All posts

PIPEDA and hosting: what the law actually requires

Ross Hill · September 11, 2026

"PIPEDA compliant hosting" is a phrase you will find on a lot of vendor pages, ours included. It is worth being precise about what it can and cannot mean, because the underlying law is narrower and stranger than most of that copy suggests.

PIPEDA does not require your data to stay in Canada. There is no data localization rule in the federal private-sector privacy law. What there is instead is an accountability rule, and accountability is a much more interesting thing to sell hosting against, because it is the part that stays with you no matter where you host.

This is not legal advice. It is a reading of the statute and the regulator's own guidance, with links so you can check both yourself.

What PIPEDA covers

The Personal Information Protection and Electronic Documents Act applies to every organization in respect of personal information it "collects, uses or discloses in the course of commercial activities". Commercial activity is defined broadly in the Act as any transaction, act, conduct, or regular course of conduct of a commercial character.

If you run a business that handles personal information about customers, users, or leads, you are almost certainly in scope. Company size is not a threshold.

The rule that is not there

Search for the localization requirement and you will not find one. The Office of the Privacy Commissioner of Canada is direct about this in its guidance on cross-border processing: "PIPEDA does not prohibit organizations in Canada from transferring personal information to an organization in another jurisdiction for processing".

The same guidance goes further, and takes a position on something that trips up a lot of privacy policies. A transfer to a service provider for processing is a use of the information, not a disclosure. Assuming the processing serves the purpose the information was originally collected for, you do not need fresh consent to move it to a processor. Hosting your database with a US provider is not, on its own, a PIPEDA violation.

So a page telling you that Canadian law requires Canadian servers has the law wrong. The real requirement is elsewhere.

The rule that is there: accountability

Schedule 1 of the Act sets out ten principles. The first is accountability, and its third clause is the one that governs hosting. Principle 4.1.3 reads: "An organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing. The organization shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party."

That is the whole hosting question. You hand data to a processor and you remain responsible for it. Whatever protection the information would have had if it never left, you have to reproduce, by contract or by some other means.

Comparable does not mean identical. It means the reader of your privacy program should not be able to point at the handoff and find the protection dropping off a cliff.

What the regulator's guidance adds

The OPC's guidelines for processing personal data across borders, published in January 2009, fill in the practical obligations that follow from that principle. Three of them matter when you are choosing where to host.

Assess the risk before you transfer. The guidance says organizations should assess the risks to the integrity, security, and confidentiality of customer information when it is transferred to a service provider operating outside Canada. That assessment is yours to do and yours to be able to show.

Tell people. Organizations should advise customers, in clear and understandable language, that their information may be sent to another jurisdiction for processing, and that while it is there it may be accessed by the courts, law enforcement, and national security authorities of that jurisdiction. Ideally you say this at the point of collection. In practice it belongs in your privacy policy, written plainly enough that a customer understands the exposure rather than being technically informed of it.

Understand what a contract can and cannot do. This is the sharpest line in the guidance, and the one to keep in view when a data processing agreement looks like it closes the question: no contract can override the criminal, national security, or any other laws of the country to which the information has been transferred.

That last point is where the accountability principle stops being paperwork and starts being an infrastructure decision.

The question this actually leaves you with

Put the pieces together and foreign hosting is allowed. What a Canadian business has to work out is whether it can carry the accountability that comes with it, and whether it wants to.

Carrying it means documenting the risk assessment for the jurisdiction you picked, holding a contract that provides comparable protection, telling your customers their data can be reached by another country's authorities, and being ready to explain all of that when a client's security review or a regulator asks. The exposure you are documenting is real and specific: for US-jurisdiction providers, the CLOUD Act lets US courts compel an American company to produce data it controls regardless of which country the server sits in. Your contract does not reach that, for exactly the reason the OPC states.

None of this is unmanageable. Plenty of Canadian businesses do it, deliberately and well. It is standing work, and it grows every time you add a processor.

Where Canadian hosting helps, and where it does not

Keeping application data on Canadian infrastructure does not make you PIPEDA compliant. Nothing about your hosting can do that, because most of PIPEDA is about consent, purposes, retention, access requests, and safeguards inside your own application.

What Canadian hosting does is shorten the accountability story for one link in the chain. There is no foreign jurisdiction to assess for that data, no foreign-authority access to disclose in your privacy policy for it, and no gap between what your contract promises and what a foreign court can order. You are not exempt from Principle 4.1.3. You just have a much easier time satisfying it, and a much shorter document to hand over when someone asks.

The reason matters. You are choosing Canadian hosting because you decided jurisdiction is worth controlling, not because the law removed the choice. That is a weaker legal argument and a more durable one.

What you can get from us in writing

Because the obligation is documentary, the useful question to ask a host is what they will put in writing. For MapleDeploy, that is:

If your client's review needs something those pages do not cover, email us and we will answer directly. We wrote up the full set of documents worth requesting from any provider, not just us, in proof of Canadian data residency: what to ask for.

The provincial layer

PIPEDA is the federal floor, not the whole picture. Alberta, British Columbia, and Quebec each have general private-sector privacy laws that have been deemed substantially similar to PIPEDA, which means PIPEDA generally steps back for organizations operating wholly inside those provinces, though it still applies when personal information crosses a provincial or national border, and to federally regulated works and undertakings such as banks and telecoms wherever they operate.

Quebec's is the one that changes the hosting analysis most, because it turns the cross-border question from a documented assessment into a conditional gate. We covered that separately in Quebec's Law 25 and Canadian data residency.

One federal obligation is worth flagging because no host takes it off you. Under section 10.1, if it is reasonable in the circumstances to believe that a breach of security safeguards creates a real risk of significant harm to an individual, you must report it to the Privacy Commissioner and notify the affected individuals. That duty follows the personal information under your control, wherever it happens to be stored.

Canadian infrastructure, documented

Dedicated VMs in Toronto, with the residency paperwork published rather than promised. 30 days free on Starter and Pro.