Data Residency in Canada Explained
Data residency is the legal and physical location where your data is stored. For many Canadian businesses, especially in public sector and regulated industries, data must remain within Canadian borders.
Data residency is the physical and legal location where your data is stored and processed. For many Canadian organisations, particularly those in public sector, healthcare, legal, financial services, and any business subject to BC PIPA, Alberta PIPA, or PIPEDA, storing data in Canadian data centres is a compliance and risk management requirement, not just a preference.
Three reasons drive data residency requirements in Canada:
1. Privacy law PIPEDA and provincial PIPA laws require you to protect personal information with measures equivalent to what would apply in Canada, even when using foreign service providers. Some regulators take the position that data sent to the US is subject to US government access laws (CLOUD Act, FISA) in ways that may not be compatible with Canadian privacy obligations.
2. Contractual and regulatory requirements Many government contracts, healthcare agreements, and financial services regulations explicitly require Canadian data residency. If your clients are in the public sector, verify their data location requirements before signing.
3. Risk management Data stored in Canadian data centres is subject to Canadian jurisdiction. Disputes, audits, and disclosure orders run through Canadian courts. Data stored in the US or elsewhere may be subject to foreign disclosure orders.
Yes, for core workloads. Microsoft 365 Canadian tenants store Exchange Online, SharePoint Online, and OneDrive for Business data in Canadian data centres (Toronto and Quebec City) by default. Microsoft publishes the data residency commitments by workload at their Trust Portal.
Important caveats:
Not by default. Google Workspace offers data region controls that allow pinning storage to specific regions, including Canada. This feature is available on Business Plus and Enterprise Standard tiers and above.
Without an explicit data region policy applied to your tenant, Google may replicate data across global regions. If Canadian data residency is required, verify that the data region setting is enabled and audited.
AWS has two Canadian regions: ca-central-1 (Montreal) and ca-west-1 (Calgary). Data stays in Canada if:
AWS does not automatically keep data in Canada, you must architect it that way. North Star audits AWS environments to verify data residency is actually enforced, not just assumed.
Verifying data residency requires more than taking a vendor's word for it:
If your business serves public sector clients, healthcare organisations, or operates under a regulated professional framework in BC, Alberta, or Yukon, data residency requirements may be contractually mandated. North Star has experience configuring and documenting compliant architectures for these clients.
Is data residency the same as data sovereignty? Related but different. Data residency is about physical location. Data sovereignty is about which government's laws apply. Canadian data residency generally provides Canadian data sovereignty, but not always, some platforms retain legal access rights regardless of where data is stored.
Does using a VPN keep my data in Canada? No. A VPN encrypts your connection but does not change where the destination servers store your data.
What if my US SaaS vendor has no Canadian region? You have three options: accept the risk and document it, seek contractual protections (data processing agreement with PIPEDA-equivalent obligations), or find a Canadian alternative.
Does Microsoft Teams store data in Canada? Core Teams data (chat, meeting recordings) follows the tenant's data residency configuration. Some Teams features use global infrastructure. Review the Microsoft 365 data residency documentation for the specific workloads you use.
Can North Star IT audit our data residency? Yes. North Star reviews tenant configurations, maps data flows, and produces a documented data residency compliance report for Canadian SMBs.
Need to verify where your business data actually lives? Call 672-983-1174 or book a free data residency review at northstarit.ca.
Quick answers.
What is data residency?
Data residency is the legal and physical location where your data is stored. For many Canadian businesses, especially in public sector and regulated industries, data must remain within Canadian borders.
Does Microsoft 365 keep data in Canada?
Core Microsoft 365 workloads for Canadian tenants are stored in Toronto and Quebec City data centres by default. Some advanced services may use other regions; this is documented in the Microsoft trust portal.
Does Google Workspace keep data in Canada?
Google offers data region controls on Business Plus and Enterprise tiers that pin storage to a region, including Canada. Without that setting, data may replicate globally.
Is AWS data resident in Canada?
AWS has Canadian regions (Central in Montreal, West in Calgary). You must explicitly deploy resources to a Canadian region and configure replication to keep data resident.
Can Northstar IT verify data residency for my business?
Yes. North Star reviews tenant configurations, runs data residency audits, and documents compliance for Canadian SMBs.
Have a specific situation in mind?
Book a free 30-minute scoping call with a Northstar IT engineer. We will walk through your environment, your questions, and what good looks like for your team.
Get a Free Assessment More guides