Geoffrey Blanc, General Manager, Cyberimpact, says Canadian organisations are increasingly discovering that data residency alone does not guarantee compliance, sovereignty or protection from foreign legal access requests.
Every year I sit across from procurement teams who have done their homework. They have reviewed vendor documentation, confirmed data residency and verified that servers are on Canadian soil. The box is checked. Everyone moves forward feeling confident.
Then someone asks who governs that data if a foreign authority comes knocking. The silence that follows is recognition. The checklist gave them answers, but it never asked the question that mattered.
Data residency and data governance are two different things. Most organisations in healthcare, education and government are operating under Canadian privacy law while running communication infrastructure that does not fully answer to it. That gap has always existed. What has changed is how often it surfaces and how much it costs when it does. Jurisdictional scrutiny across regulated sectors has tightened considerably over the past few years and the organisations that built their vendor decisions on residency alone are starting to feel it in procurement cycles, audit findings and conversations with boards that want clearer answers than they are getting.
The legal mechanism most vendors do not explain
Under the US Cloud Act and the Patriot Act, American authorities can compel an American-owned company to produce data regardless of where that data physically sits. Server location is irrelevant. What matters is who owns and controls the platform.
A vendor can truthfully say your data is stored in Canada while being fully subject to American legal authority. Both statements can be true at the same time. Neither one typically appears on a standard vendor evaluation form.
The infrastructure and the governance are separate questions. A server in a Canadian data centre does not change which legal system governs the company that operates it. A Canadian mailing address on the vendor’s website does not change it either. The legal exposure follows ownership and corporate structure, not geography.
For organisations operating under PIPEDA or Quebec’s Law 25, that creates a direct conflict between the governance structure they believe they have and the one that actually applies. Lawful access requests are handled at the vendor level under US law. The Canadian organisation is rarely notified. By the time anyone on the Canadian side becomes aware that a request was made, the data has already moved.
I raise this because the technology leaders I work with are careful people. They use evaluation frameworks that were written before these questions became operationally urgent. The gap persists for structural reasons, not careless ones. That is actually what makes it worth paying attention to.
Three moments where this becomes real
Procurement is the first. A public institution issues an RFP for a communication platform. The language asks whether data is hosted in Canada. The vendor confirms it. Nobody asks who owns the parent company, what sub-processors are involved or what legal obligations the vendor carries across jurisdictions. The contract is signed. The exposure comes with it, quietly embedded in the terms nobody interrogated.
What makes this pattern hard to break is that the vendor is answering the question honestly. The problem is the question itself. Procurement language that stops at residency gives buyers a false sense of security that the vendor has no obligation to correct.
Privacy impact assessments are the second moment. Regulated organisations are increasingly required to conduct these before deploying new tools. When the assessment is done properly, ownership and jurisdiction questions surface. Teams discover that a platform they have been running for two years creates exposure nobody had mapped. Unwinding that mid-contract is expensive and operationally disruptive in ways that tend to land on the CIO’s desk at the worst possible time, usually when something else is already demanding attention.
Incident response is the third. When something goes wrong, regulators and boards ask the same question: where was the data and who had access to it? Organisations with clear answers to that question recover differently than those piecing together their vendor’s governance structure in the middle of a crisis. The ones who struggle are rarely the ones who made reckless decisions. They are the ones who made reasonable decisions with incomplete information.
What better due diligence actually looks like
The standard checklist needs to go further than server location. A few things worth building into the next vendor review.
Ownership structure matters as much as server location. Where is the vendor incorporated and who owns the parent company? A Canadian-branded platform with a US parent is a different legal animal than a Canadian-owned platform. That distinction is what determines which legal system applies when things get complicated. It is also the question vendors are least likely to address proactively, which is a reason to ask it directly.
Ask for a real sub-processor list. The marketing summary page is not enough. You want a documented list of which third parties touch your data and where they are based. Data moves through multiple points in its lifecycle and each one carries its own jurisdictional exposure. A platform that keeps its primary servers in Canada but routes data through a US-based analytics or authentication provider has already crossed the border in ways that matter legally.
Key control is worth understanding. Sovereignty often comes down to access rather than storage. If the vendor holds the encryption keys and the vendor answers to foreign law, the practical protection is weaker than it looks on paper. Ask specifically who holds administrative access to your data, how that access is logged and what audit trail exists if something goes wrong.
Ask what the vendor does when a government access request arrives. Is there a documented process? Do they commit to notifying affected customers where legally permitted? Do they push back on requests that exceed their legal obligations or do they comply quietly to protect their own interests? Vague answers here are informative in their own way.
Independent assurance matters. SOC 2 Type II certification and current audit results are evidence that governance practices have been tested by someone outside the organisation. Ask for the actual reports, not a badge on a webpage. The difference between a vendor who can produce current documentation and one who points you to a trust page tells you something about how seriously they treat this internally.
A communication platform handles citizen data, patient records, student information and constituent communications. The governance behind it should match the accountability your organisation already carries.
Why this has moved up the agenda
Quebec’s Law 25 introduced requirements around privacy impact assessments, consent and data governance that sharpened expectations considerably. Federal privacy legislation has been in active discussion for years. These shifts are moving jurisdiction questions out of legal departments and into board conversations, procurement reviews and audit findings. The organisations that treated this as a legal abstraction are finding it has operational consequences.
CIOs sit at the intersection of that accountability and the technical decisions that determine whether the organisation can actually meet it. The reputational exposure from a poorly governed communication platform is real and it lands differently than a data breach in a core system, partly because email and citizen communications feel so routine that nobody imagines they require the same level of scrutiny.
The organisations that handle this well tend to have something in common. They asked the uncomfortable questions before circumstances forced the issue. They built governance into the vendor selection process rather than discovering the gaps during an audit or an incident.
At the next vendor review, the question worth asking goes beyond where data is stored. The real question is who governs it, under which laws and what happens when those laws conflict with the obligations your organisation already carries.
You do not need outside counsel to ask it, you just need someone in the room who’s willing to.

