If your legal department is like most, data privacy is already consuming most of your team’s time. That is according to the white paper from FTI Consulting and Relativity called “The General Counsel Report 2025: The Data Guardian in Chief,” which says that 61 percent of legal departments spend most of their time handling data privacy concerns.
Data privacy and the general counsel
Privacy in Canada is not an IT department issue anymore, and it has not been for some time. Yet many organisations still treat it that way.
Travis Walker, a Partner at Norton Rose Fulbright Canada LLP in Toronto, puts it plainly: “I think it is still fair in some instances to say that certain organizations still view these risks somewhat as a technology problem, like kind of an IT problem. We talk to clients about not doing that. These are enterprise organizational level risks and the governance really needs to reflect that.”
For a general counsel (GC) or chief legal officer (CLO), this means owning the governance architecture, such as the policies, reporting lines, board-level accountability, and response planning. “Everything else flows from that,” framed by Adam Kardash, Co-Chair of the National Privacy and Data Management Practice at Osler, Hoskin & Harcourt LLP in Toronto.
The connection between laws on data privacy and the general counsel is, at its core, a governance responsibility. It belongs on the GC’s desk, and not just the Chief Technology Officer’s.
What your data retention policy is actually exposing
Most organisations collect far more data than they need, not to mention that they keep it far longer than they should. That gap is where liability lives.
Kardash identifies data retention as a recurring feature of major incidents. “If I would canvass the large scale incidents over the last 15 years, data retention challenges were a feature in many of those,” he says.
Walker also describes the scenario GCs dread most: a ransomware actor publishes stolen data, and the in-house team discovers the organisation held information it did not even know it had, some of it a decade old. The organisation is then legally required to notify people about a breach of data it should have destroyed years earlier.
Under Principle 5 of the Personal Information Protection and Electronic Documents Act (PIPEDA), organisations must destroy, erase, or anonymise personal information that no longer serves its original purpose.
PIPEDA then puts three questions that every GC should be able to answer right now:
- What data does the organisation hold, and where is it?
- Does any of it exceed its retention period?
- When was the destruction schedule last audited?
This video can be a start for organisations to understand their responsibilities under the PIPEDA:
Bookmark Lexpert’s In-House Lawyer page for more articles to help Canadian in-house lawyers and general counsel.
What to do when a data privacy breach happens
When a large-scale breach hits, legal teams lead and does just not play a supporting role. “Legal ends up playing an outsized role in ensuring consistency and appropriate communications tailored for the range of stakeholders — the various regulatory authorities, internal communications, customer communications, eventually individual notifications, broader public-facing communications and liaising accordingly,” says Kardash.
Two things the GC must have ready before the call comes:
- A privilege strategy: Kardash is clear that privilege issues are manageable, but only “if it’s thought out at the beginning.” Internal communication protocols must be established in advance, not improvised mid-crisis.
- Familiar external partners: “It really pays off if it’s not just calling them and saying, ‘you’re on our roster,’ but actually getting them to understand the company,” Kardash says. This applies especially to forensic firms, which start from scratch without prior knowledge of the organisation.
The upcoming laws, and what to do before they land
Canada’s legislative pipeline on PIPEDA and data privacy laws is active in 2026, and GCs should be tracking these three bills:
- Bill C8: This is the reintroduced federal cybersecurity bill for critical infrastructure. Walker says to expect it to pass soon, with mandatory incident response and supply-chain reporting obligations attached.
- Federal privacy reform: This refers to PIPEDA’s successor that has still not been tabled. “The federal privacy bill, PIPEDA, is over 25 years old now, so it is desperately in need of reform,” says Walker. Two prior bills died when Parliament was prorogued in January 2025.
- Bill C22: This is a lawful access bill which raises concerns around metadata retention and encryption back doors, with particular implications for technology-sector GCs.
Walker’s advice is unambiguous: “We recommend to clients, as this stuff gets tabled, start planning now.” That planning means auditing current incident response plans, privacy programs, and vendor agreements against what is likely coming, in addition to closing any gaps before the law even requires it.
Subscribe to the free Lexpert newsletter for more updates on Canadian laws, including topics concerning data privacy for general counsel and in-house lawyers.


