Law 25 and cloud transfers outside Quebec
Law 25 section 17 requires a privacy impact assessment before personal information about people in Quebec is communicated outside Quebec. Hosting in Ontario, a US SaaS tool and offshore support all count.
If your cloud stores or gives access to personal information about people in Quebec from anywhere outside Quebec, Law 25 requires you to assess the transfer first and put a written agreement in place with the recipient. The assessment weighs the sensitivity of the information, the purpose, the protection measures including contractual ones, and the legal framework where the information goes. The transfer may proceed if the assessment shows the information will receive adequate protection.
What counts as a communication outside Quebec?
- Storing data in any region outside Quebec, including Toronto or Calgary regions.
- A SaaS subprocessor in the United States or Europe: email delivery, error tracking, support desks, analytics.
- Staff or contractors outside Quebec with access to production data.
- Provider support accessing your data from abroad.
- Sending data to an AI API hosted outside Quebec.
AWS ca-central-1 and Google Cloud's Montreal region are in Quebec. Azure Canada East is in Quebec City. Hosting there keeps storage in Quebec, but the other items on the list still apply.
The transfer assessment
- Map what personal information goes where, to whom, and why.
- Rate its sensitivity. Health, financial and biometric information weigh heaviest.
- List the protections: encryption, access controls, the recipient's certifications, contract terms.
- Consider the legal framework in the destination, including privacy law and government access.
- Conclude whether protection is adequate, and record the decision with a date and owner.
- Sign a written agreement with the recipient covering the risks identified.
One assessment can cover a category of transfers, such as all US subprocessors of the same type, if the facts are the same. Keep it current when subprocessors change.
Cloud-specific protections that help
- Region choice
- Montreal-area and Quebec City regions where available, or Canadian regions as the next best.
- Encryption with keys you control
- Customer-managed keys limit what the provider or a foreign authority could read.
- Provider certifications
- ISO 27001, 27017, 27018 and SOC 2 reports evidence the recipient's protections.
- Data processing terms
- The provider's data protection addendum is the written agreement for your IaaS provider.
The privacy law side is covered on GetAudited's Law 25 guide.
Is storing data in Toronto a transfer outside Quebec?
Yes. For Law 25, outside Quebec includes the rest of Canada. Hosting Quebec residents' personal information in a Toronto region requires the same assessment as hosting it abroad, though the conclusion is usually straightforward.
Does Law 25 require data to stay in Quebec?
No. It requires an assessment and a written agreement before the information is communicated outside Quebec. If the assessment shows adequate protection, the transfer may proceed.
Need Law 25 transfer assessments done?
Firms in the network write them for cloud estates and subprocessor lists.
Get matched