Flag of Canada

In this episode, Shir Fulga (Toronto) and Erin Schachter (Montréal) (Toronto) discuss recent Quebec and Ontario court decisions certifying consumer class actions in data breach cases—and what these rulings mean for employers handling employee data. The discussion covers how courts are lowering the threshold for claims, allowing actions based on moral damages even in the absence of proven financial harm, and applying multiple legal frameworks, including privacy statutes, consumer protection laws, and human rights legislation.

Transcript

Announcer: Welcome to the Ogletree Deakins podcast, where we provide listeners with brief discussions about important workplace legal issues. Our podcasts are for informational purposes only and should not be construed as legal advice. You can subscribe through your favorite podcast service. Please consider rating this podcast so we can get your feedback and improve our programs. Please enjoy the podcast.

Shir Fulga: Hi everyone. Welcome to our Ogletree Deakins Canada podcast series. In this podcast series, we bring our blog articles to life for listeners on the go.

Erin Schachter: In this series, we will guide you through the latest developments in Canadian employment and privacy law, breaking down complex legal topics into accessible, practical, and easy to understand conversations.

Shir Fulga: My name is Shir Fulga. I’m a lawyer in our Toronto office.

Erin Schachter: And I’m Erin Schachter in our Montreal office. We will be your host, so settle in and let’s get started.

Shir Fulga: Hi everyone. So, today we are diving into a development in Canadian privacy law that employers really shouldn’t ignore. Recent decisions from the Superior Court of Quebec and the Ontario Superior Court of Justice have certified consumer class actions and data breaches cases, and many are calling this the start of a new era in privacy litigation. While these cases focus on consumers, the reasoning has real implications for employers handling employee data. To help us unpack this, I’m joined by my co-host, Erin. So, thanks, Erin, for being here.

Erin Schachter: Thank you for having me. Fun to wear the hat of guest instead of host, and definitely an area where employers should be watching closely.

Shir Fulga: Let’s start by why this matters to employers. So, at a first glance, these, again, as we said, really look like consumer cases. So, why should employers care?

Erin Schachter: So, it really is one of the key questions. And even though in this case, the plaintiffs were consumers, the court’s reasoning applies much more broadly. For example, in Quebec, the court authorized a class action even though there was no confirmed identity thought or losses at the time. And that does tell us something important. Plaintiffs don’t necessarily need a proven financial harm for these certifications to move forward. So, for employers, that means if employee data is compromised, the risk of litigation may arise even if there’s no concrete losses or damages established.

Shir Fulga: So, the mere fact that data has been exposed combined with alleged stress or inconvenience, those could be enough to bring a claim forward?

Erin Schachter: Yes. And again, we’re at the certification class, which is a different scenario than a trial going forward. But at this stage in the proceeding, the court accepted that so-called moral damages, including distress beyond routine monitoring, could justify proceeding. And so, this is a lower threshold than what we have been seeing in data privacy. It’s something that has been coming up in other jurisdictions, but for Canada, this is a new approach.

Shir Fulga: And really one thing that stood out to me is that the Quebec court didn’t just rely on privacy legislation. It referenced other statutes too, right?

Erin Schachter: Yes. So, that’s one of the more significant developments. So, the court acknowledged potential liability under quite a few statutes. So, in Quebec, we had the Consumer Protection Act, the Charter of Human Rights and Freedom, and then the Quebec Private Sector Privacy Statute. And then in the Ontario case, we had consumer reporting laws that came into play. And we also know in Ontario, there are torts that are possible for data privacy breaches if it starts to enter into an area where it’s an unreasonable invasion of privacy.

So, we have this broader view that started to come into play. And for employers, this layered exposure is critical because a data breach could potentially trigger claims framed as privacy violations. And then it could also be misleading practices, human right infringements like in Quebec, the right to privacy under the Quebec Charter of Human Rights and Freedoms. And so, we see that even if, such as in Ontario, we don’t have a private sector privacy statute as we do in Quebec, other elements are starting to come into play and be considered by the courts.

Shir Fulga: Interesting. And on top of these kinds of statutory damages, we’re also looking at punitive damages. Is that right?

Erin Schachter: Yes. And this specifically in Quebec is important, especially for employers, because under the private sector privacy law, which would be applicable to employers, if a violation is intentional or the result of gross negligence, punitive damages may be awarded. And there’s even a statutory minimum of $1,000. And when we’re thinking about that in the context of a class action breach, that can be quite substantial.

And so, if we think about our workforce and the employees and the number and the risk of punitive damages, that raises the stakes. If there’s a serious lapse in data governance or misleading communications, and this falls under that threshold of gross negligence, then yes, punitive damages can be awarded. And then on top of that financial risk, it’s also reputational exposure.

Shir Fulga: Of course. Yeah. One of the things that both courts seem to emphasize is the contractual angle. So, contractual obligations, even in things like loyalty programs, right? So, why is that important for employers?

Erin Schachter: Yes. So, this is very interesting because it suggests that courts are willing to treat representations about data protection as enforceable commitments. Now, the context, again, it is quite different. It’s a consumer relationship. There was loyalty programs, but with these loyalty programs, you had representations that were made, but the court was willing to treat this as enforceable. And the thing that I think we do need to consider is that employers often are making statements to employees about what they’re doing with their data in things such as a privacy policy or privacy notice.

And I do think that employers may want to think about what language they’ve used to inform employees about what’s happening with their data. Example is safeguards in place and where data is stored. Because there is a potential that later down the line, if something occurs, this could be analyzed and dissected by the courts. And if there’s claims of misrepresentation, it’s a leap from a contract, but it’s not so far down the line that courts wouldn’t look at what languages did employers use when discussing with employees, and was this accurate?

So, I definitely think it’s something we want to have top in mind and take some inspiration from these cases to consider what we’ve been telling people.

Shir Fulga: Right. So, it really isn’t just about complying with a privacy statute. It’s also about making sure that the employer’s written policies are accurate.

Erin Schachter: I think so. And I think just as a general practice, it’s really good to take a look at onboarding material and documents and privacy notice on a frequent basis. I think this is something where it needs to be revisited, and it needs to be revisited frequently because often we’re making upgrades to the technology systems we’re using to process employee data. We’re making changes to where data is stored. And we just want to keep having that dialogue open so that there’s no disconnect between what’s said, what’s promised, what’s stated, and what’s being done in real practice.

So, I think having those communication channels open between different teams, making sure that there’s things in place so that we’re really reflecting actual practices in those policies is going to be a good idea.

Shir Fulga: Yeah, that makes sense. And we always tell our clients that employment agreements should be reviewed frequently for a whole host of employment-related reasons, but it sounds like taking on the privacy angle as well is really important, especially in light of those new cases. Another interesting part of the Quebec decision was the focus on communication strategy, even social media posts and hotlines, right?

Erin Schachter: Yes. And so, the court noted that there was allegations that the organization had advertised a call center that wasn’t really responsive, and it wasn’t really able to deliver the way that it had been promised. And this is something that’s important as well because this could easily come into play with employees if there was a data breach, where if we tell employees, call this number for support and that’s not a resource that’s properly staffed or functional in this case, they pointed to that as misrepresentation. And that is quite critical.

Shir Fulga: Interesting. Yeah. So, that’s really kind of going back to the difference between what’s being promised and what’s happening in reality can in itself create legal exposure.

Erin Schachter: Yes, exactly. And even to continue down that line, the wording of the data breach notices, which is something you would also share with employees if there was a data breach and employee data was involved, is you’re going to be required under the applicable laws to explain to them what type of data was involved. And in this instance, we had allegations that there had been a downplay of the scope of the breach, and there was information such as what information was available on the dark web, which is a section of the internet that’s not normally available, but often where there’s transactions around stolen data.

The information provided around what data was on the dark web was not really completely revealed in these notices. And that’s something that the court looks at closely. So, when we’re doing any type of communication related to a breach notice, we need to make sure that everybody’s on board legal, HR communications. There needs to be plans in place because if there lacks alignment on this notice and the notice goes out, this can create legal exposure.

Shir Fulga: Kind of putting everything together, what are some ideas of steps that employers can take now?

Erin Schachter: So, it’s really every organization’s going to need to work on making sure that they are compliant with the applicable law in their jurisdiction. There’s variations that can come into play. And so, it’s always good to make sure that they’ve taken the time to really look at what’s applicable to them and put things in place that are legally compliant. But some broad lines that might be helpful to consider is auditing contractual commitments. So, we were discussing reviewing policies, documents that contain data-related representations, and having a schedule in place to make sure that those are reviewed periodically so that they’re accurate.

Strengthen incident response protocols. So, if there needs to be escalation procedures, making sure that the people responsible for drafting any notice that will go out is clearly assigned to that job, that it’s legally vetted, and communications are limited to those that have been identified with that role. We want to consider third, evaluating support infrastructure. So, if there’s going to be a hotline in place, employee assistance, if we’re going to be advertising something that’s offered, make sure that organization or third party or whatever resources assigned is actually going to be able to work the way that it’s been advertised.

And then another thing that can be considered is to look across multiple legal regimes, especially in Quebec and in Ontario as well, is what type of laws might come into effect that could cover this data. Looking at things like insurance coverage, are punitive damages covered by the insurance, taking that into consideration when assessing insurers and risk, and just really making sure that we come up with a plan that will be taking into consideration this multi-legal regime that the courts have emphasized can possibly come into play.

Shir Fulga: Wow. So, this is really multidisciplinary. We’re used to maybe in the past think about privacy as merely a compliance issue, but it really seems like we’re moving away from that, and privacy is really not a siloed issue anymore. Is that right?

Erin Schachter: Yeah, I think that’s what makes these decisions so interesting is they came out in 2025, fairly recently. But in it we see this real rolling into one of all different elements like governance, communications, contractual risk, human rights, exposure on just many fronts. And we’re seeing that the expectations around privacy are that this is really integrated into big decisions that the company is making at many steps.

Shir Fulga: Yeah. Well, it certainly sounds like Canadian courts are signaling a more expansive approach to privacy-related class actions. And for employers, I guess that means the handling of employee data and especially the response to a breach really deserves kind of a broad-level, all-encompassing attention. So, thank you so much for joining us today, Erin. That was really, really interesting and informative.

Erin Schachter: Thank you. It was my pleasure.

 

Announcer: Thank you for joining us on the Ogletree Deakins podcast. You can subscribe to our podcast on Apple Podcasts or through your favorite podcast service. Please consider rating and reviewing so that we may continue to provide the content that covers your needs. And remember, the information in this podcast is for informational purposes only and is not to be construed as legal advice.

Share Podcast


Modern dark data center, all objects in the scene are 3D
Practice Group

Cybersecurity and Privacy

The attorneys in the Cybersecurity and Privacy Practice Group at Ogletree Deakins understand that data now accumulates quickly, transmits easily, and—increasingly—is processed by artificial intelligence (AI) systems that introduce new dimensions of legal risk. 

Learn more
four businesspeople with suitcases walking across a concrete plaza
Practice Group

Class Action

Our class action lawyers are veterans. We have decades of experience handling numerous types of federal and state law class and collective actions, such as those arising under Title VII, the Age Discrimination in Employment Act, the Employee Retirement Income Security Act, and the Fair Labor Standards Act.

Learn more
Glass globe representing international business and trade
Practice Group

Cross-Border

Often, a company’s employment issues are not isolated to one state, country, or region of the world. Our Cross-Border Practice Group helps clients with matters worldwide—whether involving a single non-U.S. jurisdiction or many more. 

Learn more

Sign up to receive emails about new developments and upcoming programs.

Sign Up Now