Canadian data residency for SaaS: what the law actually requires

For most Canadian SaaS companies, no statute requires personal information to be stored in Canada. Federal law permits transfers abroad and makes you accountable for them, BC removed its public-sector residency rule in 2021, and Quebec requires an assessment before information leaves the province. The residency requirements that do bind you usually arrive in a customer’s contract.

Does Canadian law require data to stay in Canada?

InstrumentResidency rule?What it does require
PIPEDA (private sector, federal)NoAccountability for transferred information, comparable protection by contract, openness about transfers
BC FIPPA (public bodies)Not since 2021Disclosure outside Canada only in accordance with the regulations; a privacy impact assessment for sensitive information stored abroad
Quebec (Law 25)No banA privacy impact assessment and a written agreement before information leaves Quebec
Alberta PIPA (private sector, Alberta)NoNotice to individuals, before or at the time of collection or transfer, when a service provider outside Canada is used (s. 13.1)
Nova Scotia PIIDPA (public bodies)Yes, with exceptionsStorage and access in Canada for public bodies and their service providers

The table reflects each instrument as of September 2026.

Does PIPEDA require Canadian hosting?

No. PIPEDA does not prohibit transferring personal information outside Canada for processing. It holds the transferring organization accountable for that information, mainly through contract, and expects it to be open about the transfer. The regulator sets this out in its guidelines for processing personal data across borders. The same guidance makes the hard point plainly: no contract can override the laws of the country the information goes to, so the risk assessment is yours to make.

In practice that means a data processing agreement with each processor, a record of where data is stored and who can reach it, and a privacy notice that says information may be processed outside Canada.

Do BC public bodies still require data to stay in Canada?

Not since November 2021, when amendments to FIPPA removed the rule that personal information be stored and accessed only in Canada. Public bodies must now assess, in a privacy impact assessment, each new program, project or system in which sensitive personal information is disclosed to be stored outside Canada. Section 33.1 of the Freedom of Information and Protection of Privacy Act now permits disclosure outside Canada only if it is in accordance with the regulations, and B.C. Reg. 294/2021 requires the added assessment.

For a vendor, this changes the sales conversation rather than removing it. Expect the buyer’s privacy office to ask where data is stored, who can access it from where, and what protects it, and expect those answers to go into their PIA. Our FIPPA PIA and ISA work prepares both sides of that; security for BC public sector vendors covers the rest.

What does Quebec require before data leaves the province?

Quebec does not ban transfers, but before communicating personal information outside Quebec an organization must complete a privacy impact assessment showing the information would receive adequate protection, and put the transfer under a written agreement. The Commission d’accès à l’information summarizes the rule, in force since September 2023. The detail most SaaS teams miss is the boundary: it is the province, not the country, so a Toronto data centre is a transfer too. More on this in Quebec Law 25 for companies outside Quebec.

Where does a residency requirement still apply?

Why do customers still ask for Canadian hosting? Usually because of a contract, not a statute. Public-sector buyers, health organizations and financial institutions often write residency into procurement terms, and a few provincial laws, such as Nova Scotia’s, still require it for public bodies and their service providers. Nova Scotia’s Personal Information International Disclosure Protection Act is the clearest example: storage and access in Canada, subject to consent and the exceptions the Act sets out.

Read “accessed” carefully wherever it appears. A Canadian region does not satisfy a residency clause if support staff abroad can reach production data.

What should a SaaS company do first about data residency?

  • Map where each category of data is stored, backed up and accessed from, including subprocessors and support.
  • Read your customer contracts for residency clauses before your architecture decides for you.
  • If you sell into Quebec, complete the transfer assessment and agreements now.
  • Offer a Canadian region where a contract requires one; do not rebuild everything for a rule that does not exist.

Which instrument applies to you is a question for counsel. The wider map is in the Canadian privacy law map, and the program work is Canadian privacy readiness.

How the work is bounded

The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.

SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.

Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.

Questions we are asked

Does PIPEDA require data to be stored in Canada?

No. PIPEDA does not prohibit transferring personal information outside Canada for processing. It holds the transferring organization accountable for that information, mainly through contract, and expects it to be open about the transfer.

Do BC public bodies still require data to stay in Canada?

Not since November 2021, when amendments to FIPPA removed the rule that personal information be stored and accessed only in Canada. Public bodies must now assess, in a privacy impact assessment, each new program, project or system in which sensitive personal information is disclosed to be stored outside Canada.

What does Quebec require before data leaves the province?

Quebec does not ban transfers, but before communicating personal information outside Quebec an organization must complete a privacy impact assessment showing the information would receive adequate protection, and put the transfer under a written agreement.

Why do customers still ask for Canadian hosting?

Usually because of a contract, not a statute. Public-sector buyers, health organizations and financial institutions often write residency into procurement terms, and a few provincial laws, such as Nova Scotia’s, still require it for public bodies and their service providers.

Answering the residency question

Send us the clause or questionnaire that raised it and a sketch of where your data lives. The reply maps where your data is stored and accessed against what the clause asks for, so your counsel can confirm which parts are legal requirements and which are only contractual. More of our writing is indexed at writing.

Discuss a scope