SlideShare a Scribd company logo
The Start-up’s Guide to Privacy at MaRS:
Legal Basics & Does Privacy Matter?
Stephen Whitney
Of Counsel
Norton Rose Fulbright Canada LLP
January 28, 2016
2
Agenda
Privacy Legislation in Canada
Comments on International Privacy Laws
What To Know About Your Privacy Practices
Does Privacy Matter?
Privacy Legislation in Canada
3
A.  Federal Legislation
•  PIPEDA - The Personal Information Protection and Electronic
Documents Act
PIPEDA applies across the country but for private companies
that primarily operate in a single province, PIPEDA will not
apply where the province has already enacted similar provisions
to PIPEDA and the business fits within the scope of the
provincial legislation.
Recommended Reading:
Privacy Toolkit
A Guide for Businesses and Organizations
Canada's Personal Information Protection and Electronic Documents Act
https://www.priv.gc.ca/information/pub/guide_org_e.pdf
4
Recommended ReadingPrivacy Legislation in Canada
PIPEDA and Digital Health
5
PIPEDA does not impose special obligations on digital health
companies.
Under s. 30(1.1), the Act states that the duties imposed on the use of
personal information in the private sector:
…does not apply to any organization in respect of personal health
information that it collects, uses or discloses within a province …
unless the organization … discloses the information outside
the province … .
Privacy Legislation in Canada
6
B. Some of the Provincial Legislation Includes:
•  British Columbia (Personal Information Act);
•  Alberta (Personal Information Protection Act);
•  Quebec (An Act Respecting the Protection of Personal Information
in the Private Sector);
•  Ontario (Personal Health Information Protection Act);
•  New Brunswick (Personal Health Information Privacy and Access
Act); and
•  Newfoundland and Labrador (Personal Health Information Act).
Comments on International Privacy Laws
7
•  International privacy laws are often similar, but not identical.
•  Typically based off of privacy principles.
•  International privacy compliance is very challenging!
•  The result is often a risk assessment of how to approach
privacy.
•  Do you have one approach globally or can you customize your
approach for unique country requirements?
Some important things to know about your privacy practices include:
•  Sector
•  Target audience
•  Countries
•  Business model
•  Operational procedures
8
What To Know About Your Privacy Practices
More specifically, for operational procedures it is important to know:
•  What personal information and information does the company collect
from the user of its products and services, website, apps, etc. and what is
the context?
•  Account and membership information?
•  Unique identifiers?
•  Information from children under 18 or under 13 years of age?
•  Information about applications used on computer/device?
•  Third party offerings (i.e. products, services, software, websites or content
provided by a third party)?
•  Cookies or similar technologies?
9
What To Know About Your Privacy Practices (cont)
•  Financial information?
•  Does the company process online payments?
•  Are the payments processed by the company or a third party payment
processor?
•  What other financial information, if any, is collected?
•  Does the company track the purchase history of customers?
•  General usage data?
•  Location information?
•  Quality assurance and customer service?
•  Health information?
•  Other?
10
What To Know About Your Privacy Practices (cont)
•  For what purposes does company use the personal information it
collects?
•  billing, activation, provision, maintenance, support, trouble shooting, resolving of
disputes, deactivation, repair, refurbishment, replacement, upgrade or update of
offerings
•  to manage or respond to your inquiries
•  to develop new and enhance existing offerings including to communicate with you
about them using various means
•  to manage and develop your business and operations
•  to meet legal and regulatory requirements and to respond to emergency situations
•  Does company use sales information?
•  Do you send marketing communications (for example, emails)?
11
What To Know About Your Privacy Practices (cont)
•  To whom does company disclose the personal information?
•  Affiliates, Service Providers, Third Parties, Other?
•  Do you send any of the personal information you collect to other
countries?
•  Data Retention
•  Where stored?
•  How long keep?
•  When and how destroy? Make anonymous?
•  Security
•  Adequate protections implemented?
•  Encryption used? At rest and in transit?
12
What To Know About Your Privacy Practices (cont)
•  Do you obtain consent? When, where, how? If yes, what does the consent say?
•  Consent by layers
•  Terms and conditions
•  Privacy policy
•  Notices
•  Reminders/Icons
13
What To Know About Your Privacy Practices (cont)
Discussion based off of Prof. Michael Sandel’s
keynote at IAPP
• Uber
• Connected Cars
• Email Providers
14
Does Privacy Matter?
Stephen Whitney
Of Counsel
Norton Rose Fulbright Canada LLP / S.E.N.C.R.L., s.r.l.
51 Breithaupt Street, Suite 100
Kitchener, Ontario N2H 5G5 Canada
OR
Royal Bank Plaza, South Tower, Suite 3800
200 Bay Street, P.O. Box 84, Toronto, ON M5J 2Z4 Canada
T: +1 226.868.9125
stephen.whitney@nortonrosefulbright.com
15
Disclaimer
Norton Rose Fulbright LLP, Norton Rose Fulbright Australia, Norton Rose Fulbright Canada LLP, Norton Rose Fulbright South Africa (incorporated as Deneys Reitz Inc) and Fulbright & Jaworski LLP,
each of which is a separate legal entity, are members (‘the Norton Rose Fulbright members’) of Norton Rose Fulbright Verein, a Swiss Verein. Norton Rose Fulbright Verein helps coordinate the
activities of the Norton Rose Fulbright members but does not itself provide legal services to clients.
References to ‘Norton Rose Fulbright’, ‘the law firm’, and ‘legal practice’ are to one or more of the Norton Rose Fulbright members or to one of their respective affiliates (together ‘Norton Rose
Fulbright entity/entities’). No individual who is a member, partner, shareholder, director, employee or consultant of, in or to any Norton Rose Fulbright entity (whether or not such individual is
described as a ‘partner’) accepts or assumes responsibility, or has any liability, to any person in respect of this communication. Any reference to a partner or director is to a member, employee or
consultant with equivalent standing and qualifications of the relevant Norton Rose Fulbright entity.
The purpose of this communication is to provide information as to developments in the law. It does not contain a full analysis of the law nor does it constitute an opinion of any Norton Rose Fulbright
entity on the points of law discussed. You must take specific legal advice on any particular matter which concerns you. If you require any advice or further information, please speak to your usual
contact at Norton Rose Fulbright.
17

More Related Content

Viewers also liked

Merger acquisition sampoerna philip morris
Merger acquisition sampoerna philip morrisMerger acquisition sampoerna philip morris
Merger acquisition sampoerna philip morris
Frisca Listyaningtyas
 
Infrastructure regulation - exploring the key models (Australia)
Infrastructure regulation - exploring the key models (Australia)Infrastructure regulation - exploring the key models (Australia)
Infrastructure regulation - exploring the key models (Australia)
Martyn Taylor
 
Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)
Robert MacLean
 
Lions and Mergers and Acquisitions, OH MY! 5 Steps to an Effective M&A Runbook.
Lions and Mergers and Acquisitions, OH MY!  5 Steps to an Effective M&A Runbook.Lions and Mergers and Acquisitions, OH MY!  5 Steps to an Effective M&A Runbook.
Lions and Mergers and Acquisitions, OH MY! 5 Steps to an Effective M&A Runbook.
Sirius
 
Mergers and acquisitions
Mergers and acquisitionsMergers and acquisitions
Mergers and acquisitions
Pradeep Yuvaraj
 
mergers and acquisitions
  mergers and acquisitions  mergers and acquisitions
mergers and acquisitions
Babasab Patil
 

Viewers also liked (7)

Merger acquisition sampoerna philip morris
Merger acquisition sampoerna philip morrisMerger acquisition sampoerna philip morris
Merger acquisition sampoerna philip morris
 
Infrastructure regulation - exploring the key models (Australia)
Infrastructure regulation - exploring the key models (Australia)Infrastructure regulation - exploring the key models (Australia)
Infrastructure regulation - exploring the key models (Australia)
 
Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)Protection of Personal Information Bill (POPI)
Protection of Personal Information Bill (POPI)
 
Lions and Mergers and Acquisitions, OH MY! 5 Steps to an Effective M&A Runbook.
Lions and Mergers and Acquisitions, OH MY!  5 Steps to an Effective M&A Runbook.Lions and Mergers and Acquisitions, OH MY!  5 Steps to an Effective M&A Runbook.
Lions and Mergers and Acquisitions, OH MY! 5 Steps to an Effective M&A Runbook.
 
Chapter 15 mergers and acquisitions
Chapter 15   mergers and acquisitionsChapter 15   mergers and acquisitions
Chapter 15 mergers and acquisitions
 
Mergers and acquisitions
Mergers and acquisitionsMergers and acquisitions
Mergers and acquisitions
 
mergers and acquisitions
  mergers and acquisitions  mergers and acquisitions
mergers and acquisitions
 

Similar to The Start-Up’s Guide to Privacy - MaRS Best Practices

B2: Fundraising in an age of GDPR
B2: Fundraising in an age of GDPRB2: Fundraising in an age of GDPR
B2: Fundraising in an age of GDPR
NCVO - National Council for Voluntary Organisations
 
Plunet Summit 2018: Plunet’s approach to the new data regulation of the EU (G...
Plunet Summit 2018: Plunet’s approach to the new data regulation of the EU (G...Plunet Summit 2018: Plunet’s approach to the new data regulation of the EU (G...
Plunet Summit 2018: Plunet’s approach to the new data regulation of the EU (G...
Plunet BusinessManager
 
Putting The Consumer First
Putting The Consumer FirstPutting The Consumer First
Putting The Consumer First
Vivastream
 
Putting the Consumer First
Putting the Consumer FirstPutting the Consumer First
Putting the Consumer FirstVivastream
 
The Story of a Lean Law Firm: Escaping the Overhead Swamp, Surviving Disrupti...
The Story of a Lean Law Firm: Escaping the Overhead Swamp, Surviving Disrupti...The Story of a Lean Law Firm: Escaping the Overhead Swamp, Surviving Disrupti...
The Story of a Lean Law Firm: Escaping the Overhead Swamp, Surviving Disrupti...
Gary Allen
 
Implementing And Managing A Multinational Privacy Program
Implementing And Managing A Multinational Privacy ProgramImplementing And Managing A Multinational Privacy Program
Implementing And Managing A Multinational Privacy ProgramMSpadea
 
EVERFI/Jackson Lewis: How to Comply with GDPR Requirements: What every U.S. C...
EVERFI/Jackson Lewis: How to Comply with GDPR Requirements: What every U.S. C...EVERFI/Jackson Lewis: How to Comply with GDPR Requirements: What every U.S. C...
EVERFI/Jackson Lewis: How to Comply with GDPR Requirements: What every U.S. C...
Michele Collu
 
Vendor Risk Management in Complex Matters (acc sa presentation)
Vendor Risk Management in Complex Matters (acc sa presentation)Vendor Risk Management in Complex Matters (acc sa presentation)
Vendor Risk Management in Complex Matters (acc sa presentation)
Amber Clark
 
GDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc MichaelsGDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc Michaels
Post Media
 
Introduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsIntroduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and Requirements
Financial Poise
 
I’m attaching some info on the agency I work for. I work remot.docx
I’m attaching some info on the agency I work for. I work remot.docxI’m attaching some info on the agency I work for. I work remot.docx
I’m attaching some info on the agency I work for. I work remot.docx
donnajames55
 
GDPR is Coming, Five Things You Can Do Now To Prepare
GDPR is Coming, Five Things You Can Do Now To PrepareGDPR is Coming, Five Things You Can Do Now To Prepare
GDPR is Coming, Five Things You Can Do Now To Prepare
Winston & Strawn LLP
 
Internet security and privacy issues
Internet security and privacy issuesInternet security and privacy issues
Internet security and privacy issues
JagdeepSingh394
 
Donors, Data Privacy & Security, and Doing What’s “Right”
Donors, Data Privacy & Security, and Doing What’s “Right”Donors, Data Privacy & Security, and Doing What’s “Right”
Donors, Data Privacy & Security, and Doing What’s “Right”
Bloomerang
 
Practical steps to take in preparation for the Protection of Personal Informa...
Practical steps to take in preparation for the Protection of Personal Informa...Practical steps to take in preparation for the Protection of Personal Informa...
Practical steps to take in preparation for the Protection of Personal Informa...Werksmans Attorneys
 
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Financial Poise
 
Family Law Magazine
Family Law MagazineFamily Law Magazine
Family Law Magazine
Thomas Mastromatto NMLS #145824
 
Corporate & Regulatory Compliance Boot Camp - Data Privacy Compliance
Corporate & Regulatory Compliance Boot Camp - Data Privacy ComplianceCorporate & Regulatory Compliance Boot Camp - Data Privacy Compliance
Corporate & Regulatory Compliance Boot Camp - Data Privacy Compliance
Financial Poise
 
Implementing and Auditing GDPR Series (8 of 10)
Implementing and Auditing GDPR Series (8 of 10) Implementing and Auditing GDPR Series (8 of 10)
Implementing and Auditing GDPR Series (8 of 10)
Jim Kaplan CIA CFE
 
A Global Marketer's Guide to Privacy
A Global Marketer's Guide to PrivacyA Global Marketer's Guide to Privacy
A Global Marketer's Guide to Privacy
FLUZO
 

Similar to The Start-Up’s Guide to Privacy - MaRS Best Practices (20)

B2: Fundraising in an age of GDPR
B2: Fundraising in an age of GDPRB2: Fundraising in an age of GDPR
B2: Fundraising in an age of GDPR
 
Plunet Summit 2018: Plunet’s approach to the new data regulation of the EU (G...
Plunet Summit 2018: Plunet’s approach to the new data regulation of the EU (G...Plunet Summit 2018: Plunet’s approach to the new data regulation of the EU (G...
Plunet Summit 2018: Plunet’s approach to the new data regulation of the EU (G...
 
Putting The Consumer First
Putting The Consumer FirstPutting The Consumer First
Putting The Consumer First
 
Putting the Consumer First
Putting the Consumer FirstPutting the Consumer First
Putting the Consumer First
 
The Story of a Lean Law Firm: Escaping the Overhead Swamp, Surviving Disrupti...
The Story of a Lean Law Firm: Escaping the Overhead Swamp, Surviving Disrupti...The Story of a Lean Law Firm: Escaping the Overhead Swamp, Surviving Disrupti...
The Story of a Lean Law Firm: Escaping the Overhead Swamp, Surviving Disrupti...
 
Implementing And Managing A Multinational Privacy Program
Implementing And Managing A Multinational Privacy ProgramImplementing And Managing A Multinational Privacy Program
Implementing And Managing A Multinational Privacy Program
 
EVERFI/Jackson Lewis: How to Comply with GDPR Requirements: What every U.S. C...
EVERFI/Jackson Lewis: How to Comply with GDPR Requirements: What every U.S. C...EVERFI/Jackson Lewis: How to Comply with GDPR Requirements: What every U.S. C...
EVERFI/Jackson Lewis: How to Comply with GDPR Requirements: What every U.S. C...
 
Vendor Risk Management in Complex Matters (acc sa presentation)
Vendor Risk Management in Complex Matters (acc sa presentation)Vendor Risk Management in Complex Matters (acc sa presentation)
Vendor Risk Management in Complex Matters (acc sa presentation)
 
GDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc MichaelsGDPR Ready Presentation - Marc Michaels
GDPR Ready Presentation - Marc Michaels
 
Introduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsIntroduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and Requirements
 
I’m attaching some info on the agency I work for. I work remot.docx
I’m attaching some info on the agency I work for. I work remot.docxI’m attaching some info on the agency I work for. I work remot.docx
I’m attaching some info on the agency I work for. I work remot.docx
 
GDPR is Coming, Five Things You Can Do Now To Prepare
GDPR is Coming, Five Things You Can Do Now To PrepareGDPR is Coming, Five Things You Can Do Now To Prepare
GDPR is Coming, Five Things You Can Do Now To Prepare
 
Internet security and privacy issues
Internet security and privacy issuesInternet security and privacy issues
Internet security and privacy issues
 
Donors, Data Privacy & Security, and Doing What’s “Right”
Donors, Data Privacy & Security, and Doing What’s “Right”Donors, Data Privacy & Security, and Doing What’s “Right”
Donors, Data Privacy & Security, and Doing What’s “Right”
 
Practical steps to take in preparation for the Protection of Personal Informa...
Practical steps to take in preparation for the Protection of Personal Informa...Practical steps to take in preparation for the Protection of Personal Informa...
Practical steps to take in preparation for the Protection of Personal Informa...
 
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
 
Family Law Magazine
Family Law MagazineFamily Law Magazine
Family Law Magazine
 
Corporate & Regulatory Compliance Boot Camp - Data Privacy Compliance
Corporate & Regulatory Compliance Boot Camp - Data Privacy ComplianceCorporate & Regulatory Compliance Boot Camp - Data Privacy Compliance
Corporate & Regulatory Compliance Boot Camp - Data Privacy Compliance
 
Implementing and Auditing GDPR Series (8 of 10)
Implementing and Auditing GDPR Series (8 of 10) Implementing and Auditing GDPR Series (8 of 10)
Implementing and Auditing GDPR Series (8 of 10)
 
A Global Marketer's Guide to Privacy
A Global Marketer's Guide to PrivacyA Global Marketer's Guide to Privacy
A Global Marketer's Guide to Privacy
 

More from MaRS Discovery District

How to Pitch a VC - Entrepreneurship 101
How to Pitch a VC - Entrepreneurship 101How to Pitch a VC - Entrepreneurship 101
How to Pitch a VC - Entrepreneurship 101
MaRS Discovery District
 
The Pitch - Entrepreneurship 101
The Pitch - Entrepreneurship 101The Pitch - Entrepreneurship 101
The Pitch - Entrepreneurship 101
MaRS Discovery District
 
25 lessons learned - Entrepreneurship 101
25 lessons learned - Entrepreneurship 10125 lessons learned - Entrepreneurship 101
25 lessons learned - Entrepreneurship 101
MaRS Discovery District
 
So you want to start a business? - Entrepreneurship 101
So you want to start a business? - Entrepreneurship 101So you want to start a business? - Entrepreneurship 101
So you want to start a business? - Entrepreneurship 101
MaRS Discovery District
 
Lessons in Startup Leadership - Entrepreneurship 101
Lessons in Startup Leadership - Entrepreneurship 101Lessons in Startup Leadership - Entrepreneurship 101
Lessons in Startup Leadership - Entrepreneurship 101
MaRS Discovery District
 
Why Should I Work for You? (The EVP)
Why Should I Work for You? (The EVP)Why Should I Work for You? (The EVP)
Why Should I Work for You? (The EVP)
MaRS Discovery District
 
A New Hiring Paradigm
A New Hiring ParadigmA New Hiring Paradigm
A New Hiring Paradigm
MaRS Discovery District
 
How to Find and Hire Top Talent
How to Find and Hire Top TalentHow to Find and Hire Top Talent
How to Find and Hire Top Talent
MaRS Discovery District
 
Startup finances: Forecasting, Modelling & Metrics
Startup finances:  Forecasting, Modelling & MetricsStartup finances:  Forecasting, Modelling & Metrics
Startup finances: Forecasting, Modelling & Metrics
MaRS Discovery District
 
Financial Modelling
Financial Modelling Financial Modelling
Financial Modelling
MaRS Discovery District
 
Forecasting Revenue
Forecasting RevenueForecasting Revenue
Forecasting Revenue
MaRS Discovery District
 
10+ Steps to Scaling Your Cheer Squad - Entrepreneurship 101
10+ Steps to Scaling Your Cheer Squad - Entrepreneurship 10110+ Steps to Scaling Your Cheer Squad - Entrepreneurship 101
10+ Steps to Scaling Your Cheer Squad - Entrepreneurship 101
MaRS Discovery District
 
Scaling Your Startup - Entrepreneurship 101
Scaling Your Startup - Entrepreneurship 101Scaling Your Startup - Entrepreneurship 101
Scaling Your Startup - Entrepreneurship 101
MaRS Discovery District
 
Scaling Outside Canada - Entrepreneurship 101
Scaling Outside Canada - Entrepreneurship 101Scaling Outside Canada - Entrepreneurship 101
Scaling Outside Canada - Entrepreneurship 101
MaRS Discovery District
 
Partnership Negotiations - Entrepreneurship 101
Partnership Negotiations - Entrepreneurship 101Partnership Negotiations - Entrepreneurship 101
Partnership Negotiations - Entrepreneurship 101
MaRS Discovery District
 
Licensing - Entrepreneurship 101
Licensing - Entrepreneurship 101Licensing - Entrepreneurship 101
Licensing - Entrepreneurship 101
MaRS Discovery District
 
Art of the deal 101: Notes from the Trenches - Entrepreneurship 101
Art of the deal 101: Notes from the Trenches - Entrepreneurship 101Art of the deal 101: Notes from the Trenches - Entrepreneurship 101
Art of the deal 101: Notes from the Trenches - Entrepreneurship 101
MaRS Discovery District
 
Social Selling - Entrepreneurship 101
Social Selling - Entrepreneurship 101Social Selling - Entrepreneurship 101
Social Selling - Entrepreneurship 101
MaRS Discovery District
 
The Art & Science of Sales: Tips, Tricks & Tools - Entrepreneurship 101
The Art & Science of Sales: Tips, Tricks & Tools - Entrepreneurship 101The Art & Science of Sales: Tips, Tricks & Tools - Entrepreneurship 101
The Art & Science of Sales: Tips, Tricks & Tools - Entrepreneurship 101
MaRS Discovery District
 
Sales Putting the Fun in Funnel - Entrepreneurship 101
Sales Putting the Fun in Funnel - Entrepreneurship 101Sales Putting the Fun in Funnel - Entrepreneurship 101
Sales Putting the Fun in Funnel - Entrepreneurship 101
MaRS Discovery District
 

More from MaRS Discovery District (20)

How to Pitch a VC - Entrepreneurship 101
How to Pitch a VC - Entrepreneurship 101How to Pitch a VC - Entrepreneurship 101
How to Pitch a VC - Entrepreneurship 101
 
The Pitch - Entrepreneurship 101
The Pitch - Entrepreneurship 101The Pitch - Entrepreneurship 101
The Pitch - Entrepreneurship 101
 
25 lessons learned - Entrepreneurship 101
25 lessons learned - Entrepreneurship 10125 lessons learned - Entrepreneurship 101
25 lessons learned - Entrepreneurship 101
 
So you want to start a business? - Entrepreneurship 101
So you want to start a business? - Entrepreneurship 101So you want to start a business? - Entrepreneurship 101
So you want to start a business? - Entrepreneurship 101
 
Lessons in Startup Leadership - Entrepreneurship 101
Lessons in Startup Leadership - Entrepreneurship 101Lessons in Startup Leadership - Entrepreneurship 101
Lessons in Startup Leadership - Entrepreneurship 101
 
Why Should I Work for You? (The EVP)
Why Should I Work for You? (The EVP)Why Should I Work for You? (The EVP)
Why Should I Work for You? (The EVP)
 
A New Hiring Paradigm
A New Hiring ParadigmA New Hiring Paradigm
A New Hiring Paradigm
 
How to Find and Hire Top Talent
How to Find and Hire Top TalentHow to Find and Hire Top Talent
How to Find and Hire Top Talent
 
Startup finances: Forecasting, Modelling & Metrics
Startup finances:  Forecasting, Modelling & MetricsStartup finances:  Forecasting, Modelling & Metrics
Startup finances: Forecasting, Modelling & Metrics
 
Financial Modelling
Financial Modelling Financial Modelling
Financial Modelling
 
Forecasting Revenue
Forecasting RevenueForecasting Revenue
Forecasting Revenue
 
10+ Steps to Scaling Your Cheer Squad - Entrepreneurship 101
10+ Steps to Scaling Your Cheer Squad - Entrepreneurship 10110+ Steps to Scaling Your Cheer Squad - Entrepreneurship 101
10+ Steps to Scaling Your Cheer Squad - Entrepreneurship 101
 
Scaling Your Startup - Entrepreneurship 101
Scaling Your Startup - Entrepreneurship 101Scaling Your Startup - Entrepreneurship 101
Scaling Your Startup - Entrepreneurship 101
 
Scaling Outside Canada - Entrepreneurship 101
Scaling Outside Canada - Entrepreneurship 101Scaling Outside Canada - Entrepreneurship 101
Scaling Outside Canada - Entrepreneurship 101
 
Partnership Negotiations - Entrepreneurship 101
Partnership Negotiations - Entrepreneurship 101Partnership Negotiations - Entrepreneurship 101
Partnership Negotiations - Entrepreneurship 101
 
Licensing - Entrepreneurship 101
Licensing - Entrepreneurship 101Licensing - Entrepreneurship 101
Licensing - Entrepreneurship 101
 
Art of the deal 101: Notes from the Trenches - Entrepreneurship 101
Art of the deal 101: Notes from the Trenches - Entrepreneurship 101Art of the deal 101: Notes from the Trenches - Entrepreneurship 101
Art of the deal 101: Notes from the Trenches - Entrepreneurship 101
 
Social Selling - Entrepreneurship 101
Social Selling - Entrepreneurship 101Social Selling - Entrepreneurship 101
Social Selling - Entrepreneurship 101
 
The Art & Science of Sales: Tips, Tricks & Tools - Entrepreneurship 101
The Art & Science of Sales: Tips, Tricks & Tools - Entrepreneurship 101The Art & Science of Sales: Tips, Tricks & Tools - Entrepreneurship 101
The Art & Science of Sales: Tips, Tricks & Tools - Entrepreneurship 101
 
Sales Putting the Fun in Funnel - Entrepreneurship 101
Sales Putting the Fun in Funnel - Entrepreneurship 101Sales Putting the Fun in Funnel - Entrepreneurship 101
Sales Putting the Fun in Funnel - Entrepreneurship 101
 

Recently uploaded

Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)
Lviv Startup Club
 
3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx
tanyjahb
 
Understanding User Needs and Satisfying Them
Understanding User Needs and Satisfying ThemUnderstanding User Needs and Satisfying Them
Understanding User Needs and Satisfying Them
Aggregage
 
Project File Report BBA 6th semester.pdf
Project File Report BBA 6th semester.pdfProject File Report BBA 6th semester.pdf
Project File Report BBA 6th semester.pdf
RajPriye
 
Authentically Social by Corey Perlman - EO Puerto Rico
Authentically Social by Corey Perlman - EO Puerto RicoAuthentically Social by Corey Perlman - EO Puerto Rico
Authentically Social by Corey Perlman - EO Puerto Rico
Corey Perlman, Social Media Speaker and Consultant
 
LA HUG - Video Testimonials with Chynna Morgan - June 2024
LA HUG - Video Testimonials with Chynna Morgan - June 2024LA HUG - Video Testimonials with Chynna Morgan - June 2024
LA HUG - Video Testimonials with Chynna Morgan - June 2024
Lital Barkan
 
Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challengesEvent Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
Holger Mueller
 
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdfModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
fisherameliaisabella
 
Set off and carry forward of losses and assessment of individuals.pptx
Set off and carry forward of losses and assessment of individuals.pptxSet off and carry forward of losses and assessment of individuals.pptx
Set off and carry forward of losses and assessment of individuals.pptx
HARSHITHV26
 
FINAL PRESENTATION.pptx12143241324134134
FINAL PRESENTATION.pptx12143241324134134FINAL PRESENTATION.pptx12143241324134134
FINAL PRESENTATION.pptx12143241324134134
LR1709MUSIC
 
The Influence of Marketing Strategy and Market Competition on Business Perfor...
The Influence of Marketing Strategy and Market Competition on Business Perfor...The Influence of Marketing Strategy and Market Competition on Business Perfor...
The Influence of Marketing Strategy and Market Competition on Business Perfor...
Adam Smith
 
Recruiting in the Digital Age: A Social Media Masterclass
Recruiting in the Digital Age: A Social Media MasterclassRecruiting in the Digital Age: A Social Media Masterclass
Recruiting in the Digital Age: A Social Media Masterclass
LuanWise
 
Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...
dylandmeas
 
Auditing study material for b.com final year students
Auditing study material for b.com final year  studentsAuditing study material for b.com final year  students
Auditing study material for b.com final year students
narasimhamurthyh4
 
In the Adani-Hindenburg case, what is SEBI investigating.pptx
In the Adani-Hindenburg case, what is SEBI investigating.pptxIn the Adani-Hindenburg case, what is SEBI investigating.pptx
In the Adani-Hindenburg case, what is SEBI investigating.pptx
Adani case
 
Agency Managed Advisory Board As a Solution To Career Path Defining Business ...
Agency Managed Advisory Board As a Solution To Career Path Defining Business ...Agency Managed Advisory Board As a Solution To Career Path Defining Business ...
Agency Managed Advisory Board As a Solution To Career Path Defining Business ...
Boris Ziegler
 
Building Your Employer Brand with Social Media
Building Your Employer Brand with Social MediaBuilding Your Employer Brand with Social Media
Building Your Employer Brand with Social Media
LuanWise
 
Premium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern BusinessesPremium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern Businesses
SynapseIndia
 
ikea_woodgreen_petscharity_cat-alogue_digital.pdf
ikea_woodgreen_petscharity_cat-alogue_digital.pdfikea_woodgreen_petscharity_cat-alogue_digital.pdf
ikea_woodgreen_petscharity_cat-alogue_digital.pdf
agatadrynko
 
amptalk_RecruitingDeck_english_2024.06.05
amptalk_RecruitingDeck_english_2024.06.05amptalk_RecruitingDeck_english_2024.06.05
amptalk_RecruitingDeck_english_2024.06.05
marketing317746
 

Recently uploaded (20)

Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)
 
3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx3.0 Project 2_ Developing My Brand Identity Kit.pptx
3.0 Project 2_ Developing My Brand Identity Kit.pptx
 
Understanding User Needs and Satisfying Them
Understanding User Needs and Satisfying ThemUnderstanding User Needs and Satisfying Them
Understanding User Needs and Satisfying Them
 
Project File Report BBA 6th semester.pdf
Project File Report BBA 6th semester.pdfProject File Report BBA 6th semester.pdf
Project File Report BBA 6th semester.pdf
 
Authentically Social by Corey Perlman - EO Puerto Rico
Authentically Social by Corey Perlman - EO Puerto RicoAuthentically Social by Corey Perlman - EO Puerto Rico
Authentically Social by Corey Perlman - EO Puerto Rico
 
LA HUG - Video Testimonials with Chynna Morgan - June 2024
LA HUG - Video Testimonials with Chynna Morgan - June 2024LA HUG - Video Testimonials with Chynna Morgan - June 2024
LA HUG - Video Testimonials with Chynna Morgan - June 2024
 
Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challengesEvent Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
Event Report - SAP Sapphire 2024 Orlando - lots of innovation and old challenges
 
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdfModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
 
Set off and carry forward of losses and assessment of individuals.pptx
Set off and carry forward of losses and assessment of individuals.pptxSet off and carry forward of losses and assessment of individuals.pptx
Set off and carry forward of losses and assessment of individuals.pptx
 
FINAL PRESENTATION.pptx12143241324134134
FINAL PRESENTATION.pptx12143241324134134FINAL PRESENTATION.pptx12143241324134134
FINAL PRESENTATION.pptx12143241324134134
 
The Influence of Marketing Strategy and Market Competition on Business Perfor...
The Influence of Marketing Strategy and Market Competition on Business Perfor...The Influence of Marketing Strategy and Market Competition on Business Perfor...
The Influence of Marketing Strategy and Market Competition on Business Perfor...
 
Recruiting in the Digital Age: A Social Media Masterclass
Recruiting in the Digital Age: A Social Media MasterclassRecruiting in the Digital Age: A Social Media Masterclass
Recruiting in the Digital Age: A Social Media Masterclass
 
Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...Discover the innovative and creative projects that highlight my journey throu...
Discover the innovative and creative projects that highlight my journey throu...
 
Auditing study material for b.com final year students
Auditing study material for b.com final year  studentsAuditing study material for b.com final year  students
Auditing study material for b.com final year students
 
In the Adani-Hindenburg case, what is SEBI investigating.pptx
In the Adani-Hindenburg case, what is SEBI investigating.pptxIn the Adani-Hindenburg case, what is SEBI investigating.pptx
In the Adani-Hindenburg case, what is SEBI investigating.pptx
 
Agency Managed Advisory Board As a Solution To Career Path Defining Business ...
Agency Managed Advisory Board As a Solution To Career Path Defining Business ...Agency Managed Advisory Board As a Solution To Career Path Defining Business ...
Agency Managed Advisory Board As a Solution To Career Path Defining Business ...
 
Building Your Employer Brand with Social Media
Building Your Employer Brand with Social MediaBuilding Your Employer Brand with Social Media
Building Your Employer Brand with Social Media
 
Premium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern BusinessesPremium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern Businesses
 
ikea_woodgreen_petscharity_cat-alogue_digital.pdf
ikea_woodgreen_petscharity_cat-alogue_digital.pdfikea_woodgreen_petscharity_cat-alogue_digital.pdf
ikea_woodgreen_petscharity_cat-alogue_digital.pdf
 
amptalk_RecruitingDeck_english_2024.06.05
amptalk_RecruitingDeck_english_2024.06.05amptalk_RecruitingDeck_english_2024.06.05
amptalk_RecruitingDeck_english_2024.06.05
 

The Start-Up’s Guide to Privacy - MaRS Best Practices

  • 1. The Start-up’s Guide to Privacy at MaRS: Legal Basics & Does Privacy Matter? Stephen Whitney Of Counsel Norton Rose Fulbright Canada LLP January 28, 2016
  • 2. 2 Agenda Privacy Legislation in Canada Comments on International Privacy Laws What To Know About Your Privacy Practices Does Privacy Matter?
  • 3. Privacy Legislation in Canada 3 A.  Federal Legislation •  PIPEDA - The Personal Information Protection and Electronic Documents Act PIPEDA applies across the country but for private companies that primarily operate in a single province, PIPEDA will not apply where the province has already enacted similar provisions to PIPEDA and the business fits within the scope of the provincial legislation.
  • 4. Recommended Reading: Privacy Toolkit A Guide for Businesses and Organizations Canada's Personal Information Protection and Electronic Documents Act https://www.priv.gc.ca/information/pub/guide_org_e.pdf 4 Recommended ReadingPrivacy Legislation in Canada
  • 5. PIPEDA and Digital Health 5 PIPEDA does not impose special obligations on digital health companies. Under s. 30(1.1), the Act states that the duties imposed on the use of personal information in the private sector: …does not apply to any organization in respect of personal health information that it collects, uses or discloses within a province … unless the organization … discloses the information outside the province … .
  • 6. Privacy Legislation in Canada 6 B. Some of the Provincial Legislation Includes: •  British Columbia (Personal Information Act); •  Alberta (Personal Information Protection Act); •  Quebec (An Act Respecting the Protection of Personal Information in the Private Sector); •  Ontario (Personal Health Information Protection Act); •  New Brunswick (Personal Health Information Privacy and Access Act); and •  Newfoundland and Labrador (Personal Health Information Act).
  • 7. Comments on International Privacy Laws 7 •  International privacy laws are often similar, but not identical. •  Typically based off of privacy principles. •  International privacy compliance is very challenging! •  The result is often a risk assessment of how to approach privacy. •  Do you have one approach globally or can you customize your approach for unique country requirements?
  • 8. Some important things to know about your privacy practices include: •  Sector •  Target audience •  Countries •  Business model •  Operational procedures 8 What To Know About Your Privacy Practices
  • 9. More specifically, for operational procedures it is important to know: •  What personal information and information does the company collect from the user of its products and services, website, apps, etc. and what is the context? •  Account and membership information? •  Unique identifiers? •  Information from children under 18 or under 13 years of age? •  Information about applications used on computer/device? •  Third party offerings (i.e. products, services, software, websites or content provided by a third party)? •  Cookies or similar technologies? 9 What To Know About Your Privacy Practices (cont)
  • 10. •  Financial information? •  Does the company process online payments? •  Are the payments processed by the company or a third party payment processor? •  What other financial information, if any, is collected? •  Does the company track the purchase history of customers? •  General usage data? •  Location information? •  Quality assurance and customer service? •  Health information? •  Other? 10 What To Know About Your Privacy Practices (cont)
  • 11. •  For what purposes does company use the personal information it collects? •  billing, activation, provision, maintenance, support, trouble shooting, resolving of disputes, deactivation, repair, refurbishment, replacement, upgrade or update of offerings •  to manage or respond to your inquiries •  to develop new and enhance existing offerings including to communicate with you about them using various means •  to manage and develop your business and operations •  to meet legal and regulatory requirements and to respond to emergency situations •  Does company use sales information? •  Do you send marketing communications (for example, emails)? 11 What To Know About Your Privacy Practices (cont)
  • 12. •  To whom does company disclose the personal information? •  Affiliates, Service Providers, Third Parties, Other? •  Do you send any of the personal information you collect to other countries? •  Data Retention •  Where stored? •  How long keep? •  When and how destroy? Make anonymous? •  Security •  Adequate protections implemented? •  Encryption used? At rest and in transit? 12 What To Know About Your Privacy Practices (cont)
  • 13. •  Do you obtain consent? When, where, how? If yes, what does the consent say? •  Consent by layers •  Terms and conditions •  Privacy policy •  Notices •  Reminders/Icons 13 What To Know About Your Privacy Practices (cont)
  • 14. Discussion based off of Prof. Michael Sandel’s keynote at IAPP • Uber • Connected Cars • Email Providers 14 Does Privacy Matter?
  • 15. Stephen Whitney Of Counsel Norton Rose Fulbright Canada LLP / S.E.N.C.R.L., s.r.l. 51 Breithaupt Street, Suite 100 Kitchener, Ontario N2H 5G5 Canada OR Royal Bank Plaza, South Tower, Suite 3800 200 Bay Street, P.O. Box 84, Toronto, ON M5J 2Z4 Canada T: +1 226.868.9125 stephen.whitney@nortonrosefulbright.com 15
  • 16.
  • 17. Disclaimer Norton Rose Fulbright LLP, Norton Rose Fulbright Australia, Norton Rose Fulbright Canada LLP, Norton Rose Fulbright South Africa (incorporated as Deneys Reitz Inc) and Fulbright & Jaworski LLP, each of which is a separate legal entity, are members (‘the Norton Rose Fulbright members’) of Norton Rose Fulbright Verein, a Swiss Verein. Norton Rose Fulbright Verein helps coordinate the activities of the Norton Rose Fulbright members but does not itself provide legal services to clients. References to ‘Norton Rose Fulbright’, ‘the law firm’, and ‘legal practice’ are to one or more of the Norton Rose Fulbright members or to one of their respective affiliates (together ‘Norton Rose Fulbright entity/entities’). No individual who is a member, partner, shareholder, director, employee or consultant of, in or to any Norton Rose Fulbright entity (whether or not such individual is described as a ‘partner’) accepts or assumes responsibility, or has any liability, to any person in respect of this communication. Any reference to a partner or director is to a member, employee or consultant with equivalent standing and qualifications of the relevant Norton Rose Fulbright entity. The purpose of this communication is to provide information as to developments in the law. It does not contain a full analysis of the law nor does it constitute an opinion of any Norton Rose Fulbright entity on the points of law discussed. You must take specific legal advice on any particular matter which concerns you. If you require any advice or further information, please speak to your usual contact at Norton Rose Fulbright. 17