Cybersecurity

Overview

Read our white paper on what to do before, during and after a cyber incident

Now more than ever, companies of all sizes and in every field must pay particular attention to the issue of cybersecurity.

The rise in cyberattacks and costs associated with data leaks is well documented. Indeed, the mobility of information in a telecommuting context, the use of cloud storage, process automation and the increased connectivity of organizational systems increase organizations’ vulnerability to cyberattacks. Data leaks can adversely affect not only an organization’s reputation with the public, but also the management and continuity of its day-to-day business.

In addition, legislative and regulatory requirements for public and private sector companies that hold personal data and information are also being enhanced, as evidenced, in particular, by the National Assembly of Québec’s very recent adoption of Bill 64 in the wake of high-profile security incidents.

Our expertise

Our service offer covers all aspects of cybersecurity, including identifying risks, understanding the issues at stake, implementing best practices in cyber vigilance and providing support should a company be sued following a breach of confidentiality.

Lavery’s team has extensive experience and expertise, particularly in crisis management with respect to:

  • Protection of personal and other sensitive data
  • Information technology
  • Technology governance
  • IT risk management
  • Disputes (including class actions)
  • Labour and employment law

Our team keeps abreast of legislative changes regarding personal information, an area currently undergoing rapid change. It also has an understanding of cutting-edge technology, including the Internet of Things, artificial intelligence and quantum computing, all of which will drastically affect cybersecurity practices in the coming years.

Service offer to private and public institutions

As we know that legal matters represent only a fraction of the issues that need to be addressed with respect to an organization’s cyber vigilance, our service offer includes legal services geared towards IT security management and non-legal services that combine a range of prevention and response measures to provide an effective and operational solution based on four criteria:

  • Strategy and transformation: Developing strategies and programs that focus on business needs and risks and support growth and resilience by making cybersecurity and privacy a company-wide priority.
  • Incident and threat management: Preparing for, identifying, responding to, investigating and handling threats with confidence.
  • Consumer privacy and protection: Designing, implementing and running a privacy program that enables your organization to maximize the use of data in accordance with the law, while building consumer trust.
  • Implementation and operations: Designing, implementing, running and improving the use of cybersecurity technologies and continuously monitoring your environment to detect and contain threats to your business.

Service offer to SMEs

Our firm has developed a cybersecurity service offer to, in particular, analyze companies’ needs in this area and identify possible flaws that require their attention.

As a first step, your organization must complete a cybersecurity needs analysis questionnaire.

Once the questionnaire is completed, we are able to establish a diagnosis, propose solutions and an action plan to remedy problematic aspects and guide you in implementing our recommendations on the following:

  • Cybersecurity governance: A sound decision-making process is important for any business when it comes to cybersecurity.
  • Processes related to employees, suppliers and subcontractors: A business’ decisions and policies respecting cybersecurity must be properly communicated not only within the organization, but also with all stakeholders.
  • Protection of personal information and data, and Canada’s anti-spam legislation: If your organization collects data or personal information as part of its operations, it must do so in accordance with the law.
  • Technical and technological component to increase cybersecurity: Legal and strategic advice associated with implementing the action plan following our cybersecurity needs analysis.

Representative mandates

  • Advised one of the largest professional orders in Quebec regarding a major computer security breach affecting its employees and members.
  • Advised a major Canadian chemical company on the theft of its employees’ and customers’ personal data.
  • Advised a Canadian tax and financial planning association following a cyberattack on its IT service provider.
  • Advised and provided a legal opinion to one of the most prominent public organizations in Quebec on the appropriateness and content of an incident report resulting from a breach of confidentiality following a cyberattack.
  • Advised a multinational tobacco company on the measures to be implemented in the event of a computer security breach and reviewed its policies, guidelines and response plans in this regard.
  • Provided training to executives of a multinational cybersecurity insurance organization.
  • Provided training to a major accounting and tax firm on cybersecurity and privacy.
  • Advised a Crown corporation on applying the General Data Protection Regulation (GDPR) and created a matrix to identify cases where this European legal framework, which includes rules on IT security breaches, should be applied.
  • Participated in data protection IT audits for various companies as part of a partnership with an international consulting firm.
  • Advised a Canadian vehicle parts company that was held to ransom following an unwarranted intrusion into its databases containing all of the technical drawings of its American and European vehicle manufacturer clients.
  • Reviewed the physical and software security rules of two major Canadian financial institutions’ IT and telecommunications systems and negotiated and drafted the physical and software security obligations incumbent on the service provider to which the operation of these systems was outsourced in order to ensure adequate contractual protection for the financial institutions against any breach of confidentiality of personal and other sensitive data entrusted to the service provider.
  • Assisted a European law firm with a major employee and supplier data breach involving a multinational electronics company and its subsidiaries in several jurisdictions around the world.
  • Advised a publicly traded company in the implementation of IT governance and security measures for the sharing of trade secrets between its various sites in Canada, the United States and Europe.
  • Represented a European company that was the victim of a cyber incident to claim damages from those responsible for the incident located in Canada.
  1. Bill C-8: A new federal cyber security framework for telecommunications and critical cyber systems

    Bill C-8 received royal assent on June 15, 2026. It deserves special attention. The bill marks a shift in our approach to cyber security, giving the federal government the means to respond quickly when a threat is identified. It also requires certain parties to comply with higher standards, and imposes real penalties for noncompliance. The legislation is structured around two main areas. The first strengthens the Telecommunications Act by empowering the Governor in Council and the Minister of Industry to impose specific measures through Orders in Council and Ministerial Orders. The second establishes the Critical Cyber Systems Protection Act (the “CCSPA”), targeting vital systems and services. With these legislative changes, cyber security is emerging from the shadows—it is becoming a matter of governance and compliance. And with the adoption of this Act, technology decisions, supplier management, and responses to cyber security incidents will need to be more robust, better regulated, and duly documented. We believe that organizations that are proactive in preparing their governance and evidence practices, as well as their contingency plans, will be more agile and more credible in the eyes of their clients and partners. That said, an important distinction must be made from the outset: the amendments to the Telecommunications Act set forth in Part 1 are now in force, whereas the CCSPA, as provided for in Part 2, will come into force following one or more Orders in Council. To date, Schedule 2 of the CCSPA, which is meant to identify the classes of designated operators and their corresponding regulatory bodies, remains blank. Key takeaways at a glance - Bill C-8 introduces: (i) the authority to issue telecommunications orders (that is, Orders in Council and Ministerial Orders); (ii) guidelines for a mandatory program for certain critical cyber systems, subject to the CCSPA coming into force and future designations; and (iii) strengthened enforcement in terms of information exchange, audits, administrative monetary penalties, and violations. Part 1 of the Act – Telecommunications: Security becomes the driving force for action Bill C-8 explicitly enshrines security in Canada’s telecommunications policy by adding the objective of “the promotion of the security of the Canadian telecommunications system.” It provides the legal basis for measures that are now designed to be direct, swift, and enforceable. An important element of the Act, both for its application and for defining the nature of the threats it addresses, is the clarification that “interference with or manipulation, disruption or degradation of a telecommunications system include actions of a technical nature that impede the operation of the telecommunications system but do not include the e?ect of lawful expression, persuasion or political debate.” The text thus expressly provides room for freedom of expression and lawful public debate. Part 1 of the Act includes a two-tier enforcement mechanism: Orders in Council and Ministerial Orders (issued by the Minister of Industry). Orders in Council The Governor in Council may issue an Order in Council if they have reasonable grounds to believe that the measure is necessary to secure the system against a threat, and that it is reasonable in relation to the gravity of that threat. Specifically, the order may: Prohibit telecommunications service providers (”TSPs”) from using the products and services provided by a specified person in, or in relation to, their networks or facilities; or Order the removal of products supplied by a specified person. Bill C-8 imposes a proportionality requirement: the scope and content must be necessary and reasonable in view of the gravity of the threat. The Order in Council takes precedence over any conflicting decisions, orders, or authorizations, including those under the Radiocommunication Act. Furthermore, the government does not bear the economic cost—no compensation is payable for financial losses attributable to the Order in Council. This is, in a sense, the “heavy artillery” of the Act. The Order in Council may also include a prohibition against disclosing its existence or all or part of its content. Before imposing such a prohibition, the Governor in Council must, in particular, consider the extent to which disclosure could undermine the objective of the order, the necessity of the prohibition in light of the nature of the threat, the possibility of limiting its scope, its impact on the transparency and accountability of the Government of Canada, and any representations made by the affected TSPs. Before issuing the order, the Governor in Council must also consider the measure’s operational impact on the affected TSPs, its financial implications, its effect on the provision of telecommunications services in Canada—including the confidentiality and security of telecommunications—as well as its potential impacts on Canadians’ privacy. Ministerial Orders The Minister of Industry may, by Ministerial Order, impose highly operational measures when they are necessary and reasonable in view of a threat. The order may, in particular: Prohibit the use of specific products or services, order the disposal of personal information, and impose conditions on the use and provision of services; Prohibit or force TSPs to terminate service agreements; Require review processes for networks, facilities, and procurement plans; Require security plans, vulnerability assessments, and mitigation measures; Require the implementation of standards; Require a backup system; Prohibit TSPs from providing services to a specified person; Order the suspension of the provision of services to a specified person for a specified period; Prohibit certain upgrades; or Order TSPs to do or refrain from doing any specified act, subject to the limitations provided for by the Act. As with Orders in Council, the minister must consider the operational and financial impacts, the effect on the provision of services—including the confidentiality and security of telecommunications—and the potential implications for the privacy of Canadians. The minister may not order the interception of a private communication or a radio-based telephone communication, nor the decryption of an encrypted private communication. The Ministerial Order also comes with a provision stating that no compensation will be paid. The Act also sets forth a specific limitation: the suspension of service to an individual may be ordered only if the order is necessary to secure the Canadian telecommunications system against a threat of a technical nature specified in the order. Like an Order in Council, a Ministerial Order may include a prohibition on disclosure. Before imposing such a prohibition, the minister must consider comparable factors, including the impact of non-disclosure on the principles of transparency and accountability of the Government of Canada. Specifics regarding the publication of orders In principle, Orders in Council and Ministerial Orders must be published in the Canada Gazette within 90 days of their issuance, but the minister making the order may specify in the text itself that it need not be published. In addition, incorporation by reference facilitates the integration of technical documents that are subject to change. We can therefore expect this process to adopt international technical standards. Collection of information by the minister Bill C-8 provides that the minister may require the disclosure of information if they have reasonable grounds to believe that it is both reasonable for the information to be provided in view of the gravity of the threat and that it is necessary. However, a confidentiality framework is in place for the information provided, particularly when it involves trade secrets or financial, commercial, scientific, or technical information. Personal information and de-identified information are also subject to protective measures. The text also provides for the exchange of information among various federal authorities, as well as with the provinces, foreign countries, or certain international organizations under written agreements. The scope and content of personal or de-identified information must be reasonable in view of the gravity of the threat. The Act also provides for the disposal of personal or de-identified information when it is no longer needed. It should also be noted that personal and de-identified information are deemed to be confidential information for the purposes of Part 1, even if they have not been expressly designated as such. Part 2 of the Act – The Critical Cyber Systems Protection Act (CCSPA) It is important to note that this part of the Act will not take effect until the date or dates set by Order in Council. Furthermore, its actual applicability will depend on future designations, since Schedule 2 is currently blank. The framework has therefore been adopted, but it has yet to be implemented. Key concepts: What the Act actually aims to achieve The CCSPA applies to critical cyber systems as strictly defined by the text, that is, a cyber system that, if its confidentiality, integrity or availability were compromised, could affect the continuity or security of a vital service or vital system. The definition of “cyber system” is intentionally broad. In practice, the Act is therefore not limited to a “network” in the traditional sense; it can encompass platforms, cloud environments, control systems, digital services, and interconnected technical assets, provided that if they were compromised, it could affect a vital service or system. The version of the text that has been assented to also adds the definition of “internal audit”, which is an independent and objective review conducted in accordance with internationally recognized guidance on professional internal auditing practices. This reinforces the idea that the expected compliance goes beyond simply adopting internal policies and, where necessary, requires structured assurance mechanisms. How organizations are designated A “designated” operator that controls, operates, or owns a critical cyber system is required to comply with the provisions of the CCSPA and its regulations pertaining to that cyber system. How are operators designated? First, “vital services” and “vital systems” are those listed in Schedule 1, namely: telecommunications services, interprovincial or international pipeline and power line systems, nuclear energy systems, transportation systems that are within the legislative authority of Parliament, banking systems, and clearing and settlement systems. By Order in Council, items may be modified, or added to or removed from this schedule within the scope of authority provided for by the Act. Second, the Act includes a schedule—which is currently blank—that allows for the establishment of classes of operators and regulatory bodies responsible for these vital services or systems. In practice, compliance depends on both the vital service or system in question (Schedule 1) and the operator class in which the organization is classified (Schedule 2). Cyber security programs: The foundational requirement At the heart of the CCSPA is the requirement to develop a cyber security program. After being designated through an amendment to Schedule 2, an operator must establish, within 90 days, a program relating to its critical cyber systems. This program must include measures, in accordance with the regulations, to identify and manage organizational risks (including supply chains and the use of third-party products and services), protect critical cyber systems, detect incidents and minimize their consequences, as well as any other measures required by the regulations. The program is therefore not merely a policy—it must cover the entire risk management cycle and be amenable to a “compliance” review. This will force organizations and companies to respond quickly when such a designation is made. The Act also imposes a monitoring mechanism: once the program is established, the operator must notify the relevant regulatory body in writing. The Act also requires that any such program be updated periodically. Lastly, reporting requirements apply when significant changes occur, including changes to ownership or control, supply chains, and the use of third parties. This approach transforms cyber security into a governance and maintenance requirement, rather than a one-time project. Supply chains and third parties: From assessment to mitigation The CCSPA explicitly emphasizes supply chains. Once the risks related to supply chains and third parties have been identified in the program (paragraph 9(1)(a)), the designated operator is required to mitigate them (section 15). The verb is important: it is not enough simply to “observe” or “monitor”; the law requires an active mitigation effort, which must be demonstrable. The Communications Security Establishment (the “CSE”) may develop guidelines on mitigating risks associated with supply chains and the use of third-party products and services, drawing on internationally recognized frameworks. The appropriate regulator may also provide the CSE with information—including confidential information—regarding the program or the measures taken, so that the CSE can provide advice, guidance, and services in accordance with its mandate. For organizations, this signals a convergence between regulatory requirements and technical expectations: managing suppliers, access, updates, software dependencies, and subcontractors is becoming a core component of compliance. Incident reporting: A requirement for speed and coordination The CCSPA establishes a requirement to report cyber security incidents to the CSE. Every designated operator must report any cyber security incident involving one of its critical cyber security systems within the prescribed time limits, which may not exceed 72 hours. The definition of “cyber security incident” covers an incident (including an act, omission, or circumstance) that interferes or may interfere with the continuity or security of a vital service or system, or the confidentiality, integrity, or availability of a critical cyber system. After filing a report with the CSE, the operator must, without delay, notify the appropriate regulatory body and provide it with a copy of the incident report. The text specifies that these obligations do not diminish the obligations arising from the Personal Information Protection and Electronic Documents Act. Cyber security guidelines: The mandatory response tool The CCSPA provides for a particularly intrusive measure: cyber security directions. By Order in Council, the government may direct any designated operator or class of operators to comply with any measure set out in the direction for the purpose of protecting a critical cyber system, but only if it has reasonable grounds to believe that the direction is necessary. Before issuing the order, the government must consider the operational impacts, public safety, privacy protection, financial impacts, and the impacts on the provision of vital services and systems. The scope and content must be reasonable in relation to the protection objective, and the operator in question is required to comply. The law also sets out two explicit limitations: the Governor in Council may not order the decryption of an encrypted private communication or the interception of a private communication or a radio-based telephone communication. In addition, a safeguard related to awareness has been put in place: an operator cannot be found guilty of contravening the direction unless they were notified of it or reasonable steps were taken to inform them of it. However, it will be important for an operator not to ignore the notifications received, even if they sometimes seem minor. The operator in question may not disclose the existence or content of a direction except to the extent necessary to comply with it. This requirement has a significant practical impact: it mandates the implementation of a “need-to-know” policy both internally and with respect to suppliers, subcontractors, insurers, and other partners. Information: Confidentiality, sharing, and removal of personal information The CCSPA establishes a comprehensive information-sharing framework, in particular to support the making, amending or revoking of directions. For purposes related to the making, amending or revoking of a direction, certain entities may collect and share information—including confidential information—with one another. The law also regulates the disclosure and use of confidential information and provides for exceptions, particularly when disclosure is required by law or necessary to protect vital services, systems, or cyber systems. “Provable” compliance The CCSPA requires the maintenance of records covering program implementation, reported incidents, steps taken to mitigate third-party risks, compliance with directions, and any other matters specified by the regulations. These documents must be kept in Canada in accordance with the terms and conditions prescribed by the regulations or, in the absence thereof, by the appropriate regulator. This requirement is central: it transforms compliance into a burden of proof. The regulatory framework provides for broad audit and enforcement powers, which are exercised by different authorities—the Superintendent of Financial Institutions, the Minister of Industry through inspectors, the Bank of Canada, the Canadian Nuclear Safety Commission, the Canadian Energy Regulator, and the Minister of Transport—depending on the sector. The provisions governing access to premises, the examination of cyber security systems, and the reproduction and temporary seizure of documents and systems are detailed in the CCSPA. Mechanisms for internal audits and compliance orders are in place, depending on the authority. The law prohibits obstruction and the provision of false or misleading information, which underscores the importance of the quality of the information provided. The version of the text that has been assented to also adds an explicit provision: the CCSPA does not infringe upon solicitor-client privilege or the professional secrecy of lawyers or notaries. Watch out for penalties! It should be noted that the law provides for substantial administrative penalties, as well as criminal offences (including imprisonment). Executives and directors may be considered co-perpetrators of a violation or offence, as the case may be. Ongoing violations can be counted on a day-by-day basis. Under Part 2 of the Act, administrative penalties may reach $500,000 for an individual and $15,000,000 in other cases. Furthermore, certain violations constitute criminal offences that are punishable, in some cases, either through charges or summary proceedings. Depending on the nature of the violation and whether the offender is an individual, imprisonment may be possible. How we can assist you in implementing Bill C-8 In particular, we can assist you with the following: Regulatory positioning Mapping your exposure (in terms of telecommunications, vital services or systems, and your current or anticipated designation) and establishing a realistic roadmap, prioritized by risk Responding to the imposed measures Supporting the receipt, analysis, and implementation of Orders in Council, Ministerial Orders, or directions Compliance Establishing or strengthening governance, record-keeping, and internal processes (including requests for information, audits and inspections, and the traceability of decisions) Third parties and procurement Reviewing and negotiating contracts and security requirements (including incident reporting, cooperation, audits, subcontracting, corrections, and withdrawal/replacement) and documenting mitigation measures Incidents and enforcement Supporting incident response (including triage, notifications, and the preservation of evidence) and managing the risk of penalties and criminal liability, including for executives and directors Conclusion In practice, organizations that may be affected would be wise to start preparing now, even though Part 2 of the law is not yet in force. The practical scope of the Act will depend on the CCSPA coming into force, the adoption of implementation regulations, and the inclusion in Schedule 2 of the classes of operators concerned and their corresponding regulators. In the meantime, organizations that begin structuring their governance, documentation, and third-party management now will be better positioned to adapt quickly once the sector-specific requirements are clarified.

    Read more
  2. Data Anonymization: Not as Simple as It Seems

    Blind spots to watch for when anonymizing data Anonymization has become a crucial step in unlocking the value of data for innovation, particularly in artificial intelligence. But without a properly executed anonymization process, organizations risk financial penalties, legal action and serious reputational harm, with potentially significant consequences for their operations. Understanding the anonymization process What the law says Under Quebec’s Act respecting the protection of personal information in the private sector (the “Private Sector Act”) and the Act respecting Access to documents held by public bodies and the Protection of personal information (the “Access Act”), information concerning a natural person is considered anonymized if it irreversibly no longer allows the person to be identified directly or indirectly. Since anonymized information no longer qualifies as personal information, this distinction is of crucial importance. However, beyond this definition, neither Act provides details on how anonymization should actually be performed. To fill this gap, the government adopted the Regulation respecting the anonymization of personal information (the “Regulation”), which sets out the criteria and framework for anonymization, grounded in high standards of privacy protection. What organizations need to know before starting Under the Regulation, before beginning any anonymization process, organizations must clearly define the “serious and legitimate purposes” for which the data will be used. These purposes must comply with either the Private Sector Act or the Access Act, as applicable, and any new purpose must meet the same requirement. The process must also be supervised by a qualified professional with the expertise to select and apply appropriate anonymization techniques. This supervision ensures both the proper implementation of the chosen methods and the ongoing validation of technological choices and security measures. The four key steps of data anonymization   DepersonalizationThe first step is to remove or replace all personal identifiers, such as names, addresses and phone numbers, with pseudonyms. It is essential to anticipate how different data sets might interact, in order to minimize the risk of re-identifying individuals through cross-referencing. Preliminary risk assessmentNext comes a preliminary analysis of re-identification risks. This step relies on three main criteria: individualization (inability to isolate a person within a dataset), correlation (inability to connect datasets concerning the same person) and inference (inability to infer personal information from other available information). Common anonymization techniques include aggregation, deletion, generalization and data perturbation. Organizations should also apply strong protective measures, such as advanced encryption and restrictive access controls, to minimize the likelihood of re-identification. In-depth risk analysisAfter the preliminary phase, a deeper risk analysis must be conducted. While no anonymization process can eliminate all risk, that risk must be reduced to the lowest possible level, taking into account factors such as data sensitivity, the availability of public datasets and the effort required to attempt re-identification. To sustain this low level of risk, organizations should perform periodic reassessments that account for technological advances that could make re-identification easier over time. Documentation and record-keepingFinally, organizations must keep a detailed record describing the anonymized information, its intended purposes, the techniques and security measures used, and the dates of any analyses or updates. This documentation strengthens transparency and demonstrates that the organization has fulfilled its legal obligations regarding anonymization.

    Read more
  3. Application for an interim injunction: Manufactured urgency is not a 9-1-1 emergency

    On March 3, 2025, Superior Court Justice Nancy Bonsaint dismissed an application for an interim interlocutory injunction that would allow Les Entreprises de la Batterie inc. to use a property it did not own for major construction work on its building. The judgment serves as a reminder that a party cannot manufacture a sense of urgency and then use that to support its application for an interim injunction. Summary of facts The Plaintiff, Les Entreprises de la Batterie inc., owns a building that has been under construction since March 2021, in order to convert it into a hotel that will serve as an extension to the hotel the Plaintiff currently operates.1 The Defendant owns a hotel and a piece of property adjacent to the building under construction. The property is used as a parking lot for his hotel guests.2 Construction work on the Plaintiff’s building was initially carried out in two separate phases, from March to November 20213 and from August 23, 2022, to July 2024.4 During those phases, the Parties reached various agreements whereby the Plaintiff could use one (1) of the Defendant’s parking spaces, in exchange for compensation.5 On February 14, 2025, the Plaintiff informed the Defendant that it planned to begin a new phase of construction (Phase 3) on February 28, 2025.6 The Plaintiff also informed the Defendant that, as part of the new phase of construction, the Plaintiff would need to use half of the Defendant’s parking lot, that is, six (6) parking spaces, and that the entrance to the parking lot would have to be relocated for more than two (2) years.7 Additionally, the Plaintiff pointed out that it would need access to the Defendant’s entire parking lot for a few days in the spring of 2025.8 The Plaintiff alleged that construction work on its building had to begin urgently on February 28, 2025.9 The Defendant objected to having to tolerate such a major disruption for an additional two (2) years, given that he had endured the inconveniences caused by the Plaintiff’s construction work for over four (4) years now, without being offered any form of compensation that would be considered fair or reasonable in the circumstances. On February 27, 2025, the Plaintiff brought anoriginating application before Justice Bonsaint, seeking orders for an interim interlocutory injunction, an interlocutory injunction and a permanent injunction, as well as for a declaration of abuse of process and damages, which was amended on February 28, 2025.10 At the interim interlocutory injunction stage, the Plaintiff asked the Court to issue a temporary order granting the Plaintiff access to the Defendant’s six (6) parking spaces so it could continue setting up its construction site.11 The Plaintiff also sought reimbursement of the professional fees incurred in applying for the injunction. The Plaintiff alleged that the hotel expansion was [TRANSLATION] “a large-scale project with costs in the tens of millions of dollars”.12 The Plaintiff further alleged that [TRANSLATION] “there is an urgent need for the construction work required to repurpose the building and turn it into a hotel to continue, without being interrupted by the Defendant’s actions”.13 The Plaintiff argued that halting construction work on its building would result in delays, significantly disrupting the timeline of the project, which was planned over the next two (2) years. Furthermore, it would lead to substantial additional costs associated with the various extras charged by the contractors it had hired to carry out the conversion and construction work.14 Needless to say, the Defendant opposed the application for an interim interlocutory injunction, arguing in particularthat the facts alleged by the Plaintiff failed to meet the urgency test.15 Those are the facts that Justice Bonsaint took into account when rendering her decision. The criteria for granting interim interlocutory injunctions In her judgment, Justice Bonsaint reviewed the legal principles governing interim interlocutory injunction applications. We will do the same below. The criteria for granting an interim interlocutory injunction are as follows: Urgency Serious issue to be tried or strong prima facie case Serious or irreparable harm Balance of convenience16 It is a discretionary and exceptional remedy that should only be granted sparingly and under strict conditions.17 The urgency criterion Urgency is [TRANSLATION] “of paramount importance”18 in determining whether an interim interlocutory injunction should be granted. If the urgency test is not met, the application simply cannot be allowed.19 Courts often describe the level of urgency required as being akin to [TRANSLATION] “a 9-1-1 emergency”.20 Interim interlocutory injunctions should only be granted in cases of [TRANSLATION] “extreme urgency”.21 For a court to find that the urgency test is met, the urgency must not result from a delay in bringing legal action. It must be [TRANSLATION] “immediate and apparent”—not the product of the plaintiff’s own lack of diligence.22 In other words, [TRANSLATION] “the alleged urgency must be real—not manufactured by the person asserting it”.23 Upon reviewing the case, Justice Bonsaint noted that the Defendant had been made aware only on January 31, 2025, that the Plaintiff would need access to his property for construction work.24 Prior to January 2025, the Plaintiff had not informed the Defendant of its true intentions regarding the work.25 It was not until February 14, 2025, that the Plaintiff officially informed the Defendant of the nature of the access required for the third phase of the project, namely, the use of at least half of the Defendant’s property from February 28, 2025, to March 31, 2027.26 Further to the Defendant’s contestation, Justice Bonsaint noted that the Plaintiff had known for several months that the third phase of the work would begin in early 2025.27 She found that the Plaintiff [TRANSLATION] “had not treated the issue of accessing the parking lot as one requiring urgent resolution”.28 The Plaintiff tried to justify its failure to be proactive, arguing that it had been unable to inform the Defendant of its space requirements before 2025 because the project timeline was still unknown at the time.29 However, Justice Bonsaint found that such explanations simply did not excuse the Plaintiff’s delay in filing its application for an interim interlocutory injunction against the Defendant.30 On the contrary, the supporting documents that the Plaintiff had submitted with its letter dated February 14, 2025, such as a plan of the Defendant’s parking lot and the preliminary project timeline, included references to “2024”.31 Given the above, Justice Bonsaint could only conclude that the Plaintiff had known for several months that construction work on its building was scheduled to begin in 2025.32 On that point, Justice Bonsaint was clear: [TRANSLATION] “The Court understands that preliminary construction timelines may be subject to change, but there is nothing to suggest that construction needed to begin ‘urgently’ on February 28, 2025. . . . the Plaintiff should have taken action as early as January 2025”.33 The Plaintiff had been aware of the access issues involving the Defendant’s property since the fall of 2024—and certainly since January 2025.34 Those issues should have prompted discussions between the Parties’ lawyers well before February 2025, and no later than January 2025.35 Discussions or attempts to settle the matter The Plaintiff also argued that, at the interim interlocutory injunction stage, discussions or attempts to settle the matter could have a bearing in determining whether the urgency requirement was met.36 Justice Bonsaint rejected that argument, given that no real negotiations had taken place, other than failed calls in November and December 2024, and again in January 2025, and that the Plaintiff had been aware of the access issues involving the Defendant’s property since the fall of 2024—and certainly since January 2025. Consequently, Justice Bonsaint dismissed the application for an interim interlocutory injunction, seeing as the Plaintiff had asked the Court to find that such an order, which would grant the Plaintiff access to half of the Defendant’s parking lot for two (2) years, needed to be issued urgently, even though the Plaintiff itself had not considered the need to access the parking lot as being an urgent matter to be resolved before the third phase of construction began.37 Key takeaways The urgency criterion is of paramount importance in determining whether an interim interlocutory injunction should be granted. That requirement must be met for the Court to allow such an application. In assessing the facts and allegations related to an application for an interim interlocutory injunction, the Court must ensure that the urgency is real—akin to a 9-1-1 situation—and not manufactured by the party seeking the relief. A delay attributable to the plaintiff cannot serve as a basis for granting an interim interlocutory injunction against the defendant. Half-hearted attempts at settlement discussions or negotiations do not excuse the delay between a party becoming aware of the facts warranting an interim interlocutory injunction and the filing of the application. Diligence is therefore essential in managing and mounting such cases, making it more likely that an interim interlocutory injunction will be granted. Entreprises de la Batterie inc. c. Biron, 2025 QCCS 608, paras. 1 and 10 (hereinafter the “Judgment”). Judgment, para. 4. Judgment, para. 10. Judgment, paras. 16 to 19. Judgment, paras. 10 to 18. Judgment, para. 27. Judgment, paras. 3 and 27. Judgment, para. 3. Judgment, para. 2. Judgment, para. 6. Judgment, para. 7. Judgment, para. 46. Judgment, para. 47. Judgment, para. 48. Judgment, para. 8. Judgment, paras. 35 and 37 to 39. Judgment, para. 36. Judgment, para. 41. Id. Judgment, paras. 41 and 43. Judgment, para. 42. Judgment, para. 42. Judgment, para. 40. Judgment, paras. 61 and 62. Judgment, para. 62. Judgment, paras. 64 and 65. Judgment, para. 68. Id. Judgment, para. 74. Judgment, para. 75. Judgment, paras. 76 and 77. Judgment, para. 82. Judgment, para. 82. Judgment, para. 84. Judgment, para. 85. Judgment, para. 83. Judgment, para. 90.

    Read more
  4. Businesses: Four tips to avoid dependency or vulnerability in your use of AI

    While the world is focused on how the tariff war is affecting various products, it may be overlooking the risks the war is posing to information technology. Yet, many businesses rely on artificial intelligence to provide their services, and many of these technologies are powered by large language models, such as the widely-used ChatGPT. It is relevant to ask whether businesses should rely on purely US-based technology service providers. There is talk of using Chinese alternatives, such as DeepSeek, but their use raises questions about data security and the associated control over information. Back in 2023, Professor Teresa Scassa wrote that, when it comes to artificial intelligence, sovereignty can take on many forms, such as state sovereignty, community sovereignty over data and individual sovereignty.1 Others have even suggested that AI will force the recalibration of international interests.2 In our current context, how can businesses protect themselves from the volatility caused by the actions of foreign governments? We believe that it’s precisely by exercising a certain degree of sovereignty over their own affairs that businesses can guard against such volatility. A few tips: Understand Intellectual property issues: Large language models underlying the majority of artificial intelligence technologies are sometimes offered under open-source licenses, but certain technologies are distributed under restrictive commercial licenses. It is important to understand the limits imposed by the licenses under which these technologies are offered. Some language model owners reserve the right to alter or restrict the technology’s functionality without notice. Conversely, permissive open-source licenses allow a language model to be used without time restrictions. From a strategic standpoint, businesses should keep intellectual property rights over their data compilations that can be integrated into artificial intelligence solutions. Consider other options: Whenever technology is used to process personal information, a privacy impact assessment is required by law before such technology is acquired, developed or redesigned.[3] Even if a privacy impact assessment is not legally required, it is prudent to assess the risks associated with technological choices. If you are dealing with a technology that your service provider integrates, check whether there are alternatives. Would you be able to quickly migrate to one of these if you faced issues? If you are dealing with custom solution, check whether it is limited to a single large language model. Adopt a modular approach: When a business chooses an external service provider to provide a large language model, it is often because the provider offers a solution that is integrated to other applications that the business already uses, or because it provides an application programming interface developed specifically for the business. In making such a choice, you should determine whether the service provider can replace the language model or application if problems were to arise. If the technology in question is a fully integrated solution from a service provider, find out whether the provider offers sufficient guarantees that it could replace a language model if it were no longer available. If it is a custom solution, find out whether the service provider can, right from the design stage, provide for the possibility of replacing one language model with another. Make a proportionate choice: Not all applications require the most powerful language models. If your technological objective is middle-of-the-road, you can consider more possibilities, including solutions hosted on local servers that use open-source language models. As a bonus, if you choose a language model proportionate to your needs, you are helping to reduce the environmental footprint of these technologies in terms of energy consumption.  These tips each require different steps to be put into practice. Remember to take legal considerations, in addition to technological constraints, into account. Licenses, intellectual property, privacy impact assessments and limited liability clauses imposed by certain service providers are all aspects that need to be considered before making any changes. This isn’t just about being prudent—it’s about taking advantage of the opportunity our businesses have to show they are technologically innovative and exercise greater control over their futures. Scassa, T. 2023. “Sovereignty and the governance of artificial intelligence.” 71 UCLA L. Rev. Disc. 214. Xu, W., Wang, S., & Zuo, X. 2025. “Whose victory? A perspective on shifts in US-China cross-border data flow rules in the AI era.” The Pacific Review, 1–27. See in particular the Act respecting the protection of personal information in the private sector, CQLR c. P-39.1, s. 3.3.

    Read more
  1. Lavery assists Agendrix in obtaining two ISO certifications for data security and privacy

    On February 6, 2023, Agendrix, a workforce management software company, announced that it had achieved certification in two globally recognized data security and privacy standards, ISO/IEC 27001:2013 and ISO/IEC 27701:2019. This made it one of the first staff scheduling and time clock software providers in Canada to obtain these certifications. The company is proactively engaging in all matters related to the security and confidentiality of the data processed by its web and mobile applications. The ISO/IEC 27001:2013 standard is aimed at improving information security systems. For Agendrix’s customers, that means its products comply with the highest information security standards. ISO/IEC 27701:2019 provides a framework for the management and handling of personal information and sensitive data. This certification confirms that Agendrix follows best practices and complies with applicable laws. A Lavery team composed of Eric Lavallée, Dave Bouchard, Ghiles Helli and Catherine Voyer supported Agendrix in obtaining these two certifications. More specifically, our professionals assisted Agendrix in the review of their standard contract with their customers, as well as in the implementation of policies and various internal documents essential to the management of personal information and information security. Agendrix was founded in 2015, and the Sherbrooke-based company now has over 150,000 users in some 13,000 workplaces. Its personnel management software is a leader in Quebec in the field of work schedule management for small and medium-sized businesses. Agendrix’s mission is to make management more human-centred by developing software that simplifies the lives of front-line employees. Today, the company employs more than 45 people.

    Read more
  2. Lavery represents ImmunoPrecise Antibodies as it acquires BioStrand

    On March 29, 2022, ImmunoPrecise Antibodies Ltd (IPA) announced that it acquired BioStrand BV, BioKey BV, and BioClue BV (together, “BioStrand”), a group of Belgian entities pioneers in the field of bioinformatics and biotechnology. With this €20 million acquisition, IPA will be able to leverage BioStrand’s revolutionary AI-powered methodology to accelerate the development of therapeutic antibody solutions. In addition to creating synergies with its subsidiaries, IPA expects to develop new markets with this revolutionary technology and strengthen its position as a world leader in biotherapeutics. Lavery was privileged to support IPA in this cross-border transaction by providing specialized expertise in cybersecurity, intellectual property, securities and mergers and acquisitions. The Lavery team was led by Selena Lu (transactional) and included Eric Lavallée (technology and intellectual property), Serge Shahinian (intellectual property), Sébastien Vézina (securities), Catherine Méthot (transactional), Jean-Paul Timothée (securities and transactional), Siddhartha Borissov-Beausoleil (transactional), Mylène Vallières (securities) and Marie-Claude Côté (securities). ImmunoPrecise Antibodies Ltd. is a biotherapeutic, innovation-powered company that supports its business partners in their quest to discover and develop novel antibodies against a broad range of target classes and diseases.

    Read more