Data residency statements for Canada
Where is our data stored is the first question Canadian public sector, finance and health buyers ask. The answer has more parts than the region name.
A data residency statement Canadian buyers accept names the cloud regions that hold production data and backups, says whether any personal information leaves Canada in normal operation, and says who outside Canada can access it, such as support staff or subprocessors. "Hosted in Canada" alone does not answer the question, because backups, logs, email, support tooling and AI features often run elsewhere.
What does a complete residency statement cover?
| Part | Example |
|---|---|
| Primary storage | Customer data is stored in AWS ca-central-1 (Montreal). |
| Backups and disaster recovery | Encrypted backups are kept in ca-west-1 (Calgary). |
| Processing outside Canada | Transactional email is sent through a US-based provider; message content includes names and email addresses. |
| Support and operations access | Support staff in Canada and the United States can access customer data for troubleshooting, with access logged. |
| Subprocessors | See the dated subprocessor list for each vendor's location. |
| AI features | Optional AI features send the text a user submits to a model provider in the United States; they are off by default. |
Which Canadian cloud regions exist?
AWS runs Canada (Central) in Montreal and Canada West in Calgary. Microsoft Azure runs Canada Central in Toronto and Canada East in Quebec City. Google Cloud runs northamerica-northeast1 in Montreal and northamerica-northeast2 in Toronto. Using two Canadian regions keeps backups in the country. Architecture detail is on CloudCompliance, a sister site in this network.
Why do Canadian buyers care?
Some public bodies have rules or policies on storing personal information outside Canada, notably in British Columbia and Nova Scotia. Quebec's Law 25 requires an assessment before personal information leaves Quebec. Financial institutions assess data location under OSFI's third-party risk guideline. Health buyers look at provincial health privacy law. Bill C-36, if passed, would require assessing transfers outside Canada. Each of these turns into the same question to you.
Common questions
Is "hosted in Canada" enough?
Rarely. Reviewers ask next about backups, support access, email, logging and subprocessors. Answer them in the statement and the follow-up questionnaire gets shorter.
Does US ownership of our cloud provider matter?
Some buyers ask about foreign legal access to data held by US-owned providers even in Canadian regions. State the facts plainly, including encryption and key management, and let the buyer assess the risk.