SOVEREIGNTY LAW ATLAS — CA
Canada
The verdict.
FOUR DOMAINS · CONFIDENCE-LABELLED · AS CAPTURED 2026-08-04Canadian jurisdiction does not legally force on-premises deployment — sovereignty here is achieved by architecture and contract, not by mandate.
ATLAS RECOMMENDATION — DOCUMENTED CONTROL · Five Eyes exposure — keep the runtime local and ungoverned paths closed. Seeded into the configurator; adjust anything.
The dossier.
SOURCES FOOTNOTED · EVIDENCE STATE LABELLEDDomains
D1 — Data residency & localization
PIPEDA is the federal private-sector baseline: no residency requirement, but the transferring organization stays accountable for data sent across borders (Principle 4.1.3).1 Quebec's Law 25 (modernizing the private-sector act) requires a privacy impact assessment before personal information is communicated outside Quebec, with adequacy-style findings.2 "Canada mandates local hosting" is a myth for the private sector — the mandate is accountability, not geography.
D2 — AI-specific regulation
AIDA, the federal AI bill inside Bill C-27, died on prorogation in January 2025. No successor had been tabled as of capture. Voluntary instruments (the Generative AI Code of Practice) carry no legal force.
D3 — Cloud & procurement sovereignty
Federal workloads are governed by the GC cloud security profiles — PBMM (Protected B, Medium Integrity, Medium Availability) being the operative tier for sensitive unclassified workloads.3 This is procurement policy, binding on government, not on private buyers.
D4 — Export & access
Canada is a Five Eyes member. US-controlled providers operating in Canada remain subject to the US CLOUD Act for data they control regardless of where it sits; the US reference record that would resolve this fully is deferred to Phase 2.
Extraterritorial exposure
The operative exposure is not Canadian law reaching outward but US law reaching inward: a workload on a US-controlled cloud in a Canadian region is within CLOUD Act reach, and PBMM's own model acknowledges this by treating sovereignty as a profile dimension rather than a location fact. Full US-side analysis deferred (reference record not yet built).
Disclaimer
This dossier describes the law as captured on 2026-08-04; it is not legal advice, and no compliance determination is made or implied.
- PIPEDA, S.C. 2000, c. 5 — Justice Laws Canada — vault
atlas-vault/ca/ca-pipeda/2026-08-04.pdf, sha25602d32bc1…, captured 2026-08-04. (VERIFIED) ↑ - Act respecting the protection of personal information in the private sector (as modernized by Law 25) — LégisQuébec — vault
atlas-vault/ca/qc-law25/2026-08-04.pdf, sha25635b0fad9…, captured 2026-08-04. (VERIFIED) ↑ - GC cloud security profiles (PBMM) — Treasury Board of Canada Secretariat — canada.ca, not vaulted (HTML source). (REPORTED) ↑
The instruments.
3 ON RECORD · 2 GAPSPersonal Information Protection and Electronic Documents Act (PIPEDA), S.C. 2000, c. 5
VERIFIEDatlas-vault/ca/ca-pipeda/2026-08-04.pdf · SHA256 02d32bc1… · CAPTURED 2026-08-04Act respecting the protection of personal information in the private sector (as modernized by Law 25 / Bill 64)
VERIFIEDatlas-vault/ca/qc-law25/2026-08-04.pdf · SHA256 35b0fad9… · CAPTURED 2026-08-04GC cloud security profile — Protected B, Medium Integrity, Medium Availability (PBMM)
REPORTEDAIDA died with Bill C-27 on prorogation (2025-01-06); no successor tabled as of capture
US CLOUD Act / FISA 702 reference record deferred to Phase 2 (PRD §3.2)
This dossier describes the law as captured 2026-08-04; it is not legal advice, and no compliance determination is made or implied.