Skip to the content
Global Data RulesData governance rules, country by country

Canada

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Active

Canada lets data leave the country. There is no approved-country list and no banned-country list. You stay responsible for the data wherever it goes, and you must tell people it may be handled abroad. The catch is that Canada is really ten jurisdictions at once, and several of them add hard storage rules on top of the national one.

Eight questions about Canada

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Canada's rules apply to my company?

Yes. Canada's national privacy law reaches a foreign company with no office here if it handles personal information about people in Canada as part of doing business. There is no revenue or headcount threshold that lets you out. You do not normally need a local representative, but payment companies are an exception: a payment firm based abroad that aims its service at people in Canada must register with the central bank and name an agent inside Canada to receive official notices.

High confidenceNational rulesAppoint a local representativeRegister or notify

Can I store my users' data outside Canada?

In general, yes, and with no government permission. Canada's national law does not restrict where personal data is stored or processed. But the headline is wrong for at least six groups. Quebec makes you do a written risk assessment first — and that applies even to sending data to Ontario. Nova Scotia public bodies and their suppliers must keep the data in Canada. Federal government data rated Protected B or higher must sit in Canada. Banks must keep a full copy of their records on servers in Canada. And under the new cyber security law, records about critical systems must be kept in Canada.

High confidenceDepends on your industryNo restriction

What do I need in place before data leaves Canada?

At the national level there is no list at all — no approved countries, no banned countries, no government form to file. What you must do instead is stay accountable: put a contract or similar protection in place with whoever handles the data for you, and tell people plainly that their information may be processed in another country and could be seen by foreign courts, police or security agencies. Quebec is different and stricter: there you must complete a written privacy risk assessment before the data moves, and sign a written agreement.

High confidenceNo restrictionNothing requiredWritten vendor contractTell people what you doPut a transfer safeguard in placeAssess high-risk projects

Who enforces the rules in Canada, and what can they do?

Canada has many regulators and they are all real, staffed and issuing decisions. The national one, the Privacy Commissioner of Canada, published findings against OpenAI, X, Bell and WestJet in the first half of 2026 alone. But it cannot fine anyone — it makes findings and recommendations, and a case has to go to the Federal Court for money. Quebec's regulator can fine, and has blocked a national grocery chain from switching on a face-recognition system. Banking, payments and cyber security each have their own separate supervisor.

High confidenceActive

How long do I have to keep the data?

The floor and the ceiling pull in opposite directions. Tax law says keep your business records for six years after the tax year they relate to, and keep them at a place of business in Canada unless the tax authority agrees to somewhere else. Privacy law says the opposite: delete personal information once the reason you collected it has gone. Where the two clash, the duty to keep wins — but only for the specific records the law names, and only for as long as it names.

High confidenceKeep data for a minimum periodDelete data after a periodKeep records of processingKeep the data in the country

What happens if there is a breach?

Count at least four clocks and they do not agree. The national privacy law gives no fixed number of hours — you report 'as soon as feasible', which in practice means days, not weeks. Payment firms get 48 hours to tell the central bank about a serious incident. Critical infrastructure operators will get no more than 72 hours to tell the national cyber agency, then must tell their own regulator immediately after. Health and provincial rules add more. The overlap is where people get caught: one incident, several reports, several deadlines.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidentsKeep records of processing

What trips people up in Canada?

Five things that are not in any summary. Quebec's cross-border rule catches you sending data to Ontario, not just abroad. Quebec also makes you tell its regulator 60 days before you switch on any face or fingerprint system, and it has already blocked a big grocery chain from doing so. British Columbia repealed its keep-it-in-Canada rule in 2021, so trackers that still show it are wrong. Nova Scotia's Canada-only rule reaches private suppliers, with fines up to half a million dollars. And your tax records have to sit at a place of business in Canada.

High confidenceKeep the data in the countryAssess high-risk projectsPut a transfer safeguard in placeFixed maximum finePercentage of global turnover

What is changing soon in Canada?

One big bill and one big law already passed. The bill is Canada's third attempt to replace its 25-year-old privacy law: it would force a written risk assessment before any personal data goes outside Canada, give people a right to have data deleted, treat everyone under 18 as sensitive, and set up a new commissioner. It was only introduced in June 2026 and is not law — do not plan around it as if it were. The law already passed is the cyber security act, which switches on in stages over the coming year.

High confidenceProposedPartly in force

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    3 rules here

  2. Layer 2

    State or provincial rule

    Made by a state or province. Only binds you for people in that state.

    4 rules here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    3 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules3 rules

Personal Information Protection and Electronic Documents Act

Act of parliament · S.C. 2000, c. 5

In forceYes — store it anywhere

Canada's national private-sector privacy law. It places no limit on where personal data is stored or processed — instead you stay accountable for it, must contract for comparable protection, and must tell people it may go abroad. The regulator cannot fine you; it makes findings and the case must go to court for money.

In force since 1 January 2001But only enforceable from 1 January 2004

Enforced by Office of the Privacy Commissioner of Canada

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Direction for Electronic Data Residency (ITPIN 2017-02), with the Policy on Service and Digital

Government policy document · Treasury Board of Canada Secretariat, Direction for Electronic Data Residency · Government

In forceNo — it stays put

If you sell cloud or software to the Canadian federal government, sensitive data has to stay on Canadian soil. Anything rated Protected B or higher must be stored in an approved facility inside Canada. This is a policy binding departments, so it reaches suppliers through procurement rather than through a fine.

In force since 1 November 2017

Enforced by Treasury Board of Canada Secretariat

Transfer model: Not allowed · Accepted routes: Government sign-off needed

High confidence

Bill C-36, An Act to enact the Protecting Privacy and Consumer Data Act

Draft law · Bill C-36, 45th Parliament, 1st Session

ProposedYes, with paperwork

A bill, not a law. If passed it would replace the private-sector half of Canada's privacy act, create a new Privacy and Consumer Data Commissioner, and — the big change — require a written risk assessment before personal data goes outside Canada. Two earlier attempts at the same reform died before becoming law.

Enforced by Office of the Privacy Commissioner of Canada

Transfer model: Approval each time · Accepted routes: Standard contract clauses

High confidence

State or provincial rule4 rules

Loi sur la protection des renseignements personnels dans le secteur privé (as amended by Law 25)

Act of parliament · CQLR c. P-39.1; amending Act S.Q. 2021, c. 25

In forceYes, with paperwork

Quebec is the strictest privacy jurisdiction in Canada and the only one that can fine you. Before personal information leaves Quebec — including to Ontario or British Columbia — you must complete a written privacy impact assessment showing the data will be adequately protected, and sign a written agreement.

In force since 22 September 2022But only enforceable from 22 September 2023

Enforced by Commission d'accès à l'information du Québec

Transfer model: Approval each time · Accepted routes: Standard contract clauses, Explicit consent

High confidence

Personal Information International Disclosure Protection Act

Act of parliament · S.N.S. 2006, c. 3 · Government

In forceNo — it stays put

Nova Scotia's hard wall. Personal information held by public bodies and municipalities must stay in Canada and be accessed only from Canada. It reaches private suppliers too, so a software vendor serving a Nova Scotia hospital, university or town hall must keep both the data and its support access inside Canada.

In force since 15 November 2006

Enforced by Nova Scotia Information Access and Privacy Services (Department of Justice)

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Freedom of Information and Protection of Privacy Act (British Columbia), section 33.1

Act of parliament · R.S.B.C. 1996, c. 165 · Government

In forceYes, with paperwork

British Columbia used to require public bodies to keep personal information in Canada. That rule was repealed in 2021 and is no longer in the statute — many compliance trackers still show it wrongly. What remains is a power for the minister to control disclosure outside Canada by regulation, which can be switched on without a new law.

In force since 25 November 2021

Enforced by Office of the Information and Privacy Commissioner for British Columbia

Transfer model: Approval each time · Accepted routes: Government sign-off needed

Medium confidence

Industry rules3 rules

Guideline B-10 Third-Party Risk Management, read with Bank Act section 245 and the equivalent provisions of the Insurance Companies Act and Trust and Loan Companies Act

Regulator guideline · OSFI Guideline B-10 (2023); Bank Act, S.C. 1991, c. 46, s. 245 · Banking

In forceA copy must stay

Federally regulated banks and insurers must keep a complete, daily-current copy of their records on servers physically in Canada. Some institutions can be exempted if the supervisor gets immediate and continuous access to records held abroad. The Superintendent can also order a bank to pull records back into Canada at any time.

In force since 1 May 2024

Enforced by Office of the Superintendent of Financial Institutions

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Critical Cyber Systems Protection Act, enacted by the Cyber Security Act (Bill C-8)

Act of parliament · S.C. 2026, c. 9

Partly in forceA copy must stay

A new localisation rule hiding inside a cyber security law. Operators of critical systems in banking, telecoms, energy and transport must keep their required records in Canada, run a cyber security programme, and report incidents to the national cyber agency within 72 hours. The law is passed but the duties do not bite until the government names who is covered.

In force since 15 June 2026

Enforced by Communications Security Establishment / Canadian Centre for Cyber Security

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence

Retail Payment Activities Act

Act of parliament · S.C. 2021, c. 23, s. 177 · Payments

In forceYes — store it anywhere

Payment firms are supervised by the central bank, not the privacy regulator. There is no rule that payment data stay in Canada, but a firm based abroad that targets Canadian users must register, name an agent inside Canada, and report a serious incident within 48 hours.

In force since 1 November 2024But only enforceable from 8 September 2025

Enforced by Bank of Canada (Retail Payments Supervision)

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Who you would hear from

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Whether Quebec's private-sector privacy law gives individuals a minimum award of punitive damages (commonly reported as C$1,000) for unlawful infringement

    The official consolidated statute on legisquebec.gouv.qc.ca returned a 502 server error on 18 August 2026 and we could not read the operative section. The Commission's own sanctions page describes administrative and penal penalties but not the private damages provision. Excluded from the record rather than asserted from a secondary source.

  • Whether Bill C-8 received royal assent on 15 or 16 June 2026

    Parliament's LEGISinfo page states Monday, 15 June 2026 (Statutes of Canada 2026, c. 9); the Public Safety Canada news release states 16 June 2026. Both are government sources and they disagree by one day. We have used 15 June 2026. Plan to the earlier date.

  • The exact classes of designated operators, sectors and regulators in Schedules 1 and 2 of the Critical Cyber Systems Protection Act, and when its obligations actually commence

    The schedules were not reproduced in the fetched portion of the assented bill and no Public Safety Canada implementation page was reachable. We can evidence the four vital service areas (finance, telecommunications, energy, transportation) from the government news release, and the 'records must be kept in Canada' and 72-hour reporting text from the bill, but not the commencement dates. The rule is therefore marked partially-in-force at medium confidence.

  • Whether the British Columbia minister has actually made regulations under section 33.1 controlling disclosure of personal information outside Canada

    The BC Freedom of Information and Protection of Privacy Regulation page on bclaws.gov.bc.ca is disallowed by robots.txt and could not be fetched. The statutory power is confirmed; whether it is populated is not. Treated as a dormant switch.

  • Whether Newfoundland and Labrador still imposes a store-and-access-only-in-Canada rule on public bodies

    A commonly cited claim. We fetched the Access to Information and Protection of Privacy Act, 2015 from the Newfoundland and Labrador House of Assembly site on 18 August 2026 and found no such section in the retrieved text. We are not confident enough to assert either the presence or the absence of the rule, so no rule was created.

  • The maximum administrative monetary penalties proposed in Bill C-36

    Widely reported in professional commentary as up to C$25 million or 5% of global revenue, but we could not locate the numerical thresholds in the sections retrieved from the first reading text. Left unstated rather than sourced to a law firm.

  • Whether PIPEDA reaches a foreign organisation with no Canadian presence at all, as distinct from one that operates in Canada

    The Commissioner's summary covers businesses that operate in Canada. The extraterritorial 'real and substantial connection' test comes from Federal Court case law that we did not verify live on this pass. Q1 is therefore phrased around doing business with people in Canada.

  • Whether any securities regulator imposes a records-in-Canada requirement on registered dealers and advisers

    The Ontario Securities Commission's page for National Instrument 31-103 returned a 403 error and the web search budget was exhausted before an alternative official source could be checked. No securities rule was created; absence of a rule here should not be read as absence of a requirement.

  • Whether Alberta's Health Information Act restricts storage or disclosure of health information outside Alberta or Canada

    The Alberta government overview page confirms custodian duties and breach notification but is silent on geography, and the King's Printer PDF of the Act is blocked by robots.txt. Alberta health data was therefore left out of the sector list rather than rated.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.