Skip to the content
Global Data RulesData governance rules, country by country

Canada

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Canada — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Active

Canada lets data leave the country. There is no approved-country list and no banned-country list. You stay responsible for the data wherever it goes. You must tell people it may be handled abroad. The catch is that Canada is really ten places at once. Several of them add strict storage rules on top of the national one.

Data governance in Canada

The eight things that decide how you handle data about people in Canada. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. Canada's national privacy law reaches a foreign company with no office here. It applies if you handle personal information about people in Canada as part of doing business. There is no revenue or headcount limit that lets you out. You do not normally need a local representative. Payment companies are the exception. A payment firm based abroad that aims its service at people in Canada must register with the central bank. It must also name an agent inside Canada to receive official notices.

What you have to do here:
Appoint a representative · Register or notify

Where the data is allowed to live

Usually yes, and you need no government permission. Canada's national law does not restrict where personal data is stored or handled. But that answer changes for at least six groups. Quebec makes you do a written risk assessment first. That applies even to sending data to Ontario. Nova Scotia public bodies and their suppliers must keep the data in Canada. Federal government data rated Protected B or higher must sit in Canada. Banks must keep a full copy of their records on servers in Canada. And under the new cyber security law, records about critical systems must be kept in Canada.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

At the national level there is no list at all. No approved countries, no banned countries, no government form to file. Instead you stay accountable. Put a contract or similar protection in place with whoever handles the data for you. Tell people plainly that their information may be handled in another country. Tell them it could be seen there by courts, police or security agencies. Quebec is stricter. There you must complete a written privacy risk assessment before the data moves, and sign a written agreement.

What you have to do here:
Written vendor contract · Tell people what you do · Put a transfer safeguard in place · Assess high-risk projects
Ways to send data out:
Nothing required

The regulator, and whether it actually acts

Canada has many regulators. They are all real, staffed and issuing decisions. The national one is the Privacy Commissioner of Canada. It published findings against OpenAI, X, Bell and WestJet in the first half of 2026 alone. But it cannot fine anyone. It makes findings and recommendations, and a case has to go to the Federal Court for money. Quebec's regulator can fine. It has blocked a national grocery chain from switching on a face-recognition system. Banking, payments and cyber security each have their own separate supervisor.

How long you must keep it — and when to delete it

Rules pull in opposite directions. Tax law says keep your business records for six years after the tax year they relate to. It also says keep them at a place of business in Canada, unless the tax authority agrees to somewhere else. Privacy law says the opposite. Delete personal information once the reason you collected it has gone. Where the two clash, the duty to keep wins. That only covers the specific records the law names, and only for as long as it names.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep records of how you use data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There are at least four clocks and they do not agree. The national privacy law gives no fixed number of hours. You report 'as soon as feasible', which usually means days, not weeks. Payment firms get 48 hours to tell the central bank about a serious incident. Critical infrastructure operators will get no more than 72 hours to tell the national cyber agency. They must then tell their own regulator immediately after. Health and provincial rules add more. The overlap is where people get caught. One incident, several reports, several deadlines.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents · Keep records of how you use data

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things that are not in any summary. Quebec's cross-border rule catches you sending data to Ontario, not just abroad. Quebec also makes you tell its regulator 60 days before you switch on any face or fingerprint system. It has already blocked a big grocery chain from doing so. British Columbia repealed its keep-it-in-Canada rule in 2021, so trackers that still show it are out of date. Nova Scotia's Canada-only rule reaches private suppliers, with fines up to half a million dollars. And your tax records have to sit at a place of business in Canada.

What you have to do here:
Keep the data in the country · Assess high-risk projects · Put a transfer safeguard in place
What it costs if you get it wrong:
Fixed maximum fine · Percentage of global turnover

What's changing next

One big bill and one big law already passed. The bill is Canada's third attempt to replace its 25-year-old privacy law. It would force a written risk assessment before any personal data goes outside Canada. It would give people a right to have data deleted. It would treat everyone under 18 as sensitive. And it would set up a new commissioner. It was only introduced in June 2026 and is not law. Do not plan around it as if it were. The law already passed is the cyber security act. It switches on in stages over the coming year.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Banking data needs a copy kept in the country

Official name: Guideline B-10 Third-Party Risk Management, read with Bank Act section 245 and the equivalent provisions of the Insurance Companies Act and Trust and Loan Companies Act · OSFI Guideline B-10 (2023); Bank Act, S.C. 1991, c. 46, s. 245 · Regulator guideline

In forceA copy must stay

Federally regulated banks and insurers must keep a complete, daily-current copy of their records on servers physically in Canada. Some institutions can be exempted if the supervisor gets immediate and continuous access to records held abroad. The Superintendent can also order a bank to pull records back into Canada at any time.

In force since 1 May 2024

Enforced by Office of the Superintendent of Financial Institutions

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Cyber security rules

Official name: Critical Cyber Systems Protection Act, enacted by the Cyber Security Act (Bill C-8) · S.C. 2026, c. 9 · Act of parliament

Partly in forceA copy must stay

A keep-it-in-Canada rule hiding inside a cyber security law. Operators of critical systems in banking, telecoms, energy and transport must keep their required records in Canada. They must run a cyber security programme. They must report incidents to the national cyber agency within 72 hours. The law is passed, but the duties do not apply until the government names who is covered.

In force since 15 June 2026

Enforced by Communications Security Establishment / Canadian Centre for Cyber Security

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.
Payments

Payment data rules

Official name: Retail Payment Activities Act · S.C. 2021, c. 23, s. 177 · Act of parliament

In forceYes — store it anywhere

Payment firms are supervised by the central bank, not the privacy regulator. There is no rule that payment data must stay in Canada. But a firm based abroad that targets Canadian users must register. It must name an agent inside Canada. And it must report a serious incident within 48 hours.

In force since 1 November 2024Enforced from 8 September 2025

Enforced by Bank of Canada (Retail Payments Supervision)

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: Personal Information Protection and Electronic Documents Act · S.C. 2000, c. 5 · Act of parliament

In forceYes — store it anywhere

Canada's national private-sector privacy law. It does not limit where personal data is stored or handled. Instead you stay accountable for it. You must contract for comparable protection, and you must tell people the data may go abroad. The regulator cannot fine you. It makes findings, and the case must go to court for money.

In force since 1 January 2001Enforced from 1 January 2004

Enforced by Office of the Privacy Commissioner of Canada

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Government

Government data must stay in the country (Government)

Official name: Direction for Electronic Data Residency (ITPIN 2017-02), with the Policy on Service and Digital · Treasury Board of Canada Secretariat, Direction for Electronic Data Residency · Government policy document

In forceNo — it stays put

If you sell cloud or software to the Canadian federal government, sensitive data has to stay on Canadian soil. Anything rated Protected B or higher must be stored in an approved facility inside Canada. This is a policy binding departments, so it reaches suppliers through procurement rather than through a fine.

In force since 1 November 2017

Enforced by Treasury Board of Canada Secretariat

How this country controls where data goes: Not allowed · Accepted routes: Government sign-off needed

General data protection law (Bill C-36, 45th Parliament, 1st Session)

Official name: Bill C-36, An Act to enact the Protecting Privacy and Consumer Data Act · Bill C-36, 45th Parliament, 1st Session · Draft law

ProposedYes, with paperwork

A bill, not a law. If passed it would replace the private-sector half of Canada's privacy act. It would create a new Privacy and Consumer Data Commissioner. The big change is that it would require a written risk assessment before personal data goes outside Canada. Two earlier attempts at the same reform died before becoming law.

Enforced by Office of the Privacy Commissioner of Canada

How this country controls where data goes: Approval each time · Accepted routes: Standard contract clauses

Applies only in certain states4 rules

Made by a state or province. It only binds you for the people living there.

General data protection law (2023)

Official name: Loi sur la protection des renseignements personnels dans le secteur privé (as amended by Law 25) · CQLR c. P-39.1; amending Act S.Q. 2021, c. 25 · Act of parliament

In forceYes, with paperwork

Quebec is the strictest place in Canada for privacy, and the only one that can fine you. Before personal information leaves Quebec you must complete a written privacy impact assessment. It must show the data will be adequately protected. You must also sign a written agreement. This applies to sending data to Ontario or British Columbia too.

In force since 22 September 2022Enforced from 22 September 2023

Enforced by Commission d'accès à l'information du Québec

How this country controls where data goes: Approval each time · Accepted routes: Standard contract clauses, Explicit consent

Government

Government data must stay in the country

Official name: Personal Information International Disclosure Protection Act · S.N.S. 2006, c. 3 · Act of parliament

In forceNo — it stays put

Nova Scotia is strict. Personal information held by public bodies and municipalities must stay in Canada and be accessed only from Canada. It reaches private suppliers too. If you sell software to a Nova Scotia hospital, university or town hall, both the data and your support access must stay inside Canada.

In force since 15 November 2006

Enforced by Nova Scotia Information Access and Privacy Services (Department of Justice)

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Government

General data protection law (Government)

Official name: Freedom of Information and Protection of Privacy Act (British Columbia), section 33.1 · R.S.B.C. 1996, c. 165 · Act of parliament

In forceYes, with paperwork

British Columbia used to require public bodies to keep personal information in Canada. That rule was repealed in 2021 and is no longer in the statute. Many compliance trackers still show it. What remains is a power for the minister to control disclosure outside Canada by regulation. That can be switched on without a new law.

In force since 25 November 2021

Enforced by Office of the Information and Privacy Commissioner for British Columbia

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.

Who you would hear from

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Whether Quebec's private-sector privacy law gives individuals a minimum award of punitive damages (commonly reported as C$1,000) for unlawful infringement

    We could not read the operative section. Quebec's official consolidated statute site returned a 502 server error on 18 August 2026. The Commission's own sanctions page describes administrative and criminal penalties, but not the private damages rule. We left it out of the record rather than assert it from a second-hand source.

  • Whether Bill C-8 received royal assent on 15 or 16 June 2026

    Parliament's LEGISinfo page states Monday, 15 June 2026 (Statutes of Canada 2026, c. 9); the Public Safety Canada news release states 16 June 2026. Both are government sources and they disagree by one day. We have used 15 June 2026. Plan to the earlier date.

  • The exact classes of designated operators, sectors and regulators in Schedules 1 and 2 of the Critical Cyber Systems Protection Act, and when its obligations actually commence

    We could not confirm the dates the law starts to apply. The schedules were not included in the part of the assented bill we retrieved, and no Public Safety Canada implementation page was reachable. We can evidence the four vital service areas of finance, telecommunications, energy and transportation from the government news release. We can evidence the 'records must be kept in Canada' wording and the 72-hour reporting deadline from the bill. The rule is marked partly in force at medium confidence.

  • Whether the British Columbia minister has actually made regulations under section 33.1 controlling disclosure of personal information outside Canada

    We could not confirm whether the minister has made any regulations. The power in the statute is confirmed. Whether it has been used is not. Treat it as a power that could be switched on at any time.

  • Whether Newfoundland and Labrador still imposes a store-and-access-only-in-Canada rule on public bodies

    We could not confirm that this rule exists. On 18 August 2026 we read the Access to Information and Protection of Privacy Act, 2015. We took it from the Newfoundland and Labrador House of Assembly site. We found no such section. We are not confident enough to say it is there, or that it is absent, so we created no rule. Check before you rely on this.

  • The maximum administrative monetary penalties proposed in Bill C-36

    Professional commentary widely reports up to 25 million Canadian dollars or 5 per cent of global revenue. We could not find those numbers in the sections we retrieved from the first reading text. We left the figures out rather than source them to a law firm.

  • Whether PIPEDA reaches a foreign organisation with no Canadian presence at all, as distinct from one that operates in Canada

    We could not verify the test for reaching companies with no office in Canada. The Commissioner's summary covers businesses that operate in Canada. The 'real and substantial connection' test comes from Federal Court case law that we did not check live. So question one is written around doing business with people in Canada.

  • Whether any securities regulator imposes a records-in-Canada requirement on registered dealers and advisers

    We could not check whether any securities rule applies. The Ontario Securities Commission's page for its rule 31-103 returned a 403 error, and the search budget ran out before we found another official source. We created no securities rule. Do not read that as meaning there is no requirement.

  • Whether Alberta's Health Information Act restricts storage or disclosure of health information outside Alberta or Canada

    The Alberta government overview page confirms custodian duties and breach notification but says nothing about geography. The King's Printer copy of the Act is blocked to automated readers. So we left Alberta health data out of the industry list rather than rate it.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.