Skip to content

Resources/Canadian data sovereignty

Does the US CLOUD Act reach your clients' files?

Reviewed

If you handle other people's documents for a living, you have probably been asked some version of "where does this actually go?" The honest answer is more interesting than a datacentre address. What decides who can compel a copy of your client's file is not the country the server sits in - it is who owns the company holding it.

What the CLOUD Act actually does

The Clarifying Lawful Overseas Use of Data Act, passed in the United States in 2018, settled a question that had been fought over in court: can US authorities compel a US provider to produce data the provider stores abroad? The answer it gave was yes. A provider subject to US jurisdiction can be served with lawful process for data in its possession, custody, or control, wherever in the world that data physically lives.

The order is served on the company, not on the building. That is the part most "our servers are in Canada" marketing pages quietly skip.

Residency is not sovereignty

Data residency means the bytes sit inside a particular country. Almost every large cloud vendor sells this: pick a Canadian region, and your files are stored in Canada. It is a real property and it matters for latency, for some contractual terms, and for a subset of procurement rules.

Data sovereignty is the stronger claim: the entity holding the data answers to that country's legal system and no other. A US-owned provider with a Toronto datacentre gives you residency. It does not give you sovereignty, because the provider is still a US company that can be served in the United States.

Neither arrangement puts data beyond all legal reach, and any vendor telling you otherwise is overselling. What changes is which government's process applies by default, and how many hops away the other one is.

Why Canadian professionals in particular ask

PIPEDA does not ban storing personal information outside Canada, but it does make you accountable for it: an organization transferring personal information to a third party for processing remains responsible for that information, and must be transparent with clients about the possibility of foreign access. Quebec's Law 25 goes further, requiring a privacy impact assessment before personal information is communicated outside Quebec. Public-sector rules add another layer in some provinces: Nova Scotia still restricts storage outside Canada, while British Columbia relaxed its long-standing in-Canada storage rule in 2021 and now leans on assessment and safeguards instead.

None of this makes a US tool illegal to use. It does mean that if a client asks you whether a foreign government could obtain their file, "it is stored in Canada" is not a complete answer, and a privacy officer will know that.

Questions worth asking a vendor

Who owns and operates the company that holds the data, and in what country is it incorporated? Which company owns and operates the physical servers - the vendor, or a hyperscaler they resell? Where do backups live, and under whose control? Which subprocessors touch the data, and where are they? Does anything leave the country in transit, including notification email?

The last one is the question most vendors, including honest ones, have the messiest answer to. Email routinely traverses providers in other jurisdictions even when file storage does not. A vendor that volunteers this distinction is usually being straight with you about the rest.

How this service answers those questions

The application, the database, and every uploaded file run on servers owned and operated by a Canadian hosting company, on Canadian soil, for a Canadian company. There is no US-owned provider in the custody chain of your clients' files, so there is no US provider to serve with a CLOUD Act order for them. Files are subject to Canadian legal process.

The exception, stated plainly: notification email is currently relayed through a provider outside Canada. Those messages carry a secure link, not file contents, and are protected by TLS in transit - but until that relay moves, the sovereignty claim is about your files and your data, not about every byte of email metadata.

And the caveat that applies to everyone: Canadian courts can compel production, and governments cooperate through treaty channels. No provider is exempt from legal process. The choice you get to make is whose process, and whether a second country's applies by default.

General information about how these rules work, not legal advice. The obligations that apply to your practice depend on your province, your regulator, and the information you hold.

Related reading

Ready to try it on your next intake? See how it works.

Does the US CLOUD Act reach your clients' files? - ReceiveVault