Canada
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Canada — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Canada lets data leave the country. There is no approved-country list and no banned-country list. You stay responsible for the data wherever it goes. You must tell people it may be handled abroad. The catch is that Canada is really ten places at once. Several of them add strict storage rules on top of the national one.
Data governance in Canada
The eight things that decide how you handle data about people in Canada. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. Canada's national privacy law reaches a foreign company with no office here. It applies if you handle personal information about people in Canada as part of doing business. There is no revenue or headcount limit that lets you out. You do not normally need a local representative. Payment companies are the exception. A payment firm based abroad that aims its service at people in Canada must register with the central bank. It must also name an agent inside Canada to receive official notices.
- What you have to do here:
- Appoint a representative · Register or notify
The Personal Information Protection and Electronic Documents Act, known as PIPEDA, covers private-sector organisations. It applies when they collect, use or disclose personal information as part of commercial activity. The Privacy Commissioner's own summary says it covers 'all businesses that operate in Canada and handle personal information that crosses provincial or national borders in the course of commercial activities'. Three provinces are excluded for activity that stays inside the province, because their own laws were declared substantially similar. They are Quebec, Alberta and British Columbia. Federal works and undertakings stay under PIPEDA everywhere, including in those three provinces. That means banks, airlines, telecoms and inter-provincial transport. Under the Retail Payment Activities Act, a foreign payment service provider must register with the Bank of Canada. That applies if it handles retail payments for an end user in Canada and aims those activities at people or businesses in Canada. If it has no office here it 'must identify the name and address of an agent or mandatary within Canada'. Quebec requires every business to have a named person in charge of protecting personal information. Their title and contact details must be published. The job falls to the most senior executive by default, and that person does not have to be in Quebec.
Sources
- Official sourceOffice of the Privacy Commissioner of CanadaPIPEDA requirements in brief — who the law applies to
priv.gc.ca
“all businesses that operate in Canada and handle personal information that crosses provincial or national borders in the course of commercial activities are subject to PIPEDA”
Link checked 18 August 2026
- Official sourceBank of CanadaFrequently asked questions about retail payments supervision — registration of foreign payment service providers
bankofcanada.ca
“must identify the name and address of an agent or mandatary within Canada”
Link checked 18 August 2026
Where the data is allowed to live
Usually yes, and you need no government permission. Canada's national law does not restrict where personal data is stored or handled. But that answer changes for at least six groups. Quebec makes you do a written risk assessment first. That applies even to sending data to Ontario. Nova Scotia public bodies and their suppliers must keep the data in Canada. Federal government data rated Protected B or higher must sit in Canada. Banks must keep a full copy of their records on servers in Canada. And under the new cyber security law, records about critical systems must be kept in Canada.
Your industry decides the answer. Checked industry by industry as at 18 August 2026: - Every industry, national level: OPEN. PIPEDA says nothing about where data must be stored. There is no approved-destination list and no banned-destination list. The Privacy Commissioner states plainly that PIPEDA does not stop this. Organisations in Canada may send personal information to an organisation in another country to be handled there. - Anyone handling data about people in Quebec: CONDITIONAL. Since September 2023 you must carry out a privacy impact assessment before personal information leaves Quebec. You may go ahead only if that assessment shows the information would get adequate protection. You also need a written agreement. Watch the geography. The trigger is leaving Quebec, so a Montreal company using a Toronto data centre is caught. - Nova Scotia public sector and its private suppliers: CLOSED. Personal information held by public bodies and municipalities 'must remain in Canada, be accessed, and disclosed only in Canada'. Only narrow exceptions apply. This binds contracted service providers, not just the public body. - Federal government data: CLOSED for sensitive categories. All Protected B, Protected C and Classified government electronic data must be stored in a government-approved computing facility inside Canada. Canadian government premises abroad also count. - Federally regulated banks and insurers: KEEP A COPY HERE. The Office of the Superintendent of Financial Institutions requires complete copies of the statutory Records to be kept on computer servers physically located in Canada. They must be updated and accurate as at the end of each business day. Some exempt institutions may hold records abroad. That only works if the supervisor gets immediate, direct, complete and ongoing access. Separately, the Superintendent can order a bank to stop keeping copies abroad, or to keep copies at a place in Canada. - Critical cyber systems in banking, telecoms, energy and transport: KEEP A COPY HERE. The Critical Cyber Systems Protection Act has been in force since June 2026. It says records a designated operator must keep 'must be kept in Canada'. - Health: OPEN in Ontario. The Ontario privacy regulator says directly that its health privacy law 'does not require that personal health information be retained and stored in Ontario or Canada'. Other provinces differ. Nova Scotia's health authorities are caught by that province's Canada-only rule. - Payments: OPEN on storage. The Retail Payment Activities Act requires registration, safeguarding and incident reporting. We found no requirement that payment data or safeguarded funds sit in Canada. - British Columbia public sector: CONDITIONAL and unsettled. The old rule requiring storage only in Canada was removed in 2021. What is left is a power. A public body 'may disclose personal information outside of Canada only if the disclosure is in accordance with the regulations, if any, made by the minister'. - Mapping and geospatial data: we found no restriction, checked 18 August 2026, confidence medium.
Sources
- Official sourceOffice of the Privacy Commissioner of CanadaGuidelines for processing personal data across borders
priv.gc.ca
“PIPEDA does not prohibit organizations in Canada from transferring personal information to an organization in another jurisdiction for processing.”
Link checked 18 August 2026
- Official sourceCommission d'accès à l'information du QuébecCommunication de renseignements personnels hors Québec
cai.gouv.qc.ca
“avant de communiquer un renseignement personnel à l'extérieur du Québec, une organisation doit procéder à une évaluation des facteurs relatifs à la vie privée”
Link checked 18 August 2026
- Official sourceNova Scotia Department of JusticePersonal Information International Disclosure Protection Act — frequently asked questions
novascotia.ca
“Personal information held by public bodies and municipalities must remain in Canada, be accessed, and disclosed only in Canada, unless certain circumstances exist.”
Link checked 18 August 2026
- Official sourceTreasury Board of Canada SecretariatDirection for Electronic Data Residency
canada.ca
“All sensitive electronic data under government control, that has been categorized as Protected B, Protected C or is Classified, will be stored in a GC-approved computing facility located within the geographic boundaries of Canada or within the premises of a GC department located abroad.”
Link checked 18 August 2026
- Official sourceOffice of the Superintendent of Financial InstitutionsGuideline B-10, Third-Party Risk Management — records and data location
osfi-bsif.gc.ca
“complete copies must be kept on a computer server(s) physically located at the places stipulated in the FRFI Statutes”
Link checked 18 August 2026
- Official sourceInformation and Privacy Commissioner of OntarioFrequently Asked Questions: Personal Health Information Protection Act
ipc.on.ca
“PHIPA does not require that personal health information be retained and stored in Ontario or Canada.”
Link checked 18 August 2026
- Official sourceKing's Printer, British ColumbiaFreedom of Information and Protection of Privacy Act (British Columbia), section 33.1
bclaws.gov.bc.ca
“A public body may disclose personal information outside of Canada only if the disclosure is in accordance with the regulations, if any, made by the minister.”
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
At the national level there is no list at all. No approved countries, no banned countries, no government form to file. Instead you stay accountable. Put a contract or similar protection in place with whoever handles the data for you. Tell people plainly that their information may be handled in another country. Tell them it could be seen there by courts, police or security agencies. Quebec is stricter. There you must complete a written privacy risk assessment before the data moves, and sign a written agreement.
- What you have to do here:
- Written vendor contract · Tell people what you do · Put a transfer safeguard in place · Assess high-risk projects
- Ways to send data out:
- Nothing required
There is no list at the national level. So the question of whether a list has been filled in does not arise federally. That is a risk in itself. There is nothing to check, nothing to watch, and nothing stopping a future government from creating a list. The Privacy Commissioner's cross-border guidance sets out three duties. First, accountability. You must use contractual or other means to give a comparable level of protection while your supplier handles the information. Second, transparency. You must tell people their information may be sent to another country to be handled. You must also tell them that while it is there, the courts, law enforcement and national security authorities may reach it. Third, a firm limit that the guidance spells out. No contract can override the criminal, national security or other laws of the destination country. Quebec works more like a safety test you run yourself. You do a privacy impact assessment, sized to the sensitivity, purpose, volume, distribution and format of the information. The transfer may go ahead only if it shows the information would get adequate protection. You also need a written agreement.
Sources
- Official sourceOffice of the Privacy Commissioner of CanadaGuidelines for processing personal data across borders — accountability and transparency
priv.gc.ca
“may be sent to another jurisdiction for processing and that while the information is in another jurisdiction it may be accessed by the courts, law enforcement and national security authorities”
Link checked 18 August 2026
- Official sourceCommission d'accès à l'information du QuébecCommunication de renseignements personnels hors Québec — assessment and written agreement
cai.gouv.qc.ca
“La communication peut être effectuée si l'évaluation démontre que le renseignement bénéficierait d'une protection adéquate. Elle doit faire l'objet d'une entente écrite”
Link checked 18 August 2026
The regulator, and whether it actually acts
Canada has many regulators. They are all real, staffed and issuing decisions. The national one is the Privacy Commissioner of Canada. It published findings against OpenAI, X, Bell and WestJet in the first half of 2026 alone. But it cannot fine anyone. It makes findings and recommendations, and a case has to go to the Federal Court for money. Quebec's regulator can fine. It has blocked a national grocery chain from switching on a face-recognition system. Banking, payments and cyber security each have their own separate supervisor.
We rate enforcement active rather than aggressive. There is plenty of activity and there are real investigations. But the main national regulator has no power to fine. Office of the Privacy Commissioner of Canada. Fully operational. Its 2025-26 annual report, published 4 June 2026, records 3,044 PIPEDA complaints received, up 109 per cent on the year before. It also records 3,146 Privacy Act complaints, up 62 per cent. It records nearly 700 private-sector breach reports, affecting more than 20 million Canadians. And it records around 450 federal institution breach reports. Published 2026 findings include a joint investigation into OpenAI in May 2026, commissioner-initiated complaints against X Corp. and X.AI in June 2026, Bell in June 2026, a WestJet compliance letter in July 2026 and Loblaw's PC Optimum loyalty programme in March 2026. It has no power to impose money penalties under PIPEDA. Commission d'accès à l'information du Québec. Operational and using its new powers. In February 2025 it stopped Metro Inc. bringing a biometric database into service. It took part in the joint OpenAI investigation that finished in May 2026. It can impose money penalties. The cap is 2 per cent of worldwide turnover, or 10 million Canadian dollars (about 7.3 million US dollars), whichever is greater. Court proceedings can reach the greater of 4 per cent of worldwide turnover or 25 million Canadian dollars (about 18 million US dollars). Both figures double for repeat offences. Office of the Superintendent of Financial Institutions. Operational. It supervises banks and insurers, and it sets the keep-records-in-Canada expectation. Bank of Canada. Operational as the retail payments supervisor since 2024-25. Registration became compulsory on 8 September 2025 and it publishes enforcement decisions. Communications Security Establishment, plus the industry regulators named in the Critical Cyber Systems Protection Act. The reporting channel is written into the law but is not switched on. The regulations naming who is covered and how to report have not been made. Provincial commissioners in Alberta, British Columbia and Ontario are all operational and publish orders.
Sources
- Official sourceOffice of the Privacy Commissioner of CanadaNews release: Privacy Commissioner of Canada's 2025-2026 annual report
priv.gc.ca
“3,044 PIPEDA complaints received, representing a 109% increase”
Link checked 18 August 2026
- Official sourceOffice of the Privacy Commissioner of CanadaInvestigations into businesses — 2026 findings list
priv.gc.ca
Link checked 18 August 2026
- Official sourceCommission d'accès à l'information du QuébecActualités — Commission d'accès à l'information (Metro biometric prohibition, February 2025; OpenAI joint investigation, May 2026)
cai.gouv.qc.ca
Link checked 18 August 2026
- Official sourceCommission d'accès à l'information du QuébecSanctions applicables aux entreprises privées
cai.gouv.qc.ca
Link checked 18 August 2026
How long you must keep it — and when to delete it
Rules pull in opposite directions. Tax law says keep your business records for six years after the tax year they relate to. It also says keep them at a place of business in Canada, unless the tax authority agrees to somewhere else. Privacy law says the opposite. Delete personal information once the reason you collected it has gone. Where the two clash, the duty to keep wins. That only covers the specific records the law names, and only for as long as it names.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep records of how you use data
MINIMUMS. Income Tax Act section 230 requires records and books of account to be kept 'at the person's place of business or residence in Canada or at such other place as may [be] designated by the Minister'. They must be kept 'until the expiration of six years from the end of the last taxation year to which the records and books of account relate'. Electronic records must stay readable by computer for that period. Under PIPEDA you must keep a record of every breach of security safeguards for two years, whether or not you had to report it. Registered payment service providers must file an annual report to the Bank of Canada by 31 March, covering the previous calendar year. That assumes you keep the underlying operational and incident data. Designated operators under the Critical Cyber Systems Protection Act must keep required records in Canada, for a period their regulator sets. Federally regulated banks must keep complete copies of statutory Records on servers in Canada, updated as at the end of each business day. MAXIMUMS. PIPEDA says you may keep personal information only as long as you need it for the purposes you identified. After that you must destroy it, erase it or make it anonymous. Quebec goes further. It makes destroying or anonymising the data an enforceable duty once the purpose is achieved. WHEN THEY CLASH. Canada settles this the ordinary way. A specific legal duty to keep records beats the general privacy duty to delete. That applies to those records and that period only. It does not let you keep anything else.
Sources
- Official sourceDepartment of Justice CanadaIncome Tax Act, section 230 — records and books of account
laws-lois.justice.gc.ca
“until the expiration of six years from the end of the last taxation year to which the records and books of account relate”
Link checked 18 August 2026
- Official sourceOffice of the Privacy Commissioner of CanadaWhat you need to know about mandatory reporting of breaches of security safeguards
priv.gc.ca
“you keep breach records of all breaches of security safeguards for two years”
Link checked 18 August 2026
- Official sourceBank of CanadaReminder: PSP reporting obligations under the Retail Payment Activities Act
bankofcanada.ca
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There are at least four clocks and they do not agree. The national privacy law gives no fixed number of hours. You report 'as soon as feasible', which usually means days, not weeks. Payment firms get 48 hours to tell the central bank about a serious incident. Critical infrastructure operators will get no more than 72 hours to tell the national cyber agency. They must then tell their own regulator immediately after. Health and provincial rules add more. The overlap is where people get caught. One incident, several reports, several deadlines.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents · Keep records of how you use data
CLOCK 1. PIPEDA, for all commercial organisations. Report to the Privacy Commissioner and tell the affected people 'as soon as feasible'. The clock starts when you decide a breach of security safeguards creates a real risk of significant harm. No hour count is set. Keep a record of every breach for 24 months. Knowingly failing to report, notify or keep records is a crime. CLOCK 2. Retail Payment Activities Act, for registered payment service providers. Tell the Bank of Canada and the affected people or businesses 'without delay but no later than 48 hours'. That runs from when you decide an incident is material. You may need to send initial, interim and final notices. There is a separate rule. Give at least five business days' notice before significant operational changes. CLOCK 3. Critical Cyber Systems Protection Act, for designated operators in banking, telecoms, energy and transport. Report a cyber security incident to the Communications Security Establishment 'within a period prescribed by the regulations, not to exceed 72 hours'. Then 'immediately after reporting' tell the right industry regulator. This clock is in the law but does not start running until the regulations and designation orders are made. CLOCK 4. Quebec. Report confidentiality incidents that risk serious injury to the Commission and to the people affected, with diligence. Keep a register of incidents. CLOCK 5. Provincial health. Alberta's Health Information Act applies where there is a risk of harm. Custodians must tell the affected people, the Information and Privacy Commissioner and the Minister of Health 'as soon as practicable'. Ontario requires notice at the first reasonable opportunity, and an agent must tell its custodian at the first reasonable opportunity. The usual mistake in Canada is not missing one deadline. It is a payments or infrastructure firm treating the privacy report as the only report.
Sources
- Official sourceOffice of the Privacy Commissioner of CanadaMandatory reporting of breaches of security safeguards under PIPEDA
priv.gc.ca
“report to the OPC any privacy breaches that pose a real risk of significant harm to an individual”
Link checked 18 August 2026
- Official sourceBank of CanadaReminder: PSP reporting obligations under the RPAA — 48-hour incident notice
bankofcanada.ca
“without delay but no later than 48 hours”
Link checked 18 August 2026
- Official sourceParliament of CanadaCritical Cyber Systems Protection Act (Bill C-8, as assented to) — incident reporting
parl.ca
“within a period prescribed by the regulations, not to exceed 72 hours”
Link checked 18 August 2026
- Official sourceGovernment of AlbertaHealth Information Act — breach notification duties
alberta.ca
“as soon as practicable”
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things that are not in any summary. Quebec's cross-border rule catches you sending data to Ontario, not just abroad. Quebec also makes you tell its regulator 60 days before you switch on any face or fingerprint system. It has already blocked a big grocery chain from doing so. British Columbia repealed its keep-it-in-Canada rule in 2021, so trackers that still show it are out of date. Nova Scotia's Canada-only rule reaches private suppliers, with fines up to half a million dollars. And your tax records have to sit at a place of business in Canada.
- What you have to do here:
- Keep the data in the country · Assess high-risk projects · Put a transfer safeguard in place
- What it costs if you get it wrong:
- Fixed maximum fine · Percentage of global turnover
TRAP 1. 'Outside Quebec' does not mean 'outside Canada'. Quebec's assessment-and-agreement rule applies to any move of personal information beyond Quebec's borders. A Quebec business moving to a Toronto or Vancouver cloud region does the same paperwork as one moving to Ireland. Most cross-border compliance programmes are built around national borders and miss this. TRAP 2. Biometrics in Quebec run on a 60-day fuse. Creating a database of biometric characteristics and measurements 'must be disclosed to the Commission d'accès à l'information promptly and not later than 60 days before it is brought into service'. Biometric checks also need express consent plus notice in advance. The Commission can suspend or ban the database. It did exactly that to Metro Inc. in February 2025. Plan the notice before you sign the supplier contract, not after. TRAP 3. British Columbia's keep-it-in-Canada rule is gone. The old requirement that public bodies store personal information only in Canada was repealed in 2021 and is not in the current statute. What is left is a power to make regulations about disclosure outside Canada. Suppliers still selling 'British Columbia data must stay in Canada' as a legal fact are selling a repealed rule. The power sits there unused, so the rule could come back without a new law. TRAP 4. Nova Scotia's rule is about you, not just about government. It binds 'service providers contracted by these entities who handle personal information'. If you sell software to a Nova Scotia municipality, university or health authority, your storage and your support team's screen access must be in Canada. Fines reach 500,000 Canadian dollars (about 365,000 US dollars) for a corporation. They reach 25,000 Canadian dollars for an unincorporated business, and 2,000 Canadian dollars for an individual employee. TRAP 5. Canada has a quiet records-location rule in tax law. Income Tax Act section 230 requires records to be kept at a place of business or residence in Canada, unless the Minister names somewhere else. It is old, it is often ignored, and it is still on the books. TRAP 6. The national privacy regulator cannot fine you, which leads people to ignore it. Quebec's regulator can reach 4 per cent of worldwide turnover. Your risk is concentrated in the province with 23 per cent of the population.
Sources
- Official sourcePublications QuébecAct to establish a legal framework for information technology (Quebec), sections 44 and 45
legisquebec.gouv.qc.ca
“The creation of a database of biometric characteristics and measurements must be disclosed to the Commission d'accès à l'information promptly and not later than 60 days before it is brought into service.”
Link checked 18 August 2026
- Official sourceNova Scotia Department of JusticePIIDPA FAQ — application to service providers and penalties
novascotia.ca
Link checked 18 August 2026
- Official sourceKing's Printer, British ColumbiaFreedom of Information and Protection of Privacy Act (British Columbia) — current text, no storage-in-Canada section
bclaws.gov.bc.ca
Link checked 18 August 2026
- Official sourceDepartment of Justice CanadaIncome Tax Act, section 230 — records kept at a place of business in Canada
laws-lois.justice.gc.ca
“at the person's place of business or residence in Canada or at such other place as may designated by the Minister”
Link checked 18 August 2026
- Official sourceCommission d'accès à l'information du QuébecDécision interdisant à Metro Inc. de mettre en service une banque de caractéristiques biométriques (27 février 2025)
cai.gouv.qc.ca
Link checked 18 August 2026
What's changing next
One big bill and one big law already passed. The bill is Canada's third attempt to replace its 25-year-old privacy law. It would force a written risk assessment before any personal data goes outside Canada. It would give people a right to have data deleted. It would treat everyone under 18 as sensitive. And it would set up a new commissioner. It was only introduced in June 2026 and is not law. Do not plan around it as if it were. The law already passed is the cyber security act. It switches on in stages over the coming year.
LANDING IN THE NEXT 12 MONTHS - Bill C-36, the Protecting Privacy and Consumer Data Act. Introduced and given first reading on 15 June 2026. At second reading in the House of Commons as at 18 August 2026. Status: proposed, no legal effect. It would repeal Part 1 of PIPEDA. It would create a Privacy and Consumer Data Commissioner inside a new Digital Safety and Data Protection Commission of Canada. It would require a privacy impact assessment, and steps to reduce risk, before personal information is disclosed or transferred outside Canada. It would create a right to ask for personal information to be disposed of. And it would define a child as anyone under 18, with children's information treated as sensitive by default. Two earlier attempts, Bill C-11 and Bill C-27, both died before becoming law. Treat passage as uncertain. - Critical Cyber Systems Protection Act phase-in. Bill C-8 received royal assent in June 2026. The Telecommunications Act security amendments took effect immediately. The Critical Cyber Systems Protection Act itself is being brought in gradually. Its real duties do not apply until the designation and reporting regulations are made. Those duties are a cyber security programme within 90 days of designation, reducing supply-chain risk, reporting incidents inside 72 hours, and keeping records in Canada. Watch for those regulations. - Bill C-2, the Strong Borders Act, would widen police access powers over service providers. It has been stuck at second reading since September 2025. Status: proposed. POWERS ALREADY HELD, USABLE WITH NO CONSULTATION 1. The Superintendent of Financial Institutions can order a bank to stop keeping copies of records in another country. It can also order copies to be kept at any place in Canada. That applies where access is inadequate, or the Minister advises it is against the national interest. The bank 'shall without delay comply'. A single order can turn a global bank's data setup into a Canadian one. 2. British Columbia's minister can make regulations about disclosing personal information outside Canada. The power is in the statute. We could not confirm whether it has been used. 3. The amended Telecommunications Act lets the Governor in Council and the Minister direct telecommunications providers on security matters. That has been in force since royal assent. 4. Nova Scotia's Canada-only rule already lets the head of a public body allow exceptions. So the strictness can be adjusted either way by administrators.
Sources
- Official sourceParliament of CanadaBill C-36, An Act to enact the Protecting Privacy and Consumer Data Act (first reading, 15 June 2026)
parl.ca
Link checked 18 August 2026
- Official sourceParliament of CanadaLEGISinfo — Bill C-36 status: second reading, House of Commons
parl.ca
Link checked 18 August 2026
- Official sourcePublic Safety CanadaRoyal assent of Bill C-8 — phased implementation
canada.ca
“amendments to the Telecommunications Act take immediate effect upon Royal Assent. The Critical Cyber Systems Protection Act will be implemented gradually, with certain provisions coming into force through a phased approach.”
Link checked 18 August 2026
- Official sourceDepartment of Justice CanadaBank Act, section 245 — Superintendent's power over where records are kept
laws-lois.justice.gc.ca
“A bank shall without delay comply with any order issued under subsection (1) or (1.1).”
Link checked 18 August 2026
- Official sourceParliament of CanadaLEGISinfo — Bill C-2, Strong Borders Act: second reading
parl.ca
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Banking data needs a copy kept in the country
Official name: Guideline B-10 Third-Party Risk Management, read with Bank Act section 245 and the equivalent provisions of the Insurance Companies Act and Trust and Loan Companies Act · OSFI Guideline B-10 (2023); Bank Act, S.C. 1991, c. 46, s. 245 · Regulator guideline
Federally regulated banks and insurers must keep a complete, daily-current copy of their records on servers physically in Canada. Some institutions can be exempted if the supervisor gets immediate and continuous access to records held abroad. The Superintendent can also order a bank to pull records back into Canada at any time.
Enforced by Office of the Superintendent of Financial Institutions
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryComplete copies of statutory Records on computer servers physically located in Canada, accurate as at the end of each business day. Exempt institutions may hold records abroad only with immediate, direct, complete and ongoing access for the supervisor.
- Written vendor contractThird-party arrangements must preserve the supervisor's ability to examine the institution's business and affairs.
- Independent audit
- Secure the data
What it costs if you get it wrong
- Order to stopSupervisory direction; the Superintendent may order a bank to stop keeping record copies abroad or to keep copies at a place in Canada, and the bank must comply without delay
Sources
- Official sourceOffice of the Superintendent of Financial InstitutionsGuideline B-10: Third-Party Risk Management
osfi-bsif.gc.ca
“complete copies must be kept on a computer server(s) physically located at the places stipulated in the FRFI Statutes”
Link checked 18 August 2026
- Official sourceDepartment of Justice CanadaBank Act, section 245 — records
laws-lois.justice.gc.ca
“A bank shall without delay comply with any order issued under subsection (1) or (1.1).”
Link checked 18 August 2026
Cyber security rules
Official name: Critical Cyber Systems Protection Act, enacted by the Cyber Security Act (Bill C-8) · S.C. 2026, c. 9 · Act of parliament
A keep-it-in-Canada rule hiding inside a cyber security law. Operators of critical systems in banking, telecoms, energy and transport must keep their required records in Canada. They must run a cyber security programme. They must report incidents to the national cyber agency within 72 hours. The law is passed, but the duties do not apply until the government names who is covered.
Enforced by Communications Security Establishment / Canadian Centre for Cyber Security
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep the data in the countryRecords a designated operator must keep 'must be kept in Canada', at a place set by regulation. Not switched on yet. The regulations are still to be made.
- Report cyber incidents — within 72 hoursTo the Communications Security Establishment within a period set by regulation, not exceeding 72 hours; then immediately notify the sector regulator.
- Secure the dataEstablish a cyber security programme within 90 days of designation.
- Written vendor contractSupply-chain and third-party cyber risks must be mitigated as soon as identified.
- Keep records of how you use data
What it costs if you get it wrong
- Fixed maximum fine: CAD 10,000,000 (CAD 15,000,000 for a subsequent violation) — about $7 millionAdministrative monetary penalty against a corporation
- Fixed maximum fine: CAD 25,000 (CAD 50,000 for a subsequent violation) — about $18 thousandAdministrative monetary penalty against an individual
Sources
- Official sourceParliament of CanadaCyber Security Act / Critical Cyber Systems Protection Act (Bill C-8, as assented to)
parl.ca
“must be kept in Canada by the designated operator at any place that is prescribed by the regulations”
Link checked 18 August 2026
- Official sourcePublic Safety CanadaGovernment of Canada strengthens cyber security with royal assent of Bill C-8
canada.ca
“The Critical Cyber Systems Protection Act will be implemented gradually, with certain provisions coming into force through a phased approach.”
Link checked 18 August 2026
- Secondary sourceOsler, Hoskin & Harcourt LLPCanada's Bill C-8: what businesses need to know
osler.com
Payment data rules
Official name: Retail Payment Activities Act · S.C. 2021, c. 23, s. 177 · Act of parliament
Payment firms are supervised by the central bank, not the privacy regulator. There is no rule that payment data must stay in Canada. But a firm based abroad that targets Canadian users must register. It must name an agent inside Canada. And it must report a serious incident within 48 hours.
Enforced by Bank of Canada (Retail Payments Supervision)
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Register or notify — from 8 September 2025No retail payment activity may be performed before the Bank of Canada issues a registration decision.
- Appoint a representativeA foreign provider with no office in Canada must name an agent or mandatary in Canada to receive notices and orders.
- Report breaches to the regulator — within 48 hoursMaterial incidents: notify the Bank of Canada and affected end users without delay and no later than 48 hours.
- Tell affected people — within 48 hours
- Secure the dataYou must have a system for managing operational risk and for safeguarding end-user funds.
- Keep records of how you use dataAnnual report to the Bank of Canada by 31 March each year covering the prior calendar year.
What it costs if you get it wrong
- Loss of your licenceRefusal or revocation of registration; the Bank publishes enforcement decisions
- Fixed maximum fineAdministrative monetary penalties for violations of the Act
Sources
- Official sourceBank of CanadaFrequently asked questions about retail payments supervision
bankofcanada.ca
“After September 8, 2025, entities must be registered (i.e., receive a registration decision from the Bank) before performing any retail payment activities.”
Link checked 18 August 2026
- Official sourceBank of CanadaReminder: PSP reporting obligations under the RPAA
bankofcanada.ca
“without delay but no later than 48 hours”
Link checked 18 August 2026
- Official sourceDepartment of Justice CanadaRetail Payment Activities Act, section 18 — notice of incidents
laws-lois.justice.gc.ca
“the payment service provider must, without delay, notify that individual or entity and the Bank of the incident”
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: Personal Information Protection and Electronic Documents Act · S.C. 2000, c. 5 · Act of parliament
Canada's national private-sector privacy law. It does not limit where personal data is stored or handled. Instead you stay accountable for it. You must contract for comparable protection, and you must tell people the data may go abroad. The regulator cannot fine you. It makes findings, and the case must go to court for money.
Enforced by Office of the Privacy Commissioner of Canada
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Get consent
- Tell people what you doMust include that the information may be handled in another country, and may be accessed there by courts, law enforcement and national security authorities.
- Secure the data
- Written vendor contractUse a contract or other means giving a comparable level of protection. You stay accountable for the data.
- Let people see their data
- Let people correct their data
- Report breaches to the regulator — from 1 November 2018As soon as feasible. No fixed hour count.
- Tell affected people — from 1 November 2018
- Keep records of how you use data — 2 years, from 1 November 2018Record of every breach of security safeguards, reportable or not.
- Delete data after a periodKeep only as long as needed for the identified purpose, then destroy, erase or anonymise.
What it costs if you get it wrong
- Fixed maximum fine: CAD 100,000 — about $73 thousandKnowingly failing to report a breach, notify individuals or keep breach records; also obstructing an investigation
- Claims by individualsFederal Court application for damages after a Commissioner report
Sources
- Official sourceOffice of the Privacy Commissioner of CanadaPIPEDA requirements in brief
priv.gc.ca
Link checked 18 August 2026
- Official sourceOffice of the Privacy Commissioner of CanadaMandatory reporting of breaches of security safeguards
priv.gc.ca
“you keep breach records of all breaches of security safeguards for two years”
Link checked 18 August 2026
- Official sourceOffice of the Privacy Commissioner of CanadaGuidelines for processing personal data across borders
priv.gc.ca
Link checked 18 August 2026
Government data must stay in the country (Government)
Official name: Direction for Electronic Data Residency (ITPIN 2017-02), with the Policy on Service and Digital · Treasury Board of Canada Secretariat, Direction for Electronic Data Residency · Government policy document
If you sell cloud or software to the Canadian federal government, sensitive data has to stay on Canadian soil. Anything rated Protected B or higher must be stored in an approved facility inside Canada. This is a policy binding departments, so it reaches suppliers through procurement rather than through a fine.
Enforced by Treasury Board of Canada Secretariat
How this country controls where data goes: Not allowed · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryProtected B, Protected C and Classified electronic data must be stored in a government-approved computing facility inside Canada, or on Canadian government premises abroad.
- Prove the data stays under local controlOnly data up to and including Protected B may be deployed to a commercial public cloud at all.
- Secure the dataProtected B and above must be encrypted in transit outside government-controlled zones.
What it costs if you get it wrong
- Order to stopNon-compliant systems must be reported to the Treasury Board with a remediation plan; contracts can be refused or terminated
Sources
- Official sourceTreasury Board of Canada SecretariatDirection for Electronic Data Residency
canada.ca
“All sensitive electronic data under government control, that has been categorized as Protected B, Protected C or is Classified, will be stored in a GC-approved computing facility located within the geographic boundaries of Canada or within the premises of a GC department located abroad.”
Link checked 18 August 2026
- Official sourceGovernment of CanadaGovernment of Canada White Paper: Data Sovereignty and Public Cloud
canada.ca
“only data up to and including Protected B may be deployed to a public cloud”
Link checked 18 August 2026
General data protection law (Bill C-36, 45th Parliament, 1st Session)
Official name: Bill C-36, An Act to enact the Protecting Privacy and Consumer Data Act · Bill C-36, 45th Parliament, 1st Session · Draft law
A bill, not a law. If passed it would replace the private-sector half of Canada's privacy act. It would create a new Privacy and Consumer Data Commissioner. The big change is that it would require a written risk assessment before personal data goes outside Canada. Two earlier attempts at the same reform died before becoming law.
Enforced by Office of the Privacy Commissioner of Canada
How this country controls where data goes: Approval each time · Accepted routes: Standard contract clauses
What you have to do
- Assess high-risk projectsProposed: a privacy impact assessment and mitigation measures before personal information is disclosed or transferred outside Canada.
- Let people delete their dataProposed right to request disposal of personal information.
- Get a parent's consent for children — applies at: under 18Proposed: a child is anyone under 18, and children's information is sensitive by default.
- Written vendor contractProposed: service providers must give equivalent protection.
What it costs if you get it wrong
- Fixed maximum fineProposed administrative monetary penalties; amounts not verified from the bill text on this pass
Sources
- Official sourceParliament of CanadaBill C-36, Protecting Privacy and Consumer Data Act (first reading text)
parl.ca
Link checked 18 August 2026
Applies only in certain states4 rules
Made by a state or province. It only binds you for the people living there.
General data protection law (2023)
Official name: Loi sur la protection des renseignements personnels dans le secteur privé (as amended by Law 25) · CQLR c. P-39.1; amending Act S.Q. 2021, c. 25 · Act of parliament
Quebec is the strictest place in Canada for privacy, and the only one that can fine you. Before personal information leaves Quebec you must complete a written privacy impact assessment. It must show the data will be adequately protected. You must also sign a written agreement. This applies to sending data to Ontario or British Columbia too.
Enforced by Commission d'accès à l'information du Québec
How this country controls where data goes: Approval each time · Accepted routes: Standard contract clauses, Explicit consent
What you have to do
- Assess high-risk projects — from 22 September 2023Required before you send personal information anywhere outside Quebec, including to other Canadian provinces.
- Put a transfer safeguard in place — from 22 September 2023You need a written agreement. The transfer is allowed only if the assessment shows the data gets adequate protection.
- Appoint a data protection officerA named person in charge of protecting personal information, published; defaults to the most senior executive.
- Report breaches to the regulatorConfidentiality incidents with a risk of serious injury, reported with diligence; register of incidents required.
- Tell affected people
- Let people delete their data
- Let people take their data elsewhere — from 22 September 2024
- Limit automated decisions
- Delete data after a period
What it costs if you get it wrong
- Percentage of global turnover: 2% of worldwide turnover or CAD 10 million, whichever is greater — about $7 millionAdministrative monetary penalty for breaches including inadequate security or failing to report a confidentiality incident
- Percentage of global turnover: 4% of worldwide turnover or CAD 25 million, whichever is greater — about $18 millionPenal proceedings; amounts double on a repeat offence
Sources
- Official sourceCommission d'accès à l'information du QuébecCommunication de renseignements personnels hors Québec
cai.gouv.qc.ca
“avant de communiquer un renseignement personnel à l'extérieur du Québec, une organisation doit procéder à une évaluation des facteurs relatifs à la vie privée”
Link checked 18 August 2026
- Official sourceCommission d'accès à l'information du QuébecSanctions applicables aux entreprises privées
cai.gouv.qc.ca
Link checked 18 August 2026
Government data must stay in the country
Official name: Personal Information International Disclosure Protection Act · S.N.S. 2006, c. 3 · Act of parliament
Nova Scotia is strict. Personal information held by public bodies and municipalities must stay in Canada and be accessed only from Canada. It reaches private suppliers too. If you sell software to a Nova Scotia hospital, university or town hall, both the data and your support access must stay inside Canada.
Enforced by Nova Scotia Information Access and Privacy Services (Department of Justice)
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryStorage, access and disclosure must all be inside Canada. Remote support access from abroad counts as access.
- Written vendor contractBinds private service providers contracted by public bodies and municipalities.
- Do not hand data to foreign authorities on demandForeign demands for the information must be reported to the Minister of Justice.
What it costs if you get it wrong
- Fixed maximum fine: CAD 500,000 — about $365 thousandCorporation storing, accessing or disclosing personal information outside Canada without authority
- Fixed maximum fine: CAD 25,000 — about $18 thousandUnincorporated business
- Fixed maximum fine: CAD 2,000 — about $1 thousandIndividual employee
Sources
- Official sourceNova Scotia Department of Justice, Information Access and Privacy ServicesPersonal Information International Disclosure Protection Act — frequently asked questions
novascotia.ca
“Personal information held by public bodies and municipalities must remain in Canada, be accessed, and disclosed only in Canada, unless certain circumstances exist.”
Link checked 18 August 2026
General data protection law (Government)
Official name: Freedom of Information and Protection of Privacy Act (British Columbia), section 33.1 · R.S.B.C. 1996, c. 165 · Act of parliament
British Columbia used to require public bodies to keep personal information in Canada. That rule was repealed in 2021 and is no longer in the statute. Many compliance trackers still show it. What remains is a power for the minister to control disclosure outside Canada by regulation. That can be switched on without a new law.
Enforced by Office of the Information and Privacy Commissioner for British Columbia
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Put a transfer safeguard in placeDisclosure outside Canada is allowed only in accordance with any regulations the responsible minister makes.
- Assess high-risk projectsPublic bodies must complete privacy impact assessments for new or changed initiatives.
What it costs if you get it wrong
- Fixed maximum fineOffence provisions under the Act; enforcement is primarily by order of the Information and Privacy Commissioner
Sources
- Official sourceKing's Printer, British ColumbiaFreedom of Information and Protection of Privacy Act (British Columbia), sections 30 to 33.1
bclaws.gov.bc.ca
“A public body may disclose personal information outside of Canada only if the disclosure is in accordance with the regulations, if any, made by the minister.”
Link checked 18 August 2026
Health data rules
Official name: Personal Health Information Protection Act, 2004 · S.O. 2004, c. 3, Sch. A · Act of parliament
Ontario health data does not have to stay in Ontario or in Canada. The regulator says so itself. The health custodian stays fully responsible for the data. It must be satisfied that the safeguards travel with the data, usually through the contract.
Enforced by Information and Privacy Commissioner of Ontario
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Secure the dataThe custodian stays accountable and must be satisfied that administrative, physical and technical safeguards are in place, typically by contract.
- Written vendor contract
- Tell affected peopleNotify affected individuals at the first reasonable opportunity; an agent must notify the custodian at the first reasonable opportunity.
- Report breaches to the regulator
What it costs if you get it wrong
- Fixed maximum fine: CAD 200,000 for an individual; CAD 1,000,000 for an organisation — about $730 thousandOffence under the Act, on prosecution
- Claims by individuals
Sources
- Official sourceInformation and Privacy Commissioner of OntarioFrequently Asked Questions: Personal Health Information Protection Act
ipc.on.ca
“PHIPA does not require that personal health information be retained and stored in Ontario or Canada.”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Whether Quebec's private-sector privacy law gives individuals a minimum award of punitive damages (commonly reported as C$1,000) for unlawful infringement
We could not read the operative section. Quebec's official consolidated statute site returned a 502 server error on 18 August 2026. The Commission's own sanctions page describes administrative and criminal penalties, but not the private damages rule. We left it out of the record rather than assert it from a second-hand source.
Whether Bill C-8 received royal assent on 15 or 16 June 2026
Parliament's LEGISinfo page states Monday, 15 June 2026 (Statutes of Canada 2026, c. 9); the Public Safety Canada news release states 16 June 2026. Both are government sources and they disagree by one day. We have used 15 June 2026. Plan to the earlier date.
The exact classes of designated operators, sectors and regulators in Schedules 1 and 2 of the Critical Cyber Systems Protection Act, and when its obligations actually commence
We could not confirm the dates the law starts to apply. The schedules were not included in the part of the assented bill we retrieved, and no Public Safety Canada implementation page was reachable. We can evidence the four vital service areas of finance, telecommunications, energy and transportation from the government news release. We can evidence the 'records must be kept in Canada' wording and the 72-hour reporting deadline from the bill. The rule is marked partly in force at medium confidence.
Whether the British Columbia minister has actually made regulations under section 33.1 controlling disclosure of personal information outside Canada
We could not confirm whether the minister has made any regulations. The power in the statute is confirmed. Whether it has been used is not. Treat it as a power that could be switched on at any time.
Whether Newfoundland and Labrador still imposes a store-and-access-only-in-Canada rule on public bodies
We could not confirm that this rule exists. On 18 August 2026 we read the Access to Information and Protection of Privacy Act, 2015. We took it from the Newfoundland and Labrador House of Assembly site. We found no such section. We are not confident enough to say it is there, or that it is absent, so we created no rule. Check before you rely on this.
The maximum administrative monetary penalties proposed in Bill C-36
Professional commentary widely reports up to 25 million Canadian dollars or 5 per cent of global revenue. We could not find those numbers in the sections we retrieved from the first reading text. We left the figures out rather than source them to a law firm.
Whether PIPEDA reaches a foreign organisation with no Canadian presence at all, as distinct from one that operates in Canada
We could not verify the test for reaching companies with no office in Canada. The Commissioner's summary covers businesses that operate in Canada. The 'real and substantial connection' test comes from Federal Court case law that we did not check live. So question one is written around doing business with people in Canada.
Whether any securities regulator imposes a records-in-Canada requirement on registered dealers and advisers
We could not check whether any securities rule applies. The Ontario Securities Commission's page for its rule 31-103 returned a 403 error, and the search budget ran out before we found another official source. We created no securities rule. Do not read that as meaning there is no requirement.
Whether Alberta's Health Information Act restricts storage or disclosure of health information outside Alberta or Canada
The Alberta government overview page confirms custodian duties and breach notification but says nothing about geography. The King's Printer copy of the Act is blocked to automated readers. So we left Alberta health data out of the industry list rather than rate it.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.