Back to furthermore
Furthermore Law
Privacy
Practice Area

Privacy Law

Privacy is a right. Get it right.

Privacy is Personal

Behind every database entry, credit card number, and email address is a real person.

Privacy law exists because this is not just data. These are people's lives. Canadian and international law treats privacy as a fundamental right, and it expects you to collect, use, and disclose personal information only for purposes a reasonable person would accept. In practice, that means handling information the way people expect — your sister in Halifax, the teenager glued to their phone, the patient in the waiting room, or the man mowing his lawn in his short sleeves.

For your organization, that same information is both an asset and a liability. The rush to collect data too often ignores the risk on the other side of the ledger. Some information carries even more weight: health records, or anything involving children, are a special class that demands extra care.

Privacy is not a problem you can patch after the fact. By the time something breaks, the damage is done, and the cost of a missed obligation or a breached standard of care can be severe. Build data protection in from the start — Privacy by Design and Security by Design embed controls into your software and operations before the first record is collected.

The rule is simple: if you cannot protect personal information, do not collect it.

Prescriptive Data Protection

For decades, privacy ran on broad principles. That era is closing. The rules are becoming prescriptive and specific, and they ask far more of every organization that handles personal information.

Today's regimes expect accountability built into how you operate, with clear limits on why you collect information, how it gets used, and whether it can be disclosed. They govern the full data lifecycle, from retention to secure disposal, and they demand transparency about how you handle information. They give individuals real rights — to access their data, correct it, delete it, and take it elsewhere — and they hold you to disciplined record keeping, including disclosing the third-party providers who handle data on your behalf.

Privacy as a Culture

Personal information is regulated everywhere, in Canada and around the world. Even within Canada, you face both public-sector and private-sector legislation, layered on top of overlapping provincial laws. Privacy rarely travels alone, either. It intersects with access to information, lawful access, and the fast-emerging rules on AI and social media. Coverage can follow your organization or the individual, and its reach is often extraterritorial — so a law written on the other side of the world can still land on your desk.

Chasing each rule one at a time is a losing game. The organizations that get this right treat privacy as a culture and a product architecture, not a compliance afterthought. The expectations that matter most — privacy impact assessments and express, informed consent — recur across jurisdictions, which makes coordinated compliance possible. Build them into how your teams work and how your products are designed, and compliance becomes a byproduct of good architecture rather than a scramble after the fact.

How We Get You There

Whether you are a business owner facing your first compliance obligations, an enterprise team that needs project-based privacy expertise, or an organization that needs an outsourced Data Protection Officer, we meet you where you are. Our privacy law services include:

  1. 01Compliance with Canadian and global privacy laws
  2. 02Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs)
  3. 03
    Commercial privacy agreements, including:
    • Software Services Agreements
    • Data Sharing Agreements
    • Data Processing Addendums
  4. 04Data Governance policies and procedures
  5. 05Indigenous Data Sovereignty governance negotiations
  6. 06On-site privacy training for boards, executives, and personnel

Privacy never stands alone, and neither do we. Our privacy work is reinforced by adjacent practices in Information Security, Regulatory Law, and AI Governance — giving you breadth across every data protection domain from a single team.

Let us help you get privacy right.

Start a conversation