orders are in place, depending on the authority. The law prohibits obstruction and the provision of false or misleading information, which underscores the importance of the quality of the information provided. The version of the text that has been assented to also adds an explicit provision: the CCSPA does not infringe upon solicitor-client privilege or the professional secrecy of lawyers or notaries. Watch out for penalties! It should be noted that the law provides for substantial administrative penalties, as well as criminal offences (including imprisonment). Executives and directors may be considered co-perpetrators of a violation or offence, as the case may be. Ongoing violations can be counted on a day-by-day basis. Under Part 2 of the Act, administrative penalties may reach $500,000 for an individual and $15,000,000 in other cases. Furthermore, certain violations constitute criminal offences that are punishable, in some cases, either through charges or summary proceedings. Depending on the nature of the violation and whether the offender is an individual, imprisonment may be possible. How we can assist you in implementing Bill C-8 In particular, we can assist you with the following: Regulatory positioning Mapping your exposure (in terms of telecommunications, vital services or systems, and your current or anticipated designation) and establishing a realistic roadmap, prioritized by risk Responding to the imposed measures Supporting the receipt, analysis, and implementation of Orders in Council, Ministerial Orders, or directions Compliance Establishing or strengthening governance, record-keeping, and internal processes (including requests for information, audits and inspections, and the traceability of decisions) Third parties and procurement Reviewing and negotiating contracts and security requirements (including incident reporting, cooperation, audits, subcontracting, corrections, and withdrawal/replacement) and documenting mitigation measures Incidents and enforcement Supporting incident response (including triage, notifications, and the preservation of evidence) and managing the risk of penalties and criminal liability, including for executives and directors Conclusion In practice, organizations that may be affected would be wise to start preparing now, even though Part 2 of the law is not yet in force. The practical scope of the Act will depend on the CCSPA coming into force, the adoption of implementation regulations, and the inclusion in Schedule 2 of the classes of operators concerned and their corresponding regulators. In the meantime, organizations that begin structuring their governance, documentation, and third-party management now will be better positioned to adapt quickly once the sector-specific requirements are clarified.

    Read more
  2. The Legal Pitfalls of Using Human DNA and Tissue in Quebec-based Biotechnology Projects

    Biotechnology projects rely on sensitive genetic data and biological material Nowadays, innovation-driven companies involved in life sciences, research and biotechnology handle some of the most legally sensitive assets: human tissue, biological material and genetic data. Innovation models involving tissue engineering, biobanks or AI-based analytical technologies are now based on the transfer and use of biological data with high scientific and commercial value. Yet, many organizations still prioritize the scientific and operational aspects of their projects without giving sufficient consideration to the legal restrictions that arise when a project involves a person’s DNA or biological material. From a business standpoint, the risk is that an organization—whether a private company or a public institution—might develop a technology, but then be unable to market that technology because it does not hold the necessary rights to use the biological material and information involved. In Canada, and particularly in Quebec, laws that protect personal and health information have become central to such projects.1 We are no longer simply dealing with typical cybersecurity or privacy concerns. These laws directly affect how biological material is:  collected used transferred stored altered and potentially leveraged for commercial or collaborative research purposes2. Why DNA and human tissue are subject to a particular legal protection The highly sensitive nature of DNA and genetic data is no longer disputed. Canadian case law has long recognized the highly personal and private nature of this type of information.3 It also emphasizes the fact that human tissue and genetic data play a unique role in research and innovation projects because of the identification risks they carry, their scientific value, and the ethical and commercial concerns related to their use.4 This perspective is evident in section 2 of the Act respecting health and social services information5, for example, which defines health information as any information that concerns “any material taken from [a] person,” including biological material. Section 5 and following of this act set out the conditions under which such information may be used, disclosed or transferred in the context of research or collaboration involving third parties6  These obligations supplement those set forth in the Act respecting the protection of personal information in the private sector,7 which requires in particular that personal information be collected for specific and legitimate purposes, and that it be used in a manner consistent with the purposes for which it was originally collected.8 Artificial intelligence, genetic data and the risk of re-identification From a biotechnology perspective, the matter becomes particularly touchy when human tissue or genetic data, which was initially collected for clinical or scientific purposes, is then used for technology or artificial intelligence projects. In fact, many projects that utilize artificial intelligence require not only biological samples and DNA, but also phenotypic data, health information and family history information from the patients from whom the biological samples were obtained. As such, there is a real risk of data cross-referencing here that must be managed with full awareness of the potential impact on those individuals. In certain projects, combining DNA with family information could compromise the privacy of not only the individuals from whom the biological material was collected, but also their family members. This problem has already been raised in relation to genetic genealogy.9 Consent, health information and secondary uses tend to be overlooked A project that was initially intended for research purposes can quickly drift into secondary uses that extend beyond its original scope. However, consent obtained at the outset does not necessarily cover all future uses, particularly where derived data or analysis results are integrated into technology platforms or used to develop analytical tools.10 Research agreements and biological material transfer agreements constitute an essential governance mechanism Agreements have thus become the key governance mechanism. Biological material transfer agreements, collaborative research agreements and data-related provisions are no longer solely intended to protect intellectual property or commercial confidentiality. They also serve to define the processes involved in transferring biological samples, ensuring data traceability, imposing restrictions on reuse and meeting anonymization requirements.11 The rights relating to intellectual property, DNA and personal information are interconnected The interplay between biotech innovation, intellectual property and personal information protection raises complex legal issues. A genetic database or a biological model derived from it can be both a strategic business asset AND a collection of highly sensitive personal information. However, any intellectual property rights that may apply to the results, algorithms or analytical methods do not exempt organizations from the obligations set out in Quebec laws regarding the protection of personal and health information12. On the contrary, in order to market a technology, organizations must hold not only the necessary intellectual property rights but also the rights required under the legal framework governing health and personal information. The commercialization of a technology begins long before it is brought to market As organizations increasingly seek to leverage data from scientific research, issues related to the governance of human tissue, DNA and biological material should no longer be treated as a secondary consideration addressed only at the end of a project. They are becoming an integral part of the legal, operational and commercial framework of modern biotechnology projects and therefore deserve careful consideration from the outset. Summary 1. From a legal standpoint, DNA is considered to be health information In Quebec, biological material and genetic data are not merely instruments of research. Under the law, they are defined as highly sensitive “health information”. The collection, use and transfer of this type of information is strictly regulated and requires explicit, informed consent. 2. Intellectual property does not confer all rights to the holder Just because a company develops a high-performance AI algorithm or an innovative biological model does not mean it can circumvent Quebec’s privacy laws. Bringing biotech products to market requires holding the necessary intellectual property rights AND complying with the legal framework governing the use of health data. 3. The pitfall of project drift (secondary uses) Consent obtained at the outset of a clinical research project usually does not extend to future uses, such as the integration of data into AI platforms. Organizations that fail to establish a solid contractual framework (e.g., transfer agreements, anonymization clauses) from the start may never be able to market their technology. Act respecting health and social services information, CQLR c R-22.1, ss. 1, 2, 5, 44 to 49 and 77. Act respecting the protection of personal information in the private sector, CQLR c P-39.1, ss. 4, 5, 8, 12 and 14. R. v. Dyment, 1988 CanLII 10 (SCC), [1988] 2 SCR 417 Marie Hirtle and Bartha Maria Knoppers, Le stockage des éléments du corps humain, les droits de propriété intellectuelle et les autres droits de propriété, Industrie Canada, 2014. Act respecting health and social services information, supra, note 1, s. 2. Id., ss. 5, 44 to 49 and 77. Act respecting the protection of personal information in the private sector, supra, note 2. Id., ss. 4, 5, 8, 12 and 14. Clausius, K., Kenny, E. & Crawford, M. J. (2023). BILL S-231: The Ethics of Familial and Genetic Genealogical Searching in Criminal Investigations. Canadian Journal of Bioethics / Revue canadienne de bioéthique, 6(3-4), 44–56.  Act respecting health and social services information, supra, note 1, ss. 44 to 49; Act respecting the protection of personal information in the private sector, supra, note 2, ss. 12 and 14. Act respecting health and social services information, supra, note 1, ss. 48 and 49; Act respecting the protection of personal information in the private sector, supra, note 2, ss. 18.3 and 23. Act respecting health and social services information, supra, note 1, ss. 5 and 49; Act respecting the protection of personal information in the private sector, supra, note 2, ss. 12, 17 and 18.3.

    Read more
  3. Behind the Scenes of Sports, Data Never Takes a Break

    The World Anti Doping Agency suffered a data breach in 2016­—a vivid illustration that even the most prominent sporting institutions are not immune to cyber incidents. The authorities have now formalized what was previously just an observation: In a bulletin published in 2024, the Canadian Centre for Cyber Security warned that the entire sports ecosystem—spectators, athletes, organizations and government representatives—is the target of cyberattack campaigns.  Malicious actors will attempt extortion through business email compromise, ransomware attacks, phishing, malicious websites and search engine poisoning, among others. Take heed, as when an incident occurs that is serious enough to require a report to the authorities, it is often too late to establish sound governance and engage in due diligence. The sporting competitions of today are producing massive amounts of data. The quantity is staggering, and the data itself almost Orwellian. Check the tables below to see for yourself. Data collected on athletes  League Information collected NFL Performance data (statistics, position and movement metrics, speed, and passing, rushing and receiving yards) Medical and/or health data (examinations, injuries, concussion protocols) Substance screening data Data on disciplinary actions and investigations Professional and contractual data Travel, logistics and security data NHL Performance data Medical and/or health data (examinations, injuries, concussion protocols) Substance screening data Data on disciplinary actions and investigations Professional and contractual data Travel, logistics and security data MLB Performance data Medical and/or health data (examinations, injuries, concussion protocols) Substance screening data Data on disciplinary actions and investigations Professional and contractual data Travel, logistics and security data   Collection of customer information online  League Information collected NFL  Information provided by individuals  Identifiers: name, email, address, telephone number, date of birth; unique identifiers (username, password, SSN and other government identifiers if required, e.g. for awards) Demographic data and other protected categories: gender, race, ethnicity, sexual orientation Financial and commercial information: payment data, purchase history Real-time geolocation; precise geolocation Communication and marketing preferences Favorite team and inferences about preferences Audio, electronic and visual information (e.g., photos provided) Biometric data, if you opt for biometric authentication at the stadium; with consent and additional notice if required Information about your contacts (name, email) that you share; if authorized, access to your contacts, calendars and photos Search queries Content posted (comments, forums) Professional and employment information Education information Information that may be health-related (e.g., accessible seating) Correspondence, waivers, consents and other information sent Automatic collection  Device and network identifiers and technical data: IP address, MAC address, advertising identifiers, device type, browser, OS Usage: page views, links clicked, browsing journeys, application usage data Tracking and emails: cookies, pixels, tags, interaction with emails (opened emails, clicks) Social media (if linked): data received according to your settings and the platform’s policy Logs and traffic: server logs, stadium Wi-Fi traffic Video and audio recordings: CCTV and pictures taken or video recorded during events   NHL  Information provided by individuals Identifiers and contact information (name, email, telephone number, address, date of birth) Commercial information (payments, purchases, services) Demographic data (language, age, gender, race, ethnicity, household composition and income) Preferences (favourite team, favourite players) Photos and/or videos Content, feedback (comments, surveys) Contact information of friends Application data (resume, references, checks permitted) Automatic collection Activity and interactions (content viewed, bids, purchases, time spent, cookies, tags), access methods (browser, OS, IP address, browsing history before and after) Device information and identifiers (type, unique identifiers, local content if allowed) Location (GPS, Bluetooth, Wi-Fi, cells) Inferences about preferences Commercial information about transactions (e.g., timestamps) Collection from third parties Member clubs (ticketing, login credential, usage logs) Fanatics, NHL Shop, NHL Auctions (name, email, items purchased; marketing engagement statistics) Other business partners, public sources, commercial sources (data brokers) Connected social media (according to the platform’s settings and policies) NHL teams* Contact information: name, email address, home address, gender, date of birth, telephone number (e.g., ticket purchase, ticket transfer, account creation, inquiries, contests, promotions) Demographic data and preferences (age group, race, gender; preferred events, preferred products, e.g., surveys) Health data related to accessibility needs Video surveillance in venues (security; sharing limited by law) Anonymous traffic analysis and device counting (cameras, technological devices; Wi-Fi); statistics that can be shared with partners Depersonalized web analytics (Google Analytics); opt-out option Online advertising and/or remarketing (Google, Facebook, LinkedIn, etc.) through cookies; opt-out mechanisms (platform settings; DAAC) Geolocation through applications if enabled Social media: profile data and authorized interactions Technical data (IP, browser, OS, resolution, location, language, origin, keywords, pages viewed, data entered, ads viewed), identifiers (IDFA, AAID), connection information (operator, ISP, Wi-Fi); ability to recognize a device) MLB Information provided by individuals Identifiers and contact information: full name, email address, home address, telephone numbers, date of birth Security and authentication: password Payments: payment details Demographic data: demographic characteristics Content and recordings: voice recordings, audiovisual recordings Preferences and interests: information about your interests and preferences Activity and event related data: information requested for an activity or event (e.g., emergency contact) Sensitive personal information: as defined by applicable laws (e.g., racial or ethnic origin; health information such as disabilities or allergies) Automatic collection  Technical and usage data: IP addresses, device data, usage data Location and contacts: location data; contacts saved on your mobile device Collection from third parties Data from third parties and integrations: information provided by other companies if individuals connect their services * This data is collected about website users, people who visit venues, people who apply for jobs or participate in contests, people who submit drafts.   How leagues are structured Regarding privacy and personal information, we must look at how sports leagues are organized to understand who does what. In most cases, sports leagues are non-profit organizations or corporations. An entire framework of rules is built around these structures, defining both how governance is done and what business model is used. First, there are the articles of association and by-laws, which dictate governance, team admissions, voting rights, and the powers of the commissioner or board of directors. There are also the sporting and competition regulations regarding eligibility, game schedules, transfers, drafts, salary caps and cost control mechanisms. The leagues also adopt integrity and security policies against doping, betting and manipulation, harassment and abuse, as well as commercial agreements covering broadcasting, sponsorships, ticketing and data leveraging, among others. There can also be collective agreements with players’ associations and formal dispute resolution mechanisms. In this environment, the league plays a central role. It generally has the power to adopt, interpret and amend its rules; admit teams; manage expansion and relocation projects and changes of control; as well as the power to impose sanctions such as fines, point deductions, suspensions or exclusions. It also centralizes strategic commercial rights, media rights, trademarks and data, and it implements revenue-sharing policies designed to maintain a competitive balance between teams. Personal information: the roles of each Teams In day-to-day relations with athletes and customers, teams are generally the main point of contact. They sign contracts with players, sell tickets, manage subscriptions and operate online stores and loyalty programs. In practice, teams are often the ones that collect personal information, that explain what the information is used for, that decide what information needs to be collected and that put in place security and incident management measures. Teams must therefore be able to clearly inform athletes and customers about the purposes for which personal information is collected, the means by which it is collected, the categories of information collected, who receives the information, and the rights that  athletes and customers have. Teams must limit collection to what is necessary. They must ensure that information is accurate; they must obtain valid, manifest, free, informed and explicit consent for sensitive information such as health or biometric data; they must implement security measures adapted to risks; they must manage and report confidentiality incidents likely to cause serious harm; they must respond to requests for access and rectification; and they must stringently govern the sharing of information with service providers and mandataries. Athletes and customers often see the team as the true holder of their data. Leagues The role leagues play regarding personal information is more difficult to understand, as it varies depending on activities. When a league directly collects information from an individual, for example through an official application, a broadcasting platform or a transactional site for its own purposes, it must assume responsibilities comparable to those a team has. This is what MLB Advanced Media does, for example, defining itself as a “data controller” with respect to its customers’ data. But in many cases, the league acts behind the scenes. In some respects, it acts as a mandatary for the teams, negotiating and signing technology contracts, broadcasting agreements and other commercial agreements that will be used by the teams. In other respects, it acts as a service provider, offering centralized technology platforms, ticketing systems, data infrastructure and shared administrative services. Under Quebec law, these two roles—mandatary and service provider—are treated the same: The team can transmit to the league the information it needs to perform the mandate or service contract without having to ask for the consent of each person again, provided that a written agreement imposes clear measures to protect privacy, limits the use of data to the sole purposes of the mandate or service and governs data retention. The league must also promptly inform a team’s privacy officer of any privacy breach or attempted privacy breach and allow the officer to conduct checks. Also, teams and the league can always choose to base certain exchanges of information on the explicit consent of athletes or customers. However, such consent must be genuinely explicit, free, informed, given for specific purposes and presented separately when asked to be given in writing. Conclusion Although professional leagues are the ones in the spotlight, the same logic applies to amateur or non-professional sports organizations. In all cases, the relationship between the league, the team and the athlete or customer must be clearly governed from a privacy standpoint. Sports organizations should map the flow of personal information, harmonize the information messages they give to the those concerned, establish a standard agreement governing the sharing of information between teams and the league, provide simple mechanisms for access and rectification, and have key employees trained in privacy matters. Incorporating these points into articles of association, by-laws and team and league agreements will reduce risks and strengthen the confidence of athletes, parents, fans and business partners. Yet, a fundamental question still remains: Given that by law, data can only be collected for serious and legitimate reasons (necessity criterion), is the mass of information currently collected in the sports ecosystem really warranted? Sports organizations will have no choice but to delve into this strategic issue. 

    Read more
  4. Export controls: implications in a world of knowledge sharing

    Introduction When we hear the term “export controls,” we may think it only applies to weapons and other highly sensitive technologies, but that is not the case. There are a multitude of circumstances—some unexpected—to which it is important to know that export controls apply. This is especially true if you are involved in research or in the design and development of seemingly innocuous solutions that are not necessarily tangible objects. Today, technological knowledge is shared not only through conventional partnerships between businesses or universities, but also through data sharing or access to databases that feed large language models. Artificial intelligence is, in itself, a means of sharing knowledge. Feeding such algorithms with sensitive data, or data that can become sensitive when combined, carries a risk of violating the applicable legal framework. Here are some key concepts. Overview of the federal export control framework The Export and Import Permits Act In Canada, the Export and Import Permits Act (the “EIPA”) establishes the primary framework governing the export of controlled goods and technologies. The EIPA gives the Minister of Foreign Affairs the power to issue, to any resident of Canada who applies for one, a permit authorizing the export or transfer of a wide range of items included on the Export Control List (the “ECL”) or destined for a country listed on the Area Control List. In other words, the EIPA regulates, and at times prohibits, the trade of critical goods and technologies outside Canada. The Export Control List To get the full picture of the ECL, we need to refer to the Guide to Canada's Export Control Listas published by the Department with its successive amendments, the most recent of which date back to May 2025 (the “Guide”). In summary, the Guide includes military goods and technologies, strategic goods and dual-use (civilian and military) goods and technology that are controlled in accordance with Canada’s commitments made in multilateral regimes, such as the Wassenaar Arrangement on Export Controls for Conventional Arms and Dual-Use Goods and Technologies, bilateral agreements, and certain unilateral controls implemented by Canada as part of its defence policy. The Guide also includes forest products, agricultural and food products, apparel goods and vehicles. Other laws that affect exports Also to take into account are the sanctions that Canada imposes under laws that affect exports, such as: the United Nations Act the Special Economic Measures Act the Justice for Victims of Corrupt Foreign Officials Act These sanctions against specific countries, organizations or persons include a number of measures, including restricting or prohibiting trade, financial transactions or other economic activities with Canada, or the freezing of property located in Canada.1 Finally, in order for an individual (or an organization) to transfer controlled goods outside Canada, they must register with the Controlled Goods Program (the “CGP”) to obtain an export permit, unless exempt. Key concepts Did you know? Certain goods and technologies are referred to as “dual-use” goods and technologies. This means that even though they were initially designed for civilian use or appear harmless, they may be subject to export controls if they can be used for military purposes or to produce military items. A “technology” is broadly defined to include technical data, technical assistance and information necessary for the development, production or use of an item listed on the ECL. Also included in this notion, albeit indirectly, are the technologies referred to in any of the regulations associated with the laws listed above, which make certain countries subject to specific technology transfer restrictions. A “transfer” in relation to a technology, means to dispose of it (e.g. sell it) or disclose its content in any manner from a place in Canada to a place outside Canada. This definition stems from legislative amendments to the EIPA, which expanded the scope of the law to include the mere transfer of intangible technologies by various means, thereby broadening the circumstances to which permits apply as regards transfers.2 Regarding trade relations with the United States, Canadian exporters may face additional restrictions and considerable challenges, particularly in situations where their employees or other stakeholders involved are foreign nationals.The International Traffic in Arms Regulations (“ITAR”) and the Export Administration Regulations(“EAR”) are two key sets of rules that govern exports from the United States.3 They protect both similar and distinct interests. While the ITAR aim to protect defence articles and defence services (including weapons and information), the EAR govern dual-use items.4 Both prevent exports5 in a broad sense, i.e., up to and including the transfer of information to so-called “foreign” persons, except with the permission of the authorities. It is thus quite possible that Canadian exporters will be required to comply with these American regulations, which, in addition to targeting territories, target the national origin of individuals. This is diametrically opposed to Canada’s export regime, which rather centres on prohibiting trade with a country or anyone located there. In this regard, note that Quebec’s Charter of Human Rights and Freedoms considers national origin to be a ground for discrimination. 6 A Quebec business can thus find itself struggling to balance its contractual obligations under a contract with an American company with the requirements of the Quebec Charter. Artificial intelligence: novel challenges The development of large language models in the field of artificial intelligence represents a new challenge from an export control standpoint, and a significant one at that. For example, if a large language model is trained using restricted data, a state subject to the aforementioned sanctions might attempt to use the large language model to indirectly obtain information to which it would not otherwise have had direct access. As a result, training a large language model on plans, technical specifications or textual descriptions of technologies covered by transfer restrictions (which can include knowledge transfers) can create a risk of non-compliance with the law. The same applies to accessing such data for retrieval-augmented generation, a widely used technique to expand and improve large language model responses. To limit the risk during research and development, a company that trains a large language models on such data or allows access to such data for retrieval-augmented generation will need to consider where the data will be hosted and processed. Similarly, once the artificial intelligence application is developed, it will be important to restrict access to it in a manner consistent with the law, both in terms of locating the servers on which the large language model will be installed and in terms of user access. Sanctions Any person or organization that contravenes any provision of the EIPA or its regulations commits an offence punishable by fine and/or imprisonment, as applicable. Also, failure to register with the CGPmay constitute an offence under federal laws that can lead to prosecution and substantial sanctions against the offender(s).7 Conclusion Canada’s export controls are quite complex, not only in how they are structured, but also in how they must be implemented. With the changing geopolitical and commercial landscape, it is advisable to periodically read the resources made available by the relevant authorities and put in place appropriate policies and measures, or to seek professional advice in this regard. Government of Canada, “Types of sanctions” (date modified: 2024-09-10): Types of sanctions Martha L. Harrison & Tonya Hughes, “Understanding Exports: A Primer on Canada’s Export Control Regime” (2010) 8(2) Canadian International Lawyer, 97 The ITAR and EAR are included in the Code of Federal Regulations (“CFR”). Austin D. Michel, “Hiring in the Export-Control Context: A Framework to Explain How Some Institutions of High Education Are Discriminating against Job Applicants” (2021) 106:4 Iowa L Review, 1993 The ITAR and EAR also provide for restrictions on re-exportation. See Maroine Bendaoud, “Quand la sécurité nationale américaine fait fléchir le principe de non-discrimination en droit canadien : le cas de l'International Traffic in Arms Regulations (ITAR)” (2013) Les cahiers de droit, 54 (2–3), 549 Government of Canada, “Guideline on Controlled Goods Program registration” (date modified: 2025-05-08): Guideline on Controlled Goods Program registration – Canada.ca

    Read more
  1. Three Partners Recognized as Leading Lawyers in Canada by Lexpert in its Special Edition in Technology

    On June 4, 2025, Lexpert recognized the expertise of three of our partners in The Lexpert Special Edition: Technology 2025. Chantal Desjardins, Raymond Doray and Alain Y. Dussault are recognized among Canada’s leaders, highlighting the firm’s excellence and strategic role in technology law. Chantal Desjardins, Partner, Lawyer and Trademark Agent, actively assists her clients in establishing their rights in the field of intellectual property, which includes the protection and defence of trademarks, industrial designs, trade secrets, copyright, domain names and other related forms of intellectual property, in order to further their business objectives. Ms. Desjardins provides legal advice and expertise in intellectual property protection and management, represents her clients in the examination of applications and opposition and litigation proceedings in Canada and in other countries. She negotiates licences, various contracts in the field and technology transfers. She advises and defends her clients’ advertising and labelling rights and on other matters, such as the Charter of the French language. Raymond Doray is a Partner and heads the information law practice, where he handles files on access to information, privacy, defamation and the application of the Canadian and Quebec charters of rights and freedoms. He also specializes in constitutional law. Over the past few years, Mr. Doray has represented several public bodies, private organizations and media companies in legal actions on the confidentiality of documents, the validity of certain government decisions and the respect of reputation and privacy. He also acts as legal counsel for a certain number of corporations, professional orders, public bodies and media companies in administrative and constitutional law cases. Alain Y. Dussault, Partner, Lawyer and Trademark Agent in the Intellectual Property group. He mainly practises intellectual property litigation and has extensive experience in patent litigation, trademarks, copyright and industrial designs. He acts in various large-scale disputes, including certain multijurisdictional disputes, for clients in various industries, including pharmaceutical, agri-food, electronics, forest and entertainment. He has represented prestigious clients in complex disputes before the courts in the province of Quebec, the federal courts and the Supreme Court of Canada. He also advises his clients on registering, managing and protecting their intellectual property rights. This recognition by Lexpert shows the quality and depth of expertise offered by Lavery, attesting to its commitment to provide solutions tailored to its technology clients. About Lavery Lavery is the leading independent law firm in Quebec. Its more than 200 professionals, based in Montréal, Québec City, Sherbrooke and Trois-Rivières, work every day to offer a full range of legal services to organizations doing business in Quebec. Recognized by the most prestigious legal directories, Lavery professionals are at the heart of what is happening in the business world and are actively involved in their communities. The firm’s expertise is frequently sought after by numerous national and international partners to provide support in cases under Quebec jurisdiction.

    Read more
  1. Lavery Advises inBeat Agency on its financing with BDC and the Acquisition of Creative Milkshake

    Lavery is proud to have advised inBeat Agency on its financing with the BDC, as well as on the acquisition of Creative Milkshake. This major transaction represents a significant milestone in inBeat’s growth trajectory and further consolidates its position within an ecosystem where influencer marketing, content creation and digital performance converge. Beyond the strategic expansion it enables, this deal brings together two talented teams with complementary expertise: inBeat, led by co-founders David Morneau and Daniel Cruz, among others, and Creative Milkshake, led by Mirella Crespi. The combined strengths of these teams enhance the group’s ability to innovate, expand its reach in Canada and internationally, and generate greater value for its clients. The mandate was handled by a Lavery team led by Jean-François Maurice and comprising Rodrigo Olmos-Hortigüela, Éric Gélinas and Julie Aubin-Perron. We would like to thank the team at inBeat Agency for their trust, as well as all parties involved for their support throughout the process. Our congratulations to inBeat Agency, Creative Milkshake and all the teams involved for this strategic achievement and the ambitious vision behind it.

    Read more
  2. Lavery supports Logient in its merger with Onepoint and the creation of Wepoint

    Lavery is pleased to announce that it acted as legal counsel to Logient in the transaction that saw French consulting group Onepoint acquire Logient nventive, giving rise to Wepoint, a new North American player in technology and consulting services. The new entity brings together close to 600 experts, including 450 from Logient nventive and 150 from Onepoint Canada. It plans to expand its team to 1,500 AI experts and generate $250 million in revenue by 2030. Wepoint combines complementary expertise in cloud solutions, AI, data, consulting, and technology products, with plans for the Montréal team to play a key role in its North American operations. The merger is creating a model that combines consulting excellence, local expertise, and large-scale innovation capacity, reflecting the technology and consulting sector’s trend toward consolidation and growth. The Lavery team that handled the transaction was led by Étienne Brassard and included Bernard Trang, Julie Aubin-Perron, Jen Deruchie and Arielle Supino. About Lavery Lavery is the leading independent law firm in Quebec. Its more than 200 professionals, based in Montréal, Quebec, Sherbrooke and Trois-Rivières, work every day to offer a full range of legal services to organizations doing business in Quebec. Recognized by the most prestigious legal directories, Lavery professionals are at the heart of what is happening in the business world and are actively involved in their communities. The firm's expertise is frequently sought after by numerous national and international partners to provide support in cases under Quebec jurisdiction.

    Read more
  3. Lavery supports Moov AI with its sale to Publicis Groupe

    On March 27, 2025, Moov AI, Canada’s leading artificial intelligence and data solutions company, announced that it entered into a definitive agreement to be acquired by Publicis Groupe. The combination of Moov AI’s best-in-class consulting, proprietary solutions and insights coupled with Publicis Groupe’s CoreAI offering will add a powerful AI-driven engine and set of capabilities for Publicis Groupe Canada to leverage in-market and with its clients. Francis Dumoulin had the privilege of representing and advising Moov AI shareholders in the sale to Publicis Groupe, with Alexandre Hébert’s support and Siddhartha Borissov-Beausoleil’s contribution in closing the transaction. About Lavery Lavery is the leading independent law firm in Québec. Its more than 200 professionals, based in Montréal, Québec City, Sherbrooke and Trois-Rivières, work every day to offer a full range of legal services to organizations doing business in Québec. Recognized by the most prestigious legal directories, Lavery professionals are at the heart of what is happening in the business world and are actively involved in their communities. The firm's expertise is frequently sought after by numerous national and international partners to provide support in cases under Québec jurisdiction.

    Read more
  4. Lavery Advises Technicolor Canada on the Sale of Mikros Animation

    This March 25th, 2025, the Superior Court of Quebec approved the sale of "Mikros Animation", the cartoon animation division of Technicolor Canada, Inc., a Canadian subsidiary of the Technicolor Group. Lavery had the privilege of advising Technicolor Canada on this transaction, which was part of the court-ordered reorganization of the corporations that make up the Technicolor Group. Simultaneously with the acquisition of the assets of the "Mikros Animation" division in Quebec, the buyer, RodeoFx, will also acquire the assets of the "Mikros Animation" division in France. This would greatly facilitate the closing of the transaction, considering that the Technicolor group is an internationally integrated company. Still due to the international component of the "Mikros Animation" division's operations, this simultaneous acquisition of it's assets in Quebec and France required the unprecedented collaboration of the Tribunal des Activités Économiques de Paris and the Quebec Superior Court. Completion of the transaction will ensure the continued operation of the "Mikros Animation" division in both Quebec and France and preserve up to 207 jobs in Montreal in the specialized field of animation, in addition to the 80 jobs in the "Mikros Animation" division in France. The Lavery team led by Sébastien Vézina and Jean Legault also included Martin Pichette, Marc Ouellet, Jessica Parent, Ouassim Tadlaoui, David Tournier, David Choinière, Jean-Paul Timothée and Yasmine Belrachid. About Lavery Lavery is the leading independent law firm in Québec. Its more than 200 professionals, based in Montréal, Québec City, Sherbrooke and Trois-Rivières, work every day to offer a full range of legal services to organizations doing business in Québec. Recognized by the most prestigious legal directories, Lavery professionals are at the heart of what is happening in the business world and are actively involved in their communities. The firm's expertise is frequently sought after by numerous national and international partners to provide support in cases under Québec jurisdiction.

    Read more