CloudCompliance

Cloud data residency in Canada

PIPEDA does not require Canadian data to stay in Canada. Quebec's Law 25 requires an assessment before it leaves Quebec. Some public sector, health and contract terms require Canadian storage outright. Which one applies to you decides the architecture.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

For most Canadian private sector companies, data residency is a customer requirement, not a legal one. PIPEDA allows personal information to be processed outside Canada, provided you protect it contractually and tell people it may be. Quebec's Law 25 adds a privacy impact assessment before personal information is communicated outside Quebec. Federal Bill C-36, introduced on 15 June 2026 and at second reading, would add a comparable assessment for transfers outside Canada. Provincial public sector and health laws in some provinces go further.

Canadian rules that affect where cloud data can live
RuleApplies toWhat it requires
PIPEDAPrivate sector commercial activity, most provincesAccountability for data sent to processors, comparable protection by contract, openness about foreign processing. No storage requirement.
Quebec Law 25Personal information of people in QuebecPrivacy impact assessment before communicating it outside Quebec, and a written agreement with the recipient
Bill C-36 (proposed)Federal private sector, if enactedWould require assessing and mitigating risk before disclosing or transferring personal information outside Canada
BC FOIPPABC public bodies and their service providersStorage outside Canada allowed since 2021 amendments, subject to the public body's own rules and assessments
Nova Scotia PIIDPANova Scotia public bodies and service providersStorage and access inside Canada unless a listed exception applies
Health information lawsHealth custodians and their agents, by provinceVaries; many custodians require Canadian storage by policy or contract
Customer contractsWhoever signed themOften the strictest rule you have. Read the data location clause.

Bill C-36 is not law. The text as introduced is on the Parliament of Canada site, and details may change in committee. Plan for its direction, not its current wording. The privacy law detail is on GetAudited's data residency page; this page covers the cloud side.

What does data residency actually require in the cloud?

Customers who say "data must stay in Canada" usually mean three different things, and it is worth asking which.

Storage location
Data at rest in a Canadian region, including backups and replicas. A region choice and a location restriction policy satisfy this.
Processing location
Data not processed outside Canada, including by global services, analytics tools and AI APIs. This touches your SaaS stack, not just the cloud account.
Access location
No access from outside Canada, including your own staff abroad, offshore contractors and provider support. This is the hardest to meet and the one most often promised by accident.

How to build for residency

  1. Choose Canadian regions for everything that stores customer data, including backups, logs and analytics.
  2. Enforce the choice with an SCP on AWS, Allowed locations policy on Azure, or the resource location constraint on Google Cloud.
  3. Map your subprocessors. Error tracking, email delivery, support desks and AI APIs often run in the US. List each with its data location.
  4. Decide on keys. Customer-managed keys in a Canadian region add a control over who can decrypt, which some contracts ask for. The key management decider helps with that call.
  5. Write it down. A data flow diagram and a subprocessor list with locations answer the residency section of every questionnaire.

Law 25 and the cloud

If you hold personal information about people in Quebec and your cloud or any subprocessor stores or accesses it outside Quebec, including in Ontario, Law 25 section 17 requires a privacy impact assessment before the transfer, considering the sensitivity of the data, the purpose, the protection measures and the legal framework where it goes. A Canadian region in another province still counts as outside Quebec. Law 25 cloud transfers covers the assessment in detail.

Foreign legal access

Buyers sometimes ask whether a US-headquartered provider can be compelled to hand over data stored in Canada. It is a real question, not a reason to avoid AWS, Azure or Google Cloud. Providers publish transparency reports and commit to challenging requests. Customer-managed keys, and for the most sensitive workloads external key management, reduce what a provider could hand over. Answer the question honestly, with the controls you have, rather than claiming the risk is zero.

Does PIPEDA require data to be stored in Canada?

No. PIPEDA allows transfers to processors outside Canada as long as you remain accountable, protect the data by contract to a comparable standard, and are open with individuals that it may be processed abroad. Residency requirements come from Quebec law, some provincial public sector and health rules, and customer contracts.

If we use ca-central-1, are we compliant with Law 25?

Not automatically. ca-central-1 is in the Montreal area, so storage is in Quebec, but any access, support, analytics or subprocessor outside Quebec is still a communication outside Quebec that needs a privacy impact assessment and a written agreement.

What should we tell a customer who asks for Canadian data residency?

Say exactly what is true: which regions store their data, which subprocessors see it and where, whether any staff access it from outside Canada, and what contractual and technical controls apply. A precise answer closes the question faster than a blanket promise.

Not sure which rule applies to your data? The data residency checker answers it in five questions.

Need your residency position checked?

Firms in the network map data flows and write the privacy impact assessments.

Get matched