← SOVEREIGNTY LAW ATLAS

SOVEREIGNTY LAW ATLAS — CA

Canada

TIER DEMO · STATUS PUBLISHED · LAST FULL REVIEW 2026-08-04 · 3 INSTRUMENTS ON RECORD

The verdict.

FOUR DOMAINS · CONFIDENCE-LABELLED · AS CAPTURED 2026-08-04
Data residency & localizationD1 — WHERE DATA MUST LIVE Transfer controls not localizationVERIFIED
AI-specific regulationD2 — AI ACTS & REGISTRATION DUTIES No instrumentVERIFIED ABSENCE
Cloud & procurement sovereigntyD3 — CERTIFICATION & MANDATES Procurement frameworkREPORTED
Export & access lawsD4 — EXTRATERRITORIAL REACH Five eyes exposureJUDGMENT
Instruments on record 3
Last full review 2026-08-04
Status PUBLISHED
For a buyer

Canadian jurisdiction does not legally force on-premises deployment — sovereignty here is achieved by architecture and contract, not by mandate.

Configure your SovereigntyBox for Canada →

ATLAS RECOMMENDATION — DOCUMENTED CONTROL · Five Eyes exposure — keep the runtime local and ungoverned paths closed. Seeded into the configurator; adjust anything.

The dossier.

SOURCES FOOTNOTED · EVIDENCE STATE LABELLED

Domains

D1 — Data residency & localization

PIPEDA is the federal private-sector baseline: no residency requirement, but the transferring organization stays accountable for data sent across borders (Principle 4.1.3).1 Quebec's Law 25 (modernizing the private-sector act) requires a privacy impact assessment before personal information is communicated outside Quebec, with adequacy-style findings.2 "Canada mandates local hosting" is a myth for the private sector — the mandate is accountability, not geography.

D2 — AI-specific regulation

AIDA, the federal AI bill inside Bill C-27, died on prorogation in January 2025. No successor had been tabled as of capture. Voluntary instruments (the Generative AI Code of Practice) carry no legal force.

D3 — Cloud & procurement sovereignty

Federal workloads are governed by the GC cloud security profiles — PBMM (Protected B, Medium Integrity, Medium Availability) being the operative tier for sensitive unclassified workloads.3 This is procurement policy, binding on government, not on private buyers.

D4 — Export & access

Canada is a Five Eyes member. US-controlled providers operating in Canada remain subject to the US CLOUD Act for data they control regardless of where it sits; the US reference record that would resolve this fully is deferred to Phase 2.

Extraterritorial exposure

The operative exposure is not Canadian law reaching outward but US law reaching inward: a workload on a US-controlled cloud in a Canadian region is within CLOUD Act reach, and PBMM's own model acknowledges this by treating sovereignty as a profile dimension rather than a location fact. Full US-side analysis deferred (reference record not yet built).

Disclaimer

This dossier describes the law as captured on 2026-08-04; it is not legal advice, and no compliance determination is made or implied.

  1. PIPEDA, S.C. 2000, c. 5 — Justice Laws Canada — vault atlas-vault/ca/ca-pipeda/2026-08-04.pdf, sha256 02d32bc1…, captured 2026-08-04. (VERIFIED)
  2. Act respecting the protection of personal information in the private sector (as modernized by Law 25) — LégisQuébec — vault atlas-vault/ca/qc-law25/2026-08-04.pdf, sha256 35b0fad9…, captured 2026-08-04. (VERIFIED)
  3. GC cloud security profiles (PBMM) — Treasury Board of Canada Secretariat — canada.ca, not vaulted (HTML source). (REPORTED)

The instruments.

3 ON RECORD · 2 GAPS

Personal Information Protection and Electronic Documents Act (PIPEDA), S.C. 2000, c. 5

VERIFIED
TYPE STATUTESTATUS IN-FORCEENACTED 2000-04-13 · IN FORCE 2001-01-01
EvidenceVAULT atlas-vault/ca/ca-pipeda/2026-08-04.pdf · SHA256 02d32bc1… · CAPTURED 2026-08-04
RAGblocked — parser staging 401 (2026-08-04)

Act respecting the protection of personal information in the private sector (as modernized by Law 25 / Bill 64)

VERIFIED
TYPE STATUTE (PROVINCIAL)STATUS IN-FORCEENACTED 2021-09-22 · IN FORCE 2022-09-22 (staged to 2024-09)
AuthorityLégisQuébec
EvidenceVAULT atlas-vault/ca/qc-law25/2026-08-04.pdf · SHA256 35b0fad9… · CAPTURED 2026-08-04
RAGblocked — parser staging 401

GC cloud security profile — Protected B, Medium Integrity, Medium Availability (PBMM)

REPORTED
TYPE POLICY-FRAMEWORKSTATUS IN-FORCE
Evidencenot-vaulted — HTML-only source
RAGnot-submitted
GAP — D2 · VERIFIED 2026-08-04VERIFIED ABSENCE

AIDA died with Bill C-27 on prorogation (2025-01-06); no successor tabled as of capture

GAP — D4 · VERIFIED 2026-08-04VERIFIED ABSENCE

US CLOUD Act / FISA 702 reference record deferred to Phase 2 (PRD §3.2)

This dossier describes the law as captured 2026-08-04; it is not legal advice, and no compliance determination is made or implied.

SBX CONCIERGEnothing leaves this page