LF logo
by learnformula
search
Log in
search
Courses/Technology, Privacy & Intellectual Property/Privacy & Data Protection

Privacy Compliance in 2026: Advising Your Small Businesses Clients

Navigate the evolving Canadian privacy landscape without overwhelming your small business clients.

Created byCanadian Bar Association
BeginnerUpdated Sep 26, 2026
Privacy Compliance in 2026: Advising Your Small Businesses Clients

What You'll Learn

check_circleAnalyze the applicability of federal and provincial privacy laws to small business operations
check_circleApply the 'real risk of significant harm' threshold to determine breach reporting obligations
check_circleEvaluate the legality of workplace surveillance and employee monitoring practices
check_circleDevelop practical governance frameworks for the responsible use of AI in business
check_circleImplement privacy-by-design principles when deploying new information systems

About This Course

Canadian privacy compliance is no longer optional, theoretical, or reserved for large organizations. Québec's Law 25 is now fully in force, enforcement activity is increasing across jurisdictions, and federal privacy reform remains active and dynamic — even as uncertainty continues around timing and final scope.

Small businesses are under growing pressure from regulators, customers, insurers, and commercial partners to demonstrate meaningful privacy governance. They are turning to their lawyers for clear, practical guidance.

Make sure you are equipped to confidently advise clients in a complex and evolving privacy landscape, without overwhelming small organizations.

Enhance your abilities to:

  • Translate current Canadian privacy obligations into clear, achievable steps using a practical compliance roadmap grounded in PIPEDA as currently in force, Québec's Law 25, and anticipated federal reform trends.
  • Deploy customizable client-readiness including privacy notices, consent language, retention schedules, breach-response checklists, and internal accountability documentation.
  • Identify early indicators of privacy risk in small organizations — before complaints, audits, or incidents arise.
  • Develop scalable, profitable privacy micro-services aligned with small-business realities rather than enterprise compliance models.

Your Instructors

Canadian Bar Association
Canadian Bar Association
menu_book34 courses
star260 reviews

The CBA is a professional organization that provides educational and networking opportunities for lawyers. Representing more than 36,000 lawyers, judges, notaries, law teachers, and law students from across Canada, the CBA is committed to enhancing the professional and commercial interests of a diverse membership and to protecting the independence of the judiciary and the Bar.

Olalekan (Wole)  Akinremi
Olalekan (Wole) Akinremi

Partner at WeirFoulds LLP

Wole's expertise spans an impressive range of technology and privacy law spheres. He provides invaluable guidance to clients on matters such as artificial intelligence, privacy compliance, robust data security measures, software integration, outsourcing strategies, cloud computing, and IP ownership. Wole's clients also rely on him to navigate the complexities of Software-as-a-Service (SaaS) agreements, Platform-as-a-Service (PaaS) agreements, Infrastructure-as-a-Service (IaaS) agreements, and licensing agreements with ease. Prior to joining WeirFoulds, Wole was a Partner at a boutique law firm that was heavily focused on Intellectual Property Law and Technology Law. At this firm, Wole served as a Co-Chair of the Technology Law Practice Group. Wole also has extensive in-house experience, as he has held roles as legal counsel at a Big Four professional services firm and two Fortune 500 companies. Beyond his legal practice, Wole frequently speaks on technology, artificial intelligence, and privacy law matters. Recently, Wole was a co-speaker at Osgoode Professional Development's National Forum on Artificial Intelligence, Ethics and the Law for Financial Services, where he spoke about the risks and mitigation strategies related to open source generative artificial intelligence. Wole is also the Director for the non-profit CLEO (Community Legal Education Ontario / Éducation juridique communautaire Ontario), a Certified Information Privacy Professional (CIPP/C) and is also a contributor for OneTrust's Data Guidance legal research platform.

Dany  Guimond-Valcourt
Dany Guimond-Valcourt

Lawyer at LCM Avocats Inc.

Ms. Guimond-Valcourt advises organizations on technology risk management, data governance, and regulatory compliance, including privacy protection and the negotiation of technology agreements. She also leverages her extensive experience to support the implementation of integrated security and governance strategies, as well as cybersecurity incident preparedness and response. As a Breach Coach, she coordinates legal and regulatory responses to data breaches and cyberattacks, guiding executive teams in strategic decision-making around resilience and compliance. Before joining LCM, Ms. Guimond-Valcourt held key positions in cybersecurity, governance, and risk management at major institutions such as Desjardins and the Caisse de dépôt et placement du Québec (La Caisse). At Desjardins, she contributed to strengthening corporate frameworks for resilience, compliance, and incident management, while at La Caisse, she supported portfolio companies in enhancing their cybersecurity and risk governance practices. A member of the Quebec Bar since 2009, Ms. Guimond-Valcourt holds academic credentials in law, management, and cybersecurity. She serves as a lecturer at Polytechnique Montréal, where she teaches in the Master's program in Computer and Software Engineering, focusing on laws, standards, and reference frameworks in data protection and cybersecurity, as well as organizational resilience, including incident response — courses she helped develop. She also teaches at Université de Sherbrooke, in the Graduate Diploma program (DESS) in Business Law and Enterprise Risk. As Chair of the Technology Integration Committee of the Barreau de Montréal, she leads initiatives aimed at promoting the responsible adoption of technology in legal practice and the administration of justice, thereby contributing to public protection and supporting lawyers as they adapt to the evolving digital landscape. She is also a frequent speaker at industry events, where she shares practical insights on technology law, cybersecurity, and information governance.

Ilana  Daulan
Ilana Daulan

Litigation Lawyer at LCM Avocats Inc.

Ilana Daulan is a civil and commercial litigation lawyer at the Montreal litigation boutique LCM Avocats Inc. She possesses specialized expertise in privacy law and data protection regulations. Current Role: Associate Attorney at LCM Avocats Inc. She originally joined the firm in 2024 as an articling student from the École du Barreau du Québec. Following the successful completion of her articling period, she was officially sworn in and welcomed as a full litigation associate in March 2025. Credentials: She holds the prestigious CIPP/C (Certified Information Privacy Professional/Canada) designation issued by the International Association of Privacy Professionals (IAPP). This certification verifies her mastery of Canadian federal, provincial, and territorial privacy laws, making her highly skilled in navigating modern regulatory compliance and data protection frameworks. Dual-Trained Jurisdiction: She is uniquely dual-trained across the legal systems of both Canada and France. Corporate Experience: Before practicing at LCM Avocats, she gained critical corporate and technology-sector experience working with major multinational tech companies, including Salesforce and eBay.

Kris  Klein
Kris Klein

Founding Partner at nNovation LLP

Kris Klein, CIPP/C, CIPM, FIP and Westin Fellow, has more than two and a half decades of public and private sector experience in the federal regulatory arena in Canada, and is one of Canada's leading advisors on privacy, data and AI governance, information security and access to information. Prior to starting Canada's first boutique law firm that specialized in this industry, Kris litigated and counseled extensively on federal regulatory law with a pre-eminent national firm, and, subsequently, for Canada's Department of Justice. Before leaving public service, he advised the Privacy Commissioner of Canada. In that role, Kris counseled on legal, policy and strategic issues, including on the handling of high-profile and sensitive cases. He negotiated and settled complaints with private and public sector organizations facing scrutiny over privacy compliance issues. Kris also represented the Commissioner and her office publicly before Parliamentary committees, as a conference speaker, and before the media.

Rachel  E. Schechter
Rachel E. Schechter

Lawyer at Roper Greyell LLP

Rachel Schechter, CIPP/C, CIPM, FIP, practices in all areas of workplace law, with a strong emphasis on privacy, data governance, cybersecurity, access to information, artificial intelligence, and related grievances and disputes. Rachel is recognized in Best Lawyers in Canada for her work in Privacy and Data Security Law, is a Certified Information Privacy Professional (Canada), a Certified Information Privacy Manager, and is recognized as a Fellow of Information Privacy. Rachel practices in all areas of privacy and data governance. She advises public and private sector clients on compliance, policy development, access requests, cyber incident preparedness, and impact assessments, including as related to novel products and technologies, such as AI, biometrics, and surveillance. Rachel acts in inquiries before the OIPC, and in related judicial reviews. She acts as breach counsel for clients experiencing cybersecurity attacks, helping manage risk, forensic investigations, and notification and reporting. Rachel is a talented labour lawyer, assisting unionized employers as counsel in arbitration and board work, collective bargaining, and strategic planning. She draws on varied dispute resolution experience, having appeared before all levels of court in British Columbia, the Federal Court, and federal and provincial labour boards. Rachel is Chair of the CBABC Women Lawyers Forum, and Past Chair of the Freedom of Information and Privacy Section Executive. She co-authored the book Personal Information Protection Act, British Columbia and Alberta: Quick Reference, published by Thomson Reuters in 2026. Outside of law, Rachel is a wine and concert enthusiast, and can be found hosting dinners, antiquing, or spending time with her husband and dogs.

Erin  Hardy
Erin Hardy

General Counsel and Chief Privacy Officer, General Counsel and Privacy (Division), Service New Brunswick

Erin Hardy is the General Counsel, Corporate Secretary, and Chief Privacy Officer for Service New Brunswick, a Crown corporation based in Fredericton, New Brunswick, Canada. In this role, she oversees regulatory compliance, access to information, corporate governance, and privacy practices for the organization. Erin brings over 17 years of legal experience spanning both private practice and the public sector across New Brunswick and Nova Scotia. Before joining the civil service, she spent a decade as a corporate commercial lawyer at a large regional law firm, building a strong foundation in corporate and commercial law. She has served with Service New Brunswick since September 2016, having previously held the position of Associate General Counsel before assuming her current role as Chief Privacy Officer. She holds a Bachelor of Science (B.Sc.) and a Bachelor of Laws (LL.B.), along with a Certificate in Information Access and Protection of Privacy (CIAPP), reflecting her specialized expertise in privacy and information law. Beyond her role at Service New Brunswick, Erin is active in the broader legal and privacy community. She serves as Section Chair for Privacy Law with the Canadian Bar Association in New Brunswick (CBANB) and is a Director on the board of the Digital ID & Authentication Council of Canada (DIACC), contributing to national conversations on digital identity and authentication standards.

Credit Information

Professional development requirements vary by profession, country, and regulatory body. Before enrolling, review the course details and confirm that the content, learning format, and any listed credits meet your specific requirements. You are responsible for confirming eligibility with your regulator or professional association and keeping the records required for reporting.

What Students Are Saying

0.0
Student's Choice
0 reviews

Frequently Asked Questions

We are a registered provider with 327+ associations and regulatory bodies worldwide. We operate across 29 global markets including Canada, the US, Australia, and the UK. Every course page clearly displays its specific accreditations. Upon completion, you receive a professional certificate that can be validated online. Our certificates include all necessary accreditation details, credit hours, and completion dates, and are formatted specifically to meet the submission requirements of most global regulatory bodies.

You May Also Like

Accounting & Tax: Technology for Accountants

Claude Fundamentals for Accountants (2026 Update)

star5.0(401)
2.5 CPD hrs
Audit & Assurance: Fraud

The Dark Triad and Fraud: Behavioural Red Flags Before Financial Misconduct

star5.0(1)
1.5 CPD hrs
Public, Regulatory & International Law: Constitutional & Civil Rights

Encounters with Aboriginal Law and Indigenous Law in the Current Canadian Landscape

1 CPD hr