Section 17 is the provision of Quebec's private-sector privacy act that governs personal information leaving the province, and it says three things. Before you communicate personal information outside Quebec, you must conduct a privacy impact assessment. You may proceed only if that assessment establishes the information would receive adequate protection. The communication must then be covered by a written agreement that reflects what the assessment found. That wording has been in force since September 22, 2023.
"Outside Quebec" means outside the province, not outside the country. A server in Toronto is outside Quebec in the same way a server in Virginia is. Section 17 applies to both.
This is not legal advice. If your organization has significant Quebec operations, or you are unsure whether a particular transfer clears the adequacy bar, consult a Quebec privacy lawyer.
What section 17 requires
The statute is the Act respecting the protection of personal information in the private sector (P-39.1), which Law 25 amended. Section 17 has four working parts.
The assessment. Before communicating personal information outside Quebec, an enterprise must conduct a privacy impact assessment that takes into account, "in particular":
- the sensitivity of the information
- the purposes for which it is to be used
- the protection measures, including contractual ones, that would apply to it
- the legal framework applicable in the State where the information would be communicated, including the personal information protection principles applicable there
"In particular" is doing work in that sentence. The four factors are a floor, not a closed list.
The gate. The information may be communicated "if the assessment establishes that it would receive adequate protection, in particular in light of generally recognized principles regarding the protection of personal information". An assessment that cannot reach that conclusion is not a risk to note and accept. It describes a transfer you are not permitted to make.
The written agreement. The communication "must be the subject of a written agreement" that takes into account the results of the assessment and, where applicable, the terms agreed on to mitigate the risks it identified. Running the assessment and skipping the contract does not satisfy the section.
Outsourcing counts. The third paragraph applies all of the above where an enterprise "entrusts a person or body outside Québec with the task of collecting, using, communicating or keeping" personal information on its behalf. That sentence is the one that catches hosting, managed databases, backup storage, email delivery, analytics, error tracking, and support tooling.
Section 17 has one carve-out. It does not apply to a communication made under section 18, paragraph 7, where information must be communicated because of the urgency of a situation that threatens a person's life, health, or safety.
Outside Quebec includes the rest of Canada
The Commission d'accès à l'information (CAI), Quebec's privacy regulator, states the obligation directly on its guidance for businesses, which is published in French only. It applies before communicating personal information to an entity located outside Quebec, interprovincially as well as internationally, and before entrusting such information to a person or body outside Quebec. An Ontario provider storing data in Ontario is a section 17 transfer. So is a British Columbia one.
The drafting is awkward on this point, and it is worth knowing why. The fourth factor asks about the legal framework "in the State" where the information would be communicated, which reads like a country rather than a province. The trigger in the first paragraph is plainly "outside Québec", and the regulator reads it to cover interprovincial transfers, so that is the working answer. Applied to another province, the fourth factor becomes a question about PIPEDA and provincial law rather than about a foreign legal system, which is a far shorter analysis.
What section 17 does not say
It does not mention consent. The CAI's guidance page lists informing and obtaining consent alongside the assessment, which is broader than the section's own text. The transparency duty comes from section 8, which requires you to tell people at collection about the possibility that their information could be communicated outside Quebec. The consent rules come from sections 12 through 14, and section 18.3 permits communication to a service provider without consent where the information is necessary to perform the contract. Read those together rather than treating section 17 as a consent trigger on its own.
How much assessment is enough
The Act answers this directly. A privacy impact assessment "must be proportionate to the sensitivity of the information concerned, the purposes for which it is to be used, the quantity and distribution of the information and the medium on which it is stored" (section 3.3). A mailing list and a customer profile database do not get the same document.
There is no Quebec adequacy list. The EU publishes adequacy decisions that organizations can rely on. Law 25 instead leaves the determination with the enterprise making the transfer, measured against generally recognized principles, and the CAI can ask to see the reasoning afterwards. The CAI publishes a guide to conducting an assessment (French only).
What Canadian hosting changes, and what it does not
Canadian hosting does not discharge a section 17 obligation for a Quebec enterprise. If the server is in Toronto, the information has left the province, and the assessment and the written agreement are both still owed. Canadian data residency is not Law 25 compliance, and nobody should sell it to you as though it were.
What it changes is the content of the assessment, not whether you do one. The third factor gets easier, because you are contracting with a Canadian company under Canadian law. The fourth gets much shorter, because the destination is a PIPEDA jurisdiction rather than a foreign legal system you have to research and defend. Move the same data to US infrastructure and that fourth factor has to address the CLOUD Act, which is a substantially harder paragraph to write.
The only way to have no section 17 transfer at all is to keep the information in Quebec with a provider in Quebec. MapleDeploy's servers are in Toronto, so that is not what we sell. What we offer is the short version of the assessment instead of the long one.
Where MapleDeploy fits
MapleDeploy runs dedicated Canadian infrastructure in Toronto. Each customer gets an isolated VM and their own Coolify instance. Application data, databases, and server configurations stay in Canada.
For the assessment you have to write, the facts are published rather than available on request. Our data residency attestation names the infrastructure provider, its corporate jurisdiction, and the data controls in place. Our sub-processor list names every third party we use, what it handles, and where it sits. We run our own section 17 assessment for the interprovincial transfer to our infrastructure provider. The agreement your own assessment needs, though, is the one between you and us, and it is worth being direct about what that is: MapleDeploy does not currently offer a separate data processing agreement, so our terms of service are the written contract on offer. If your assessment concludes you need terms beyond them, settle that before you build on us.
One scoping point, because section 17's first factor is sensitivity. Our terms prohibit health and medical information, payment card data, government-issued and financial identifiers such as Social Insurance and health-card numbers, biometric identifiers, and genetic data. If the personal information you are assessing falls into those categories, MapleDeploy is not the destination to assess.
For the paperwork side, our data residency documentation checklist covers what to collect and keep.
The rest of Law 25, briefly
Section 17 is one obligation among many, and hosting touches only this one. Your organization still needs a designated person in charge of the protection of personal information, published governance policies and practices, collection notices that meet section 8, valid consent, a privacy impact assessment for new information system projects under section 3.3, a privacy incident register with notification to the CAI and affected individuals where an incident presents a risk of serious injury, and a process for access, rectification, portability, and de-indexation requests. None of those are infrastructure questions.
Penalties
Both enforcement routes reach an unlawful transfer. Administrative monetary penalties apply to anyone who "collects, uses, communicates, keeps or destroys personal information in contravention of the law", up to $10 million or 2% of worldwide turnover for the preceding fiscal year, whichever is greater. The penal offence uses the same words and runs from $15,000 to $25 million, or 4% of worldwide turnover. Section 93.1 adds punitive damages of at least $1,000 where an intentional infringement or a gross fault causes injury.
Where to start
- List every place personal information goes, including backups, logs, and support tools
- Mark which destinations are outside Quebec, other provinces included
- Run the four factors against each one and write down the conclusion
- Put the written agreement in place before the transfer, not after
- Check that your collection notices say information may be communicated outside Quebec
- Redo the assessment when a vendor, a region, or the data itself changes
The shortest version of that work is the one where the destination is Canada. It is still work.
Canadian hosting, and the facts your assessment needs
Your application data stays in Toronto. Try MapleDeploy free for 30 days.