Data Residency vs. Data Sovereignty: What Canadian Law Actually Requires

Ed Leavens

July 22, 2026

Canadian law doesn't mandate Canadian hosting, it mandates risk mitigation. Here's what Bill C-36 and Law 25 really require...and where tokenization fits.

Ask a Canadian enterprise where its data lives and you will get a confident answer: a Canadian region, a Canadian data centre, a Canadian subsidiary. Ask who can compel access to it, and the room goes quiet.

Residency is a geographic fact: where the bytes sit. Sovereignty is a legal question: which government can compel production, and what your provider is technically able to hand over when they do.

Canadian law is increasingly clear about which of the two it cares about, and it is not the one most organizations have optimized for.

Residency Is Being Quietly Abandoned as a Legal Control

The conventional wisdom is that Canada is tightening data localization. The legislative record says the opposite.

British Columbia had the strictest residency rule in the country. The Freedom of Information and Protection of Privacy Act's (FIPPA) former section 30.1 required public bodies to store and access personal information only in Canada. Bill 22 repealed it effective November 25, 2021. BC public bodies may now store personal information outside Canada, subject to a privacy impact assessment where it is sensitive.

Nova Scotia's Personal Information International Disclosure Protection Act (PIIDPA) still restricts cross-border storage by public bodies, with limited exceptions. It is also being repealed, its restrictions folding into a modernized FOIPOP framework effective April 1, 2027.

Quebec, with the most demanding private-sector privacy law in Canada, never banned cross-border transfers at all. Law 25's section 17 requires a privacy impact assessment before personal information is communicated outside Quebec, confirmation it will receive adequate protection there, and a written agreement with the recipient.

That applies to a transfer to Ontario as much as to Virginia. Staying inside Canada does not exempt you.

The pattern is consistent. Canadian legislators are not mandating Canadian data centres. They are mandating that you assess and mitigate the risk of foreign access.

Bill C-36 Makes the Distinction Explicit

On June 15, 2026, the federal government introduced Bill C-36, which would enact the Protecting Privacy and Consumer Data Act and replace Part 1 of The Personal Information Protection and Electronic Documents Act (PIPEDA). It is Ottawa's third attempt at reform after Bill C-11 and Bill C-27 both died on the Order Paper.

The government's backgrounder includes a section headed Protecting Canada's Digital Sovereignty.

Read what is in it. Two commitments: that organizations put appropriate security safeguards in place and take privacy implications into account when using service providers, and that they assess and mitigate privacy risks before sending personal information outside Canada.

That is the whole of it. No residency mandate. No Canadian-hosting requirement. The flagship sovereignty provision is a risk assessment obligation.

The enforcement behind it is not soft. Administrative monetary penalties reach $10 million or 3 percent of global revenue, whichever is greater, and fines reach $25 million or 5 percent for the most serious offences, administered by a new Digital Safety and Data Protection Commission of Canada with binding order-making powers.

One caveat, stated plainly. C-36 received first reading on June 15 and is not law. It faces second reading, committee, and the Senate, and its coming into force is tied to standing up the new Commission. Provisions will change. The direction will not.

A Canadian Court Already Showed Why Geography Fails

Per reporting on the proceeding, in September 2024 the Ontario Court of Justice ordered OVHcloud, a French provider, to produce customer data stored in France, the UK, and Australia, reasoning that its commercial presence here created a virtual presence sufficient to compel compliance regardless of where the data sat.

The RCMP had bypassed the Mutual Legal Assistance Treaty process and France objected formally. The matter is under appeal and much of the public detail is secondary reporting rather than the docket, so treat the doctrine as instructive and the outcome as open.

The doctrine is what matters. A production order compels records a party controls, and control is a question of technical capability, not geography. It is also why encryption alone is a weak sovereignty control: if a provider holds the keys, the order shifts from produce the data to produce the keys.

Technical access is legal liability. Geography is not a defence.

The Nuance Most Vendors Skip

Here is where I argue against the easy version of my own pitch.

C-36 draws a hard line between de-identified information, where identifying detail is removed but re-identification remains possible, and anonymized information, irreversibly modified so no individual can be identified.

Anonymized falls outside the Act. De-identified stays fully inside it.

Vaulted tokenization is reversible. That is the product. You detokenize, on purpose, every day. So tokenized data is de-identified rather than anonymized, and it stays in scope under C-36 and Law 25.

Anyone telling you tokenization makes your cross-border obligation disappear is wrong, including anyone selling tokenization.

What the Concession Does Not License

Nothing else exits scope either. Encryption keeps you in scope. Contractual controls keep you in scope. Canadian hosting keeps you in scope, and C-36 does not ask for it in the first place. Short of true anonymization, which destroys the utility that made the data worth holding, no architecture takes you out.

In scope is not a verdict on tokenization. It is the baseline condition for every option on the table.

And scope exit was never the test.

Read the obligation again: assess and mitigate privacy risks before sending personal information outside Canada.

Not eliminate. Not exit. Mitigate.

Tokenization is not a workaround to that obligation. It is the mitigation the obligation asks for, delivered at the data layer instead of in a contract.

What It Actually Changes

A transfer impact assessment asks whether information will receive adequate protection given the legal regime it is entering.

If what crosses the border is a token carrying no derivable relationship to the original, the question of what a foreign authority could compel from that processor has a concrete answer: placeholders.

You still perform the assessment and still document it. But you are assessing an exposure you deliberately bounded rather than one you are arguing away with paperwork.

And you moved the exposure rather than eliminating it. A vault in Canada is within reach of any Canadian court with jurisdiction over you. That is the trade: one controlled, auditable, defensible point of exposure instead of usable copies scattered across every downstream system and provider in your chain.

Worth a great deal. Not immunity.

The Question to Ask

Law 25 today, C-36 tomorrow, BC's FIPPA regulations, the flow-downs from federal and provincial clients: every framework converging on Canadian organizations asks the same thing:

Can you demonstrate that personal information leaving your control is adequately protected against the legal regime it is entering?

You cannot answer that with a map.

The Canadian market has spent a decade selling residency as sovereignty. The legislation moving through Ottawa does not ask where your data lives. It asks what happens to it when someone with legal authority comes looking, and how much of it is usable when they do.

How Protected Is Your Sensitive Data?
Get your free, personalized data security risk report with actionable recommendations. Our assessment is 100% confidential and takes less than five minutes to see your results.

Get Started →‍

About the Author:

Ed Leavens

Ed Leavens is the Chief Strategic Officer, co-founder and former CEO at DataStealth.io and a cybersecurity innovator.