Skip to content

Resources/Canadian data sovereignty

Is Dropbox PIPEDA compliant?

Reviewed

It is the question every Canadian professional eventually types into a search bar, usually with a different product name in it: Dropbox, Google Drive, OneDrive, WeTransfer. The honest answer is that the question is slightly the wrong shape, and understanding why tells you more than a yes or a no would.

The short answer: PIPEDA regulates you, not the tool

PIPEDA applies to organizations that collect, use, or disclose personal information in the course of commercial activity. It does not certify software, and there is no government list of approved products. A vendor can be built well or badly, but it cannot be compliant on your behalf, and any vendor claiming to make you compliant is selling you something the law does not offer.

So the question worth asking is narrower: if I use this tool for client documents, can I still meet my own obligations? For the mainstream file-sync services the answer is usually yes with work, sometimes no, and it depends far more on how you use them than on the logo.

What the accountability principle actually requires

PIPEDA's first principle is accountability, and it does not stop at your own door. When you hand personal information to a third party for processing, you remain responsible for it, and you are expected to use contractual or other means to provide a comparable level of protection while it is in their hands.

The Privacy Commissioner's long-standing position is that a transfer for processing is a use of the information, not a disclosure, so you do not need fresh consent to put client files in a cloud tool. What you do need is transparency: your privacy policy should make clear that information may be processed by service providers, and that it may be stored in or accessible from outside Canada, where foreign courts and agencies may be able to obtain it.

That transparency obligation is the part most small firms miss. It is not onerous. It is a paragraph. But if a client asks where their file went and the honest answer is not in your privacy policy, that is the gap.

Where the US-owned part changes the picture

Dropbox, Google, Microsoft, and the rest of the large file tools are US-incorporated companies. Several of them let you choose where files are stored, and a Canadian or regional option is a genuine feature worth having. But storage location and legal reach are different things: a US company can be served with US legal process for data in its possession, custody, or control regardless of which datacentre holds the bytes.

That does not make those tools unlawful for you to use, and it does not mean anyone is reading your files. It means that a claim like "stored in Canada" answers a question about geography, not about jurisdiction, and a privacy officer or opposing counsel will know the difference.

The mismatch that matters more day to day

Set the jurisdiction question aside for a moment, because there is a plainer problem. Consumer file-sync tools are built to share a folder you already have. Collecting documents from a client is the opposite motion, and the tools show it: you end up emailing an upload link, or worse, a link to a folder that other people can also see.

Ask what the tool gives you for the things that matter in an intake: a per-client checklist, a link that expires, a record of exactly what arrived and when, malware scanning on the way in, and a deletion schedule you do not have to remember. Sync tools were not built for that, so those controls are either bolted on, tied to an expensive tier, or absent.

There is also the copy problem. Anything in a synced folder is on every device that folder syncs to, including a laptop that leaves the office. That is not a privacy-law argument, it is a practical one, and it is usually the one that changes people's minds.

A short due-diligence list before you commit

  1. Who owns the company, and in which country is it incorporated?
  2. Where are files stored, and separately, where are backups stored?
  3. Which subprocessors touch the data?
  4. Is there a data processing agreement you can actually sign?
  5. What is the breach notification commitment, and on what timeline?
  6. Can you get a complete export, and a verified deletion?
  7. Is there an audit log you can show a client or a regulator?

If a vendor answers those seven questions clearly and in writing, they are a serious vendor whether or not they are Canadian. If they cannot, the flag colour does not matter.

General information about how these rules work, not legal advice. The obligations that apply to your practice depend on your province, your regulator, and the information you hold.

Related reading

Ready to try it on your next intake? See how it works.

Is Dropbox PIPEDA compliant? - ReceiveVault