Resources/Canadian data sovereignty
Does the US CLOUD Act reach your clients' files?
Reviewed
If you handle other people's documents for a living, you have probably been asked some version of "where does this actually go?" The honest answer is more interesting than a datacentre address. What decides who can compel a copy of your client's file is not the country the server sits in - it is who owns the company holding it.
What the CLOUD Act actually does
The Clarifying Lawful Overseas Use of Data Act, passed in the United States in 2018, settled a question that had been fought over in court: can US authorities compel a US provider to produce data the provider stores abroad? The answer it gave was yes. A provider subject to US jurisdiction can be served with lawful process for data in its possession, custody, or control, wherever in the world that data physically lives.
The order is served on the company, not on the building. That is the part most "our servers are in Canada" marketing pages quietly skip.
Residency is not sovereignty
Data residency means the bytes sit inside a particular country. Almost every large cloud vendor sells this: pick a Canadian region, and your files are stored in Canada. It is a real property and it matters for latency, for some contractual terms, and for a subset of procurement rules.
Data sovereignty is the stronger claim: the entity holding the data answers to that country's legal system and no other. A US-owned provider with a Toronto datacentre gives you residency. It does not give you sovereignty, because the provider is still a US company that can be served in the United States.
Neither arrangement puts data beyond all legal reach, and any vendor telling you otherwise is overselling. What changes is which government's process applies by default, and how many hops away the other one is.
Why Canadian professionals in particular ask
PIPEDA does not ban storing personal information outside Canada, but it does make you accountable for it: an organization transferring personal information to a third party for processing remains responsible for that information, and must be transparent with clients about the possibility of foreign access. Quebec's Law 25 goes further, requiring a privacy impact assessment before personal information is communicated outside Quebec. Public-sector rules add another layer in some provinces: Nova Scotia still restricts storage outside Canada, while British Columbia relaxed its long-standing in-Canada storage rule in 2021 and now leans on assessment and safeguards instead.
None of this makes a US tool illegal to use. It does mean that if a client asks you whether a foreign government could obtain their file, "it is stored in Canada" is not a complete answer, and a privacy officer will know that.
Questions worth asking a vendor
Who owns and operates the company that holds the data, and in what country is it incorporated? Which company owns and operates the physical servers - the vendor, or a hyperscaler they resell? Where do backups live, and under whose control? Which subprocessors touch the data, and where are they? Does anything leave the country in transit, including notification email?
The last one is the question most vendors, including honest ones, have the messiest answer to. Email routinely traverses providers in other jurisdictions even when file storage does not. A vendor that volunteers this distinction is usually being straight with you about the rest.
How this service answers those questions
The application, the database, and every uploaded file run on servers owned and operated by a Canadian hosting company, on Canadian soil, for a Canadian company. There is no US-owned provider in the custody chain of your clients' files, so there is no US provider to serve with a CLOUD Act order for them. Files are subject to Canadian legal process.
The exception, stated plainly: notification email is currently relayed through a provider outside Canada. Those messages carry a secure link, not file contents, and are protected by TLS in transit - but until that relay moves, the sovereignty claim is about your files and your data, not about every byte of email metadata.
And the caveat that applies to everyone: Canadian courts can compel production, and governments cooperate through treaty channels. No provider is exempt from legal process. The choice you get to make is whose process, and whether a second country's applies by default.
General information about how these rules work, not legal advice. The obligations that apply to your practice depend on your province, your regulator, and the information you hold.
Related reading
- Is Dropbox PIPEDA compliant?
PIPEDA does not certify software, so no tool can hand you compliance. Here is what the law actually asks of you when you put client documents in a US-owned cloud, and what to check before you do.
- Quebec Law 25 and storing client files outside Quebec
Law 25 does not ban sending personal information out of the province, but since 2023 it does require an assessment first. Here is what triggers it and what the assessment involves.
- Law society guidance on storing client files in the cloud
Canadian law societies permit cloud storage and have for years. What they ask for is due diligence, and the jurisdiction question is where privilege makes a lawyer's analysis different from everyone else's.
- Twelve questions to ask a vendor about where your data lives
A due-diligence checklist you can paste into an email. The answers separate vendors who have thought about jurisdiction from vendors who have a Canadian flag on the pricing page.
Ready to try it on your next intake? See how it works.