Canada
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Canada lets data leave the country. There is no approved-country list and no banned-country list. You stay responsible for the data wherever it goes, and you must tell people it may be handled abroad. The catch is that Canada is really ten jurisdictions at once, and several of them add hard storage rules on top of the national one.
Eight questions about Canada
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Canada's rules apply to my company?
Yes. Canada's national privacy law reaches a foreign company with no office here if it handles personal information about people in Canada as part of doing business. There is no revenue or headcount threshold that lets you out. You do not normally need a local representative, but payment companies are an exception: a payment firm based abroad that aims its service at people in Canada must register with the central bank and name an agent inside Canada to receive official notices.
The Personal Information Protection and Electronic Documents Act (PIPEDA) applies to private-sector organisations that collect, use or disclose personal information in the course of commercial activity. The Privacy Commissioner's own summary states it covers 'all businesses that operate in Canada and handle personal information that crosses provincial or national borders in the course of commercial activities'. Three provinces are carved out for purely intra-provincial activity because their own laws were declared substantially similar: Quebec, Alberta and British Columbia. Federal works and undertakings (banks, airlines, telecoms, inter-provincial transport) stay under PIPEDA everywhere, including in those three provinces. Under the Retail Payment Activities Act, a foreign payment service provider that performs retail payment activities for an end user in Canada and directs those activities at people or entities in Canada must register with the Bank of Canada; if it has no office here it 'must identify the name and address of an agent or mandatary within Canada'. Quebec requires every business to have a named person in charge of protecting personal information, whose title and contact details must be published; that person defaults to the most senior executive but need not sit in Quebec.
Sources
- Official sourceOffice of the Privacy Commissioner of CanadaPIPEDA requirements in brief — who the law applies to
priv.gc.ca
“all businesses that operate in Canada and handle personal information that crosses provincial or national borders in the course of commercial activities are subject to PIPEDA”
Link checked 18 August 2026
- Official sourceBank of CanadaFrequently asked questions about retail payments supervision — registration of foreign payment service providers
bankofcanada.ca
“must identify the name and address of an agent or mandatary within Canada”
Link checked 18 August 2026
Can I store my users' data outside Canada?
In general, yes, and with no government permission. Canada's national law does not restrict where personal data is stored or processed. But the headline is wrong for at least six groups. Quebec makes you do a written risk assessment first — and that applies even to sending data to Ontario. Nova Scotia public bodies and their suppliers must keep the data in Canada. Federal government data rated Protected B or higher must sit in Canada. Banks must keep a full copy of their records on servers in Canada. And under the new cyber security law, records about critical systems must be kept in Canada.
Rated sectoral Sector-by-sector picture as at 18 August 2026: - All industries, national layer: OPEN. PIPEDA has no localisation rule, no approved-destination list and no prohibited-destination list. The Privacy Commissioner states plainly that 'PIPEDA does not prohibit organizations in Canada from transferring personal information to an organization in another jurisdiction for processing.' - Anyone handling data about people in Quebec: CONDITIONAL. Since September 2023, before personal information is communicated outside Quebec a business must carry out a privacy impact assessment, and may proceed only if that assessment shows the information would get adequate protection. It must also be covered by a written agreement. Note the geography: the trigger is 'outside Quebec', so a Montreal company using a Toronto data centre is caught. - Nova Scotia public sector and its private suppliers: CLOSED. Personal information held by public bodies and municipalities 'must remain in Canada, be accessed, and disclosed only in Canada' unless a narrow exception applies. This binds contracted service providers, not just the public body. - Federal government data: CLOSED for sensitive categories. All Protected B, Protected C and Classified government electronic data must be stored in a government-approved computing facility inside Canada (or on Canadian government premises abroad). - Federally regulated banks and insurers: MIRROR. OSFI's third-party risk guideline requires that complete copies of the statutory Records be kept on computer servers physically located in Canada, updated and accurate as at the end of each business day. Certain exempt institutions may hold records abroad only if OSFI gets immediate, direct, complete and ongoing access. Separately, the Superintendent can order a bank to stop keeping copies abroad, or to keep copies at a place in Canada. - Critical cyber systems in banking, telecoms, energy and transport: MIRROR. The Critical Cyber Systems Protection Act, in force since June 2026, says records a designated operator must keep 'must be kept in Canada'. - Health: OPEN in Ontario. The Ontario privacy regulator says directly that its health privacy law 'does not require that personal health information be retained and stored in Ontario or Canada'. This corrects a very common myth. Other provinces differ and Nova Scotia's health authorities are caught by that province's Canada-only rule. - Payments: OPEN on storage. The Retail Payment Activities Act imposes registration, safeguarding and incident reporting, but we found no requirement that payment data or safeguarded funds sit in Canada. - British Columbia public sector: CONDITIONAL and unsettled. The old rule requiring storage only in Canada was removed in 2021. What remains is a power: a public body 'may disclose personal information outside of Canada only if the disclosure is in accordance with the regulations, if any, made by the minister'. - Mapping and geospatial data: no restriction found, checked 18 August 2026, confidence medium.
Sources
- Official sourceOffice of the Privacy Commissioner of CanadaGuidelines for processing personal data across borders
priv.gc.ca
“PIPEDA does not prohibit organizations in Canada from transferring personal information to an organization in another jurisdiction for processing.”
Link checked 18 August 2026
- Official sourceCommission d'accès à l'information du QuébecCommunication de renseignements personnels hors Québec
cai.gouv.qc.ca
“avant de communiquer un renseignement personnel à l'extérieur du Québec, une organisation doit procéder à une évaluation des facteurs relatifs à la vie privée”
Link checked 18 August 2026
- Official sourceNova Scotia Department of JusticePersonal Information International Disclosure Protection Act — frequently asked questions
novascotia.ca
“Personal information held by public bodies and municipalities must remain in Canada, be accessed, and disclosed only in Canada, unless certain circumstances exist.”
Link checked 18 August 2026
- Official sourceTreasury Board of Canada SecretariatDirection for Electronic Data Residency
canada.ca
“All sensitive electronic data under government control, that has been categorized as Protected B, Protected C or is Classified, will be stored in a GC-approved computing facility located within the geographic boundaries of Canada or within the premises of a GC department located abroad.”
Link checked 18 August 2026
- Official sourceOffice of the Superintendent of Financial InstitutionsGuideline B-10, Third-Party Risk Management — records and data location
osfi-bsif.gc.ca
“complete copies must be kept on a computer server(s) physically located at the places stipulated in the FRFI Statutes”
Link checked 18 August 2026
- Official sourceInformation and Privacy Commissioner of OntarioFrequently Asked Questions: Personal Health Information Protection Act
ipc.on.ca
“PHIPA does not require that personal health information be retained and stored in Ontario or Canada.”
Link checked 18 August 2026
- Official sourceKing's Printer, British ColumbiaFreedom of Information and Protection of Privacy Act (British Columbia), section 33.1
bclaws.gov.bc.ca
“A public body may disclose personal information outside of Canada only if the disclosure is in accordance with the regulations, if any, made by the minister.”
Link checked 18 August 2026
What do I need in place before data leaves Canada?
At the national level there is no list at all — no approved countries, no banned countries, no government form to file. What you must do instead is stay accountable: put a contract or similar protection in place with whoever handles the data for you, and tell people plainly that their information may be processed in another country and could be seen by foreign courts, police or security agencies. Quebec is different and stricter: there you must complete a written privacy risk assessment before the data moves, and sign a written agreement.
Model at the national layer is dg:xmodel:unrestricted. Because there is no list, the question 'is the list populated?' does not arise federally — and that is itself the risk picture: nothing to check, nothing to watch, and nothing stopping a future government from creating one. The Privacy Commissioner's cross-border guidance sets out three duties. First, accountability: 'The organization shall use contractual or other means to provide a comparable level of protection while the information is being processed by the third party.' Second, transparency: organisations must advise individuals that their information 'may be sent to another jurisdiction for processing and that while the information is in another jurisdiction it may be accessed by the courts, law enforcement and national security authorities'. Third, a hard limit the guidance is explicit about: no contract can override the criminal, national security or other laws of the destination country. In Quebec the model is closer to a self-assessed adequacy test: a privacy impact assessment proportionate to the sensitivity, purpose, volume, distribution and format of the information, and the transfer may proceed only if it shows the information would receive adequate protection, backed by a written agreement.
Sources
- Official sourceOffice of the Privacy Commissioner of CanadaGuidelines for processing personal data across borders — accountability and transparency
priv.gc.ca
“may be sent to another jurisdiction for processing and that while the information is in another jurisdiction it may be accessed by the courts, law enforcement and national security authorities”
Link checked 18 August 2026
- Official sourceCommission d'accès à l'information du QuébecCommunication de renseignements personnels hors Québec — assessment and written agreement
cai.gouv.qc.ca
“La communication peut être effectuée si l'évaluation démontre que le renseignement bénéficierait d'une protection adéquate. Elle doit faire l'objet d'une entente écrite”
Link checked 18 August 2026
Who enforces the rules in Canada, and what can they do?
Canada has many regulators and they are all real, staffed and issuing decisions. The national one, the Privacy Commissioner of Canada, published findings against OpenAI, X, Bell and WestJet in the first half of 2026 alone. But it cannot fine anyone — it makes findings and recommendations, and a case has to go to the Federal Court for money. Quebec's regulator can fine, and has blocked a national grocery chain from switching on a face-recognition system. Banking, payments and cyber security each have their own separate supervisor.
Rated actively enforced, not aggressive: high activity, real investigations, but the flagship national regulator has no direct fining power. Office of the Privacy Commissioner of Canada — fully operational. Its 2025-26 annual report, published 4 June 2026, records 3,044 PIPEDA complaints received (up 109% year on year), 3,146 Privacy Act complaints (up 62%), nearly 700 private-sector breach reports affecting more than 20 million Canadians, and around 450 federal institution breach reports. Published 2026 findings include a joint investigation into OpenAI (May 2026), commissioner-initiated complaints against X Corp. and X.AI (June 2026), Bell (June 2026), a WestJet compliance letter (July 2026) and Loblaw's PC Optimum loyalty programme (March 2026). It has no administrative monetary penalty power under PIPEDA. Commission d'accès à l'information du Québec — operational and using its new powers. In February 2025 it prohibited Metro Inc. from bringing a biometric database into service. It participated in the joint OpenAI investigation concluded May 2026. It can impose administrative monetary penalties of up to the greater of 2% of worldwide turnover or C$10 million (about US$7.3 million), and penal proceedings can reach the greater of 4% of worldwide turnover or C$25 million (about US$18 million), doubled for repeat offences. Office of the Superintendent of Financial Institutions — operational, supervises banks and insurers, sets the records-in-Canada expectation. Bank of Canada — operational as the retail payments supervisor since 2024-25; registration became compulsory on 8 September 2025 and it publishes enforcement decisions. Communications Security Establishment and the sector regulators named in the Critical Cyber Systems Protection Act — the reporting pipe is legislated but not yet switched on, because the designation and reporting regulations are still to be made. Provincial commissioners in Alberta, British Columbia and Ontario are all operational and publish orders.
Sources
- Official sourceOffice of the Privacy Commissioner of CanadaNews release: Privacy Commissioner of Canada's 2025-2026 annual report
priv.gc.ca
“3,044 PIPEDA complaints received, representing a 109% increase”
Link checked 18 August 2026
- Official sourceOffice of the Privacy Commissioner of CanadaInvestigations into businesses — 2026 findings list
priv.gc.ca
Link checked 18 August 2026
- Official sourceCommission d'accès à l'information du QuébecActualités — Commission d'accès à l'information (Metro biometric prohibition, February 2025; OpenAI joint investigation, May 2026)
cai.gouv.qc.ca
Link checked 18 August 2026
- Official sourceCommission d'accès à l'information du QuébecSanctions applicables aux entreprises privées
cai.gouv.qc.ca
Link checked 18 August 2026
How long do I have to keep the data?
The floor and the ceiling pull in opposite directions. Tax law says keep your business records for six years after the tax year they relate to, and keep them at a place of business in Canada unless the tax authority agrees to somewhere else. Privacy law says the opposite: delete personal information once the reason you collected it has gone. Where the two clash, the duty to keep wins — but only for the specific records the law names, and only for as long as it names.
FLOOR. Income Tax Act section 230 requires records and books of account to be kept 'at the person's place of business or residence in Canada or at such other place as may [be] designated by the Minister', and retained 'until the expiration of six years from the end of the last taxation year to which the records and books of account relate'. Electronic records must be kept in an electronically readable format for that period. Under PIPEDA an organisation must keep a record of every breach of security safeguards for two years, whether or not it was reportable. Registered payment service providers must file an annual report to the Bank of Canada by 31 March covering the previous calendar year, which presupposes retaining the underlying operational and incident data. Designated operators under the Critical Cyber Systems Protection Act must keep prescribed records in Canada, for a period their regulator sets. Federally regulated banks must keep complete copies of statutory Records on servers in Canada, updated as at the end of each business day. CEILING. PIPEDA's limiting-use principle requires personal information to be retained only as long as necessary to fulfil the identified purposes, and destroyed, erased or made anonymous once no longer required. Quebec goes further and adds an enforceable destruction-or-anonymisation duty once the purpose is achieved. CONFLICT. Canada resolves this the ordinary way: a specific statutory retention duty overrides the general privacy duty to delete, for those records and that period only. It does not licence keeping everything else.
Sources
- Official sourceDepartment of Justice CanadaIncome Tax Act, section 230 — records and books of account
laws-lois.justice.gc.ca
“until the expiration of six years from the end of the last taxation year to which the records and books of account relate”
Link checked 18 August 2026
- Official sourceOffice of the Privacy Commissioner of CanadaWhat you need to know about mandatory reporting of breaches of security safeguards
priv.gc.ca
“you keep breach records of all breaches of security safeguards for two years”
Link checked 18 August 2026
- Official sourceBank of CanadaReminder: PSP reporting obligations under the Retail Payment Activities Act
bankofcanada.ca
Link checked 18 August 2026
What happens if there is a breach?
Count at least four clocks and they do not agree. The national privacy law gives no fixed number of hours — you report 'as soon as feasible', which in practice means days, not weeks. Payment firms get 48 hours to tell the central bank about a serious incident. Critical infrastructure operators will get no more than 72 hours to tell the national cyber agency, then must tell their own regulator immediately after. Health and provincial rules add more. The overlap is where people get caught: one incident, several reports, several deadlines.
CLOCK 1 — PIPEDA (all commercial organisations). Report to the Privacy Commissioner and notify affected individuals 'as soon as feasible' after determining that a breach of security safeguards creates a real risk of significant harm. No hour count is specified. Keep a record of every breach for 24 months. Knowingly failing to report, notify or keep records is an offence. CLOCK 2 — Retail Payment Activities Act (registered payment service providers). Notify the Bank of Canada and affected individuals or entities 'without delay but no later than 48 hours' after determining an incident is material. Initial, interim and final notices may all be required. Separate rule: at least five business days' advance notice before significant operational changes. CLOCK 3 — Critical Cyber Systems Protection Act (designated operators in banking, telecoms, energy and transport). Report a cyber security incident to the Communications Security Establishment 'within a period prescribed by the regulations, not to exceed 72 hours', and 'immediately after reporting' notify the appropriate sector regulator. This clock is legislated but does not start running until the regulations and designation orders are made. CLOCK 4 — Quebec. Confidentiality incidents presenting a risk of serious injury must be reported to the Commission and to the people affected with diligence, and a register of incidents kept. CLOCK 5 — provincial health. Alberta's Health Information Act requires custodians to notify affected individuals, the Information and Privacy Commissioner and the Minister of Health 'as soon as practicable' where there is a risk of harm. Ontario requires notification at the first reasonable opportunity, and an agent must tell its custodian at the first reasonable opportunity. The practical failure mode in Canada is not missing a single deadline. It is a payments or infrastructure firm treating the privacy report as the only report.
Sources
- Official sourceOffice of the Privacy Commissioner of CanadaMandatory reporting of breaches of security safeguards under PIPEDA
priv.gc.ca
“report to the OPC any privacy breaches that pose a real risk of significant harm to an individual”
Link checked 18 August 2026
- Official sourceBank of CanadaReminder: PSP reporting obligations under the RPAA — 48-hour incident notice
bankofcanada.ca
“without delay but no later than 48 hours”
Link checked 18 August 2026
- Official sourceParliament of CanadaCritical Cyber Systems Protection Act (Bill C-8, as assented to) — incident reporting
parl.ca
“within a period prescribed by the regulations, not to exceed 72 hours”
Link checked 18 August 2026
- Official sourceGovernment of AlbertaHealth Information Act — breach notification duties
alberta.ca
“as soon as practicable”
Link checked 18 August 2026
What trips people up in Canada?
Five things that are not in any summary. Quebec's cross-border rule catches you sending data to Ontario, not just abroad. Quebec also makes you tell its regulator 60 days before you switch on any face or fingerprint system, and it has already blocked a big grocery chain from doing so. British Columbia repealed its keep-it-in-Canada rule in 2021, so trackers that still show it are wrong. Nova Scotia's Canada-only rule reaches private suppliers, with fines up to half a million dollars. And your tax records have to sit at a place of business in Canada.
TRAP 1 — 'Outside Quebec' does not mean 'outside Canada'. Quebec's assessment-and-agreement requirement bites on any communication of personal information beyond Quebec's borders. A Quebec business moving to a Toronto or Vancouver cloud region triggers the same paperwork as one moving to Ireland. Most cross-border compliance programmes are built around national borders and miss this entirely. TRAP 2 — Biometrics in Quebec run on a 60-day fuse. The creation of a database of biometric characteristics and measurements 'must be disclosed to the Commission d'accès à l'information promptly and not later than 60 days before it is brought into service', and biometric verification needs express consent plus prior notice. The Commission can suspend or prohibit the database. It did exactly that to Metro Inc. in February 2025. Plan the notification before you sign the vendor contract, not after. TRAP 3 — British Columbia's data-residency rule is gone. The old requirement that public bodies store personal information only in Canada was repealed in 2021 and does not appear in the current statute. What is left is a regulation-making power over disclosure outside Canada. Vendors still marketing 'BC data residency required' as a legal fact are selling a repealed rule. That said, the power sits there unused, so this is a dormant switch, not a settled liberalisation. TRAP 4 — Nova Scotia's rule is about you, not just about government. It binds 'service providers contracted by these entities who handle personal information'. If you sell software to a Nova Scotia municipality, university or health authority, your storage and your support team's screen access must be in Canada. Fines reach C$500,000 (about US$365,000) for a corporation, C$25,000 for an unincorporated business and C$2,000 for an individual employee. TRAP 5 — Canada has a quiet records-location rule in tax law. Income Tax Act section 230 requires records to be kept at a place of business or residence in Canada unless the Minister designates somewhere else. It is old, it is routinely ignored, and it is still on the books. TRAP 6 — The national privacy regulator cannot fine you, which lulls people into ignoring it, while Quebec's regulator can reach 4% of worldwide turnover. Risk is concentrated in the province with 23% of the population.
Sources
- Official sourcePublications QuébecAct to establish a legal framework for information technology (Quebec), sections 44 and 45
legisquebec.gouv.qc.ca
“The creation of a database of biometric characteristics and measurements must be disclosed to the Commission d'accès à l'information promptly and not later than 60 days before it is brought into service.”
Link checked 18 August 2026
- Official sourceNova Scotia Department of JusticePIIDPA FAQ — application to service providers and penalties
novascotia.ca
Link checked 18 August 2026
- Official sourceKing's Printer, British ColumbiaFreedom of Information and Protection of Privacy Act (British Columbia) — current text, no storage-in-Canada section
bclaws.gov.bc.ca
Link checked 18 August 2026
- Official sourceDepartment of Justice CanadaIncome Tax Act, section 230 — records kept at a place of business in Canada
laws-lois.justice.gc.ca
“at the person's place of business or residence in Canada or at such other place as may designated by the Minister”
Link checked 18 August 2026
- Official sourceCommission d'accès à l'information du QuébecDécision interdisant à Metro Inc. de mettre en service une banque de caractéristiques biométriques (27 février 2025)
cai.gouv.qc.ca
Link checked 18 August 2026
What is changing soon in Canada?
One big bill and one big law already passed. The bill is Canada's third attempt to replace its 25-year-old privacy law: it would force a written risk assessment before any personal data goes outside Canada, give people a right to have data deleted, treat everyone under 18 as sensitive, and set up a new commissioner. It was only introduced in June 2026 and is not law — do not plan around it as if it were. The law already passed is the cyber security act, which switches on in stages over the coming year.
LANDING IN THE NEXT 12 MONTHS - Bill C-36, the Protecting Privacy and Consumer Data Act. Introduced and given first reading on 15 June 2026; at second reading in the House of Commons as at 18 August 2026. Status: proposed, no legal effect. It would repeal Part 1 of PIPEDA, create a Privacy and Consumer Data Commissioner inside a new Digital Safety and Data Protection Commission of Canada, require a privacy impact assessment and mitigation measures before personal information is disclosed or transferred outside Canada, create a right to request disposal of personal information, and define a child as anyone under 18 with children's information treated as sensitive by default. Two previous attempts (Bill C-11 and Bill C-27) both died on the order paper, so treat passage as uncertain. - Critical Cyber Systems Protection Act phase-in. Bill C-8 received royal assent in June 2026. The Telecommunications Act security amendments took effect immediately. The Critical Cyber Systems Protection Act itself is being brought in gradually, and its real obligations — cyber security programme within 90 days of designation, supply-chain risk mitigation, incident reporting inside 72 hours, records kept in Canada — do not bite until the designation and reporting regulations are made. Watch for those regulations. - Bill C-2, the Strong Borders Act, would expand lawful-access powers over service providers. It has been stuck at second reading since September 2025. Status: proposed. DORMANT SWITCHES — powers already held, usable without consultation 1. The Superintendent of Financial Institutions can order a bank to stop keeping copies of records in another country, or to keep copies at any place in Canada, where access is inadequate or the Minister advises it is against the national interest. The bank 'shall without delay comply'. This can turn a global bank's data architecture into a Canadian one with a single order. 2. British Columbia's minister can make regulations governing disclosure of personal information outside Canada. The power sits in the statute; whether it has been exercised we could not confirm. 3. The amended Telecommunications Act gives the Governor in Council and the Minister power to direct telecommunications providers on security matters, in force since royal assent. 4. Nova Scotia's Canada-only rule already allows the head of a public body to authorise exceptions — meaning the strictness is administratively adjustable in both directions.
Sources
- Official sourceParliament of CanadaBill C-36, An Act to enact the Protecting Privacy and Consumer Data Act (first reading, 15 June 2026)
parl.ca
Link checked 18 August 2026
- Official sourceParliament of CanadaLEGISinfo — Bill C-36 status: second reading, House of Commons
parl.ca
Link checked 18 August 2026
- Official sourcePublic Safety CanadaRoyal assent of Bill C-8 — phased implementation
canada.ca
“amendments to the Telecommunications Act take immediate effect upon Royal Assent. The Critical Cyber Systems Protection Act will be implemented gradually, with certain provisions coming into force through a phased approach.”
Link checked 18 August 2026
- Official sourceDepartment of Justice CanadaBank Act, section 245 — Superintendent's power over where records are kept
laws-lois.justice.gc.ca
“A bank shall without delay comply with any order issued under subsection (1) or (1.1).”
Link checked 18 August 2026
- Official sourceParliament of CanadaLEGISinfo — Bill C-2, Strong Borders Act: second reading
parl.ca
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
3 rules here
Layer 2
State or provincial rule
Made by a state or province. Only binds you for people in that state.
4 rules here
Layer 3
Industry rules
Made by an industry regulator. These usually beat the general position.
3 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules3 rules
Personal Information Protection and Electronic Documents Act
Act of parliament · S.C. 2000, c. 5
Canada's national private-sector privacy law. It places no limit on where personal data is stored or processed — instead you stay accountable for it, must contract for comparable protection, and must tell people it may go abroad. The regulator cannot fine you; it makes findings and the case must go to court for money.
Enforced by Office of the Privacy Commissioner of Canada
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Get consent
- Tell people what you doMust include that information may be processed in another country and may be accessed there by courts, law enforcement and national security authorities.
- Secure the data
- Written vendor contractContractual or other means providing a comparable level of protection. The transferring organisation stays accountable.
- Let people see their data
- Let people correct their data
- Report breaches to the regulator — from 1 November 2018As soon as feasible. No fixed hour count.
- Tell affected people — from 1 November 2018
- Keep records of processing — 2 years, from 1 November 2018Record of every breach of security safeguards, reportable or not.
- Delete data after a periodKeep only as long as needed for the identified purpose, then destroy, erase or anonymise.
What it costs if you get it wrong
- Fixed maximum fine: CAD 100,000 — about $73 thousandKnowingly failing to report a breach, notify individuals or keep breach records; also obstructing an investigation
- Claims by individualsFederal Court application for damages after a Commissioner report
Sources
- Official sourceOffice of the Privacy Commissioner of CanadaPIPEDA requirements in brief
priv.gc.ca
Link checked 18 August 2026
- Official sourceOffice of the Privacy Commissioner of CanadaMandatory reporting of breaches of security safeguards
priv.gc.ca
“you keep breach records of all breaches of security safeguards for two years”
Link checked 18 August 2026
- Official sourceOffice of the Privacy Commissioner of CanadaGuidelines for processing personal data across borders
priv.gc.ca
Link checked 18 August 2026
Direction for Electronic Data Residency (ITPIN 2017-02), with the Policy on Service and Digital
Government policy document · Treasury Board of Canada Secretariat, Direction for Electronic Data Residency · Government
If you sell cloud or software to the Canadian federal government, sensitive data has to stay on Canadian soil. Anything rated Protected B or higher must be stored in an approved facility inside Canada. This is a policy binding departments, so it reaches suppliers through procurement rather than through a fine.
Enforced by Treasury Board of Canada Secretariat
Transfer model: Not allowed · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryProtected B, Protected C and Classified electronic data must be stored in a government-approved computing facility inside Canada, or on Canadian government premises abroad.
- Prove the data stays under local controlOnly data up to and including Protected B may be deployed to a commercial public cloud at all.
- Secure the dataProtected B and above must be encrypted in transit outside government-controlled zones.
What it costs if you get it wrong
- Order to stopNon-compliant systems must be reported to the Treasury Board with a remediation plan; contracts can be refused or terminated
Sources
- Official sourceTreasury Board of Canada SecretariatDirection for Electronic Data Residency
canada.ca
“All sensitive electronic data under government control, that has been categorized as Protected B, Protected C or is Classified, will be stored in a GC-approved computing facility located within the geographic boundaries of Canada or within the premises of a GC department located abroad.”
Link checked 18 August 2026
- Official sourceGovernment of CanadaGovernment of Canada White Paper: Data Sovereignty and Public Cloud
canada.ca
“only data up to and including Protected B may be deployed to a public cloud”
Link checked 18 August 2026
Bill C-36, An Act to enact the Protecting Privacy and Consumer Data Act
Draft law · Bill C-36, 45th Parliament, 1st Session
A bill, not a law. If passed it would replace the private-sector half of Canada's privacy act, create a new Privacy and Consumer Data Commissioner, and — the big change — require a written risk assessment before personal data goes outside Canada. Two earlier attempts at the same reform died before becoming law.
Enforced by Office of the Privacy Commissioner of Canada
Transfer model: Approval each time · Accepted routes: Standard contract clauses
What it makes you do
- Assess high-risk projectsProposed: a privacy impact assessment and mitigation measures before personal information is disclosed or transferred outside Canada.
- Let people delete their dataProposed right to request disposal of personal information.
- Get a parent's consent for children — applies at: under 18Proposed: a child is anyone under 18, and children's information is sensitive by default.
- Written vendor contractProposed: service providers must give equivalent protection.
What it costs if you get it wrong
- Fixed maximum fineProposed administrative monetary penalties; amounts not verified from the bill text on this pass
Sources
- Official sourceParliament of CanadaBill C-36, Protecting Privacy and Consumer Data Act (first reading text)
parl.ca
Link checked 18 August 2026
State or provincial rule4 rules
Loi sur la protection des renseignements personnels dans le secteur privé (as amended by Law 25)
Act of parliament · CQLR c. P-39.1; amending Act S.Q. 2021, c. 25
Quebec is the strictest privacy jurisdiction in Canada and the only one that can fine you. Before personal information leaves Quebec — including to Ontario or British Columbia — you must complete a written privacy impact assessment showing the data will be adequately protected, and sign a written agreement.
Enforced by Commission d'accès à l'information du Québec
Transfer model: Approval each time · Accepted routes: Standard contract clauses, Explicit consent
What it makes you do
- Assess high-risk projects — from 22 September 2023Required before any communication of personal information outside Quebec — including to other Canadian provinces.
- Put a transfer safeguard in place — from 22 September 2023Written agreement required; transfer permitted only if the assessment shows adequate protection.
- Appoint a data protection officerA named person in charge of protecting personal information, published; defaults to the most senior executive.
- Report breaches to the regulatorConfidentiality incidents with a risk of serious injury, reported with diligence; register of incidents required.
- Tell affected people
- Let people delete their data
- Let people take their data elsewhere — from 22 September 2024
- Limit automated decisions
- Delete data after a period
What it costs if you get it wrong
- Percentage of global turnover: 2% of worldwide turnover or CAD 10 million, whichever is greater — about $7 millionAdministrative monetary penalty for breaches including inadequate security or failing to report a confidentiality incident
- Percentage of global turnover: 4% of worldwide turnover or CAD 25 million, whichever is greater — about $18 millionPenal proceedings; amounts double on a repeat offence
Sources
- Official sourceCommission d'accès à l'information du QuébecCommunication de renseignements personnels hors Québec
cai.gouv.qc.ca
“avant de communiquer un renseignement personnel à l'extérieur du Québec, une organisation doit procéder à une évaluation des facteurs relatifs à la vie privée”
Link checked 18 August 2026
- Official sourceCommission d'accès à l'information du QuébecSanctions applicables aux entreprises privées
cai.gouv.qc.ca
Link checked 18 August 2026
Personal Information International Disclosure Protection Act
Act of parliament · S.N.S. 2006, c. 3 · Government
Nova Scotia's hard wall. Personal information held by public bodies and municipalities must stay in Canada and be accessed only from Canada. It reaches private suppliers too, so a software vendor serving a Nova Scotia hospital, university or town hall must keep both the data and its support access inside Canada.
Enforced by Nova Scotia Information Access and Privacy Services (Department of Justice)
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryStorage, access and disclosure must all be inside Canada. Remote support access from abroad counts as access.
- Written vendor contractBinds private service providers contracted by public bodies and municipalities.
- Do not hand data to foreign authorities on demandForeign demands for the information must be reported to the Minister of Justice.
What it costs if you get it wrong
- Fixed maximum fine: CAD 500,000 — about $365 thousandCorporation storing, accessing or disclosing personal information outside Canada without authority
- Fixed maximum fine: CAD 25,000 — about $18 thousandUnincorporated business
- Fixed maximum fine: CAD 2,000 — about $1 thousandIndividual employee
Sources
- Official sourceNova Scotia Department of Justice, Information Access and Privacy ServicesPersonal Information International Disclosure Protection Act — frequently asked questions
novascotia.ca
“Personal information held by public bodies and municipalities must remain in Canada, be accessed, and disclosed only in Canada, unless certain circumstances exist.”
Link checked 18 August 2026
Freedom of Information and Protection of Privacy Act (British Columbia), section 33.1
Act of parliament · R.S.B.C. 1996, c. 165 · Government
British Columbia used to require public bodies to keep personal information in Canada. That rule was repealed in 2021 and is no longer in the statute — many compliance trackers still show it wrongly. What remains is a power for the minister to control disclosure outside Canada by regulation, which can be switched on without a new law.
Enforced by Office of the Information and Privacy Commissioner for British Columbia
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Put a transfer safeguard in placeDisclosure outside Canada is allowed only in accordance with any regulations the responsible minister makes.
- Assess high-risk projectsPublic bodies must complete privacy impact assessments for new or changed initiatives.
What it costs if you get it wrong
- Fixed maximum fineOffence provisions under the Act; enforcement is primarily by order of the Information and Privacy Commissioner
Sources
- Official sourceKing's Printer, British ColumbiaFreedom of Information and Protection of Privacy Act (British Columbia), sections 30 to 33.1
bclaws.gov.bc.ca
“A public body may disclose personal information outside of Canada only if the disclosure is in accordance with the regulations, if any, made by the minister.”
Link checked 18 August 2026
Personal Health Information Protection Act, 2004
Act of parliament · S.O. 2004, c. 3, Sch. A · Health and social care
A widely believed myth, corrected by the regulator itself: Ontario health data does not have to stay in Ontario or in Canada. The health custodian simply remains fully responsible for it and must be satisfied that the safeguards travel with it, usually through the contract.
Enforced by Information and Privacy Commissioner of Ontario
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Secure the dataThe custodian stays accountable and must be satisfied that administrative, physical and technical safeguards are in place, typically by contract.
- Written vendor contract
- Tell affected peopleNotify affected individuals at the first reasonable opportunity; an agent must notify the custodian at the first reasonable opportunity.
- Report breaches to the regulator
What it costs if you get it wrong
- Fixed maximum fine: CAD 200,000 for an individual; CAD 1,000,000 for an organisation — about $730 thousandOffence under the Act, on prosecution
- Claims by individuals
Sources
- Official sourceInformation and Privacy Commissioner of OntarioFrequently Asked Questions: Personal Health Information Protection Act
ipc.on.ca
“PHIPA does not require that personal health information be retained and stored in Ontario or Canada.”
Link checked 18 August 2026
Industry rules3 rules
Guideline B-10 Third-Party Risk Management, read with Bank Act section 245 and the equivalent provisions of the Insurance Companies Act and Trust and Loan Companies Act
Regulator guideline · OSFI Guideline B-10 (2023); Bank Act, S.C. 1991, c. 46, s. 245 · Banking
Federally regulated banks and insurers must keep a complete, daily-current copy of their records on servers physically in Canada. Some institutions can be exempted if the supervisor gets immediate and continuous access to records held abroad. The Superintendent can also order a bank to pull records back into Canada at any time.
Enforced by Office of the Superintendent of Financial Institutions
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryComplete copies of statutory Records on computer servers physically located in Canada, accurate as at the end of each business day. Exempt institutions may hold records abroad only with immediate, direct, complete and ongoing access for the supervisor.
- Written vendor contractThird-party arrangements must preserve the supervisor's ability to examine the institution's business and affairs.
- Independent audit
- Secure the data
What it costs if you get it wrong
- Order to stopSupervisory direction; the Superintendent may order a bank to stop keeping record copies abroad or to keep copies at a place in Canada, and the bank must comply without delay
Sources
- Official sourceOffice of the Superintendent of Financial InstitutionsGuideline B-10: Third-Party Risk Management
osfi-bsif.gc.ca
“complete copies must be kept on a computer server(s) physically located at the places stipulated in the FRFI Statutes”
Link checked 18 August 2026
- Official sourceDepartment of Justice CanadaBank Act, section 245 — records
laws-lois.justice.gc.ca
“A bank shall without delay comply with any order issued under subsection (1) or (1.1).”
Link checked 18 August 2026
Critical Cyber Systems Protection Act, enacted by the Cyber Security Act (Bill C-8)
Act of parliament · S.C. 2026, c. 9
A new localisation rule hiding inside a cyber security law. Operators of critical systems in banking, telecoms, energy and transport must keep their required records in Canada, run a cyber security programme, and report incidents to the national cyber agency within 72 hours. The law is passed but the duties do not bite until the government names who is covered.
Enforced by Communications Security Establishment / Canadian Centre for Cyber Security
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep the data in the countryRecords that a designated operator must keep 'must be kept in Canada' at a place prescribed by regulation. Not yet triggered — the regulations are still to be made.
- Report cyber incidents — within 72 hoursTo the Communications Security Establishment within a period set by regulation, not exceeding 72 hours; then immediately notify the sector regulator.
- Secure the dataEstablish a cyber security programme within 90 days of designation.
- Written vendor contractSupply-chain and third-party cyber risks must be mitigated as soon as identified.
- Keep records of processing
What it costs if you get it wrong
- Fixed maximum fine: CAD 10,000,000 (CAD 15,000,000 for a subsequent violation) — about $7 millionAdministrative monetary penalty against a corporation
- Fixed maximum fine: CAD 25,000 (CAD 50,000 for a subsequent violation) — about $18 thousandAdministrative monetary penalty against an individual
Sources
- Official sourceParliament of CanadaCyber Security Act / Critical Cyber Systems Protection Act (Bill C-8, as assented to)
parl.ca
“must be kept in Canada by the designated operator at any place that is prescribed by the regulations”
Link checked 18 August 2026
- Official sourcePublic Safety CanadaGovernment of Canada strengthens cyber security with royal assent of Bill C-8
canada.ca
“The Critical Cyber Systems Protection Act will be implemented gradually, with certain provisions coming into force through a phased approach.”
Link checked 18 August 2026
- Secondary sourceOsler, Hoskin & Harcourt LLPCanada's Bill C-8: what businesses need to know
osler.com
Retail Payment Activities Act
Act of parliament · S.C. 2021, c. 23, s. 177 · Payments
Payment firms are supervised by the central bank, not the privacy regulator. There is no rule that payment data stay in Canada, but a firm based abroad that targets Canadian users must register, name an agent inside Canada, and report a serious incident within 48 hours.
Enforced by Bank of Canada (Retail Payments Supervision)
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Register or notify — from 8 September 2025No retail payment activity may be performed before the Bank of Canada issues a registration decision.
- Appoint a local representativeA foreign provider with no office in Canada must name an agent or mandatary in Canada to receive notices and orders.
- Report breaches to the regulator — within 48 hoursMaterial incidents: notify the Bank of Canada and affected end users without delay and no later than 48 hours.
- Tell affected people — within 48 hours
- Secure the dataOperational risk management and end-user fund safeguarding framework.
- Keep records of processingAnnual report to the Bank of Canada by 31 March each year covering the prior calendar year.
What it costs if you get it wrong
- Loss of your licenceRefusal or revocation of registration; the Bank publishes enforcement decisions
- Fixed maximum fineAdministrative monetary penalties for violations of the Act
Sources
- Official sourceBank of CanadaFrequently asked questions about retail payments supervision
bankofcanada.ca
“After September 8, 2025, entities must be registered (i.e., receive a registration decision from the Bank) before performing any retail payment activities.”
Link checked 18 August 2026
- Official sourceBank of CanadaReminder: PSP reporting obligations under the RPAA
bankofcanada.ca
“without delay but no later than 48 hours”
Link checked 18 August 2026
- Official sourceDepartment of Justice CanadaRetail Payment Activities Act, section 18 — notice of incidents
laws-lois.justice.gc.ca
“the payment service provider must, without delay, notify that individual or entity and the Bank of the incident”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Whether Quebec's private-sector privacy law gives individuals a minimum award of punitive damages (commonly reported as C$1,000) for unlawful infringement
The official consolidated statute on legisquebec.gouv.qc.ca returned a 502 server error on 18 August 2026 and we could not read the operative section. The Commission's own sanctions page describes administrative and penal penalties but not the private damages provision. Excluded from the record rather than asserted from a secondary source.
Whether Bill C-8 received royal assent on 15 or 16 June 2026
Parliament's LEGISinfo page states Monday, 15 June 2026 (Statutes of Canada 2026, c. 9); the Public Safety Canada news release states 16 June 2026. Both are government sources and they disagree by one day. We have used 15 June 2026. Plan to the earlier date.
The exact classes of designated operators, sectors and regulators in Schedules 1 and 2 of the Critical Cyber Systems Protection Act, and when its obligations actually commence
The schedules were not reproduced in the fetched portion of the assented bill and no Public Safety Canada implementation page was reachable. We can evidence the four vital service areas (finance, telecommunications, energy, transportation) from the government news release, and the 'records must be kept in Canada' and 72-hour reporting text from the bill, but not the commencement dates. The rule is therefore marked partially-in-force at medium confidence.
Whether the British Columbia minister has actually made regulations under section 33.1 controlling disclosure of personal information outside Canada
The BC Freedom of Information and Protection of Privacy Regulation page on bclaws.gov.bc.ca is disallowed by robots.txt and could not be fetched. The statutory power is confirmed; whether it is populated is not. Treated as a dormant switch.
Whether Newfoundland and Labrador still imposes a store-and-access-only-in-Canada rule on public bodies
A commonly cited claim. We fetched the Access to Information and Protection of Privacy Act, 2015 from the Newfoundland and Labrador House of Assembly site on 18 August 2026 and found no such section in the retrieved text. We are not confident enough to assert either the presence or the absence of the rule, so no rule was created.
The maximum administrative monetary penalties proposed in Bill C-36
Widely reported in professional commentary as up to C$25 million or 5% of global revenue, but we could not locate the numerical thresholds in the sections retrieved from the first reading text. Left unstated rather than sourced to a law firm.
Whether PIPEDA reaches a foreign organisation with no Canadian presence at all, as distinct from one that operates in Canada
The Commissioner's summary covers businesses that operate in Canada. The extraterritorial 'real and substantial connection' test comes from Federal Court case law that we did not verify live on this pass. Q1 is therefore phrased around doing business with people in Canada.
Whether any securities regulator imposes a records-in-Canada requirement on registered dealers and advisers
The Ontario Securities Commission's page for National Instrument 31-103 returned a 403 error and the web search budget was exhausted before an alternative official source could be checked. No securities rule was created; absence of a rule here should not be read as absence of a requirement.
Whether Alberta's Health Information Act restricts storage or disclosure of health information outside Alberta or Canada
The Alberta government overview page confirms custodian duties and breach notification but is silent on geography, and the King's Printer PDF of the Act is blocked by robots.txt. Alberta health data was therefore left out of the sector list rather than rated.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.