WalledCare WalledCareLearn
Canada

Data residency for senior-care software in Canada: does the data have to stay here?

No Canadian law makes a retirement home, a long-term care home or a home-care agency keep its software data inside Canada. "Hosted in Canada" still matters, because a US court order can follow the company rather than the building — so ask about backups, support access, subprocessors and ownership, not just the data-centre address.

A living-room shelf holding a wireless router, with a WalledCare sensor plugged into the outlet beside it.
Everything a connected product records leaves the building through a box like this one. Where it lands afterwards, who can reach it, and under whose law, is what a procurement team has to ask out loud.

Disclosure: WalledCare Learn is published by Moneli Automation, maker of WalledCare. Product listings are not paid. See our comparison methodology.

PIPEDA allows data to be processed abroad as long as you stay accountable for it. Nova Scotia is the exception that does impose in-Canada storage on public bodies and their service providers, and Quebec requires an assessment before information leaves the province. We found no in-Canada storage clause in Ontario's PHIPA, but could not verify the statute text directly, so have a privacy professional confirm it.

Key facts

  • PIPEDA "does not prohibit organizations in Canada from transferring personal information to an organization in another jurisdiction for processing." The sender stays responsible and must use "contractual or other means" to get "a comparable level of protection." (OPC, 2009)
  • The US CLOUD Act reaches data in a provider's "possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States." In plain words: a US order can follow the company, not the building. (18 U.S. Code 2713, Cornell LII, 2018)
  • As of CIHI's 2021 count, Canada had 2,076 long-term care homes, 54% of them privately owned — so most buyers here sit under private-sector privacy law. (CIHI, 2021)

This page is general information, not legal advice. Privacy law differs by province and by whether you are a public body, a health custodian or a private business. Have a qualified privacy professional review any contract.

Why "hosted in Canada" is still worth asking about

Vendors put "hosted in Canada" on sales pages because buyers ask for it. It is worth asking about, because foreign law can reach data held by foreign-controlled companies, some buyers do have hard rules, and families expect it. In the Equifax investigation the Privacy Commissioner found that individuals buying those products "would not reasonably expect, given the indications to the contrary, that sensitive information was being collected by, and disclosed to, a third party outside of Canada." (PIPEDA Findings #2019-001, OPC, 2019)

What does the law actually say?

Federal PIPEDA: transfers allowed, you stay accountable

PIPEDA covers private businesses except where a substantially similar provincial law applies. Alberta's PIPA, British Columbia's PIPA and Quebec's private-sector act cover commercial activity inside those provinces instead, so a private retirement home in Calgary or Vancouver is under a provincial PIPA. (Provincial laws that may apply instead of PIPEDA, OPC, modified 2020)

Where PIPEDA applies, transfers abroad are allowed, as the Key facts quote sets out, and you stay on the hook. Microsoft's compliance page puts both halves together: "PIPEDA doesn't require Canadian businesses to keep personal information in Canada. However, depending on the province where organizations do business, or their industry, they could be required to keep certain types of data within Canadian borders." (Canada privacy laws, Azure Compliance, Microsoft Learn, updated 2024)

Ontario PHIPA and Alberta HIA: agreements and accountability

Four provincial health privacy laws replace PIPEDA for health custodians: Ontario's PHIPA, New Brunswick's PHIPAA, and the Personal Health Information Acts of Newfoundland and Labrador and Nova Scotia. (OPC, modified 2020) Alberta's Health Information Act governs custodians under Alberta law, but is not on that list.

We could not fetch Ontario's PHIPA text: e-Laws serves only a JavaScript shell to automated requests. We found no reported in-Canada storage clause, but cannot cite one either way. Ask your privacy reviewer to confirm the current sections.

Alberta's HIA is readable, and clear. Section 66(2) says a custodian "must enter into a written agreement with an information manager in accordance with the regulations," and s. 66(6) says "a custodian continues to be responsible for compliance with this Act" for information handed to that manager. (Section 66(1) was repealed in 2025, leaving s. 66(2)'s reference to "subsection (1)" dangling.) Section 60(1)(b) expressly contemplates health information "stored or used in a jurisdiction outside Alberta" and requires the custodian to safeguard it. The Act plans for data leaving Alberta rather than forbidding it. (Health Information Act, RSA 2000, c. H-5, consolidated 2026)

Quebec Law 25: an assessment before data leaves Quebec

Quebec is stricter, but does not ban transfers. Under its private-sector act, an enterprise must run a privacy impact assessment before sending personal information outside Quebec, and may send it only if the assessment shows the information would get adequate protection there. A written agreement is required. A separate obligation covers any project to acquire, develop or overhaul an information system handling personal information — a resident-monitoring system qualifies. "Outside Québec" includes Ontario, so a Toronto data centre needs the assessment too.

Two caveats. LégisQuébec blocks automated access, so we could not fetch the statute text; treat this as a plain-language pointer, not a citation. And most of Law 25's changes came into force on 22 September 2023, not on assent in 2021. (Bill 64, Assemblée nationale du Québec, assented 2021, in force 2023) Separately, Quebec's public health and social services network — CHSLDs, CIUSSS-run homes and their suppliers — is governed by its own health-information statute rather than the private-sector act. We could not verify that statute here, so a public-network buyer must check with counsel which act binds it.

Nova Scotia and the federal directive: the closest thing to hard rules

Nova Scotia's PIIDPA is the strongest rule we verified. A public body, "a service provider or associate of a service provider" must ensure personal information in its custody or control "is stored only in Canada and accessed only in Canada." A "service provider" is anyone retained under contract to perform services for a public body who handles personal information doing so, so a private operator or software vendor under contract to a Nova Scotia public body is caught. Exceptions cover consent, disclosures the Act allows, and approval by the head of the public body for "the necessary requirements of the public body's operation," reported to the Minister each year. (PIIDPA, s. 5, 2006)

Federal departments follow the Treasury Board Directive on Service and Digital. The government describes those rules as "requirements for the storage of data within Canada." (Digital sovereignty, Government of Canada, 2025) The Treasury Board site blocks automated requests, so we do not quote a clause number here. For a private operator it is a benchmark, not a mandate.

British Columbia: the 2021 repeal people still get wrong

BC's in-Canada storage rule for public bodies, FIPPA s. 30.1, was repealed in 2021. Current s. 33.1 says a public body "may disclose personal information outside of Canada only if the disclosure is in accordance with the regulations, if any, made by the minister responsible for this Act." (FIPPA, RSBC 1996, c. 165, ss. 30.1 and 33.1, 2021) Whether any such regulations exist is unverified here.

Why location still matters: the US CLOUD Act

The CLOUD Act took effect on March 23, 2018. It requires a provider of electronic communication service or remote computing service subject to US jurisdiction to disclose customer data in its possession, custody or control wherever that data sits. (18 U.S. Code 2713, Cornell LII, 2018)

On June 10, 2025, a French Senate committee asked Microsoft under oath whether it could guarantee French data would never be handed to US authorities without French consent. Anton Carniaux, Microsoft France's director of public and legal affairs, answered: "Non, je ne peux pas le garantir, mais, encore une fois, cela ne s'est encore jamais produit." In English: "No, I cannot guarantee it, but, again, it has never happened." (Sénat français, 2025) Both halves matter. There is no public evidence that US authorities routinely pull Canadian health data. The point is that a provider cannot promise they never will.

The Privacy Commissioner said the same in 2009: "No contract can override the criminal, national security or any other laws of the country to which the information has been transferred." (OPC guidelines, 2009)

So separate three things. Residency is where the data sits. Sovereignty is whose laws apply: data in Toronto held by a US-controlled company is subject to both Canadian and US law. Control is who can actually reach it. Residency is the easiest to check and the least complete.

Data leaves "Canada" in five ordinary ways

Backups, offshore support access, subprocessors (email, SMS alerts, analytics, crash reporting, AI features), the vendor's own corporate ownership, and the servers sensors and mobile apps phone home to for firmware and registration. Each is a route out, and none of them shows up in the phrase "hosted in Canada." The Equifax finding shows how ownership alone can do it: Equifax Canada remained in control of data sent to its US parent, had no formal written agreement, and was held responsible. (OPC, 2019) So ask about all five.

Nine questions to put in the RFP

  1. Where is the production database hosted? Name the cloud provider, region and city.
  2. Where are backups stored? Are they encrypted, and who holds the keys?
  3. From which countries can support staff access resident data? Is access logged?
  4. List every subprocessor that touches resident data, with its country.
  5. Who is your ultimate parent company, and where is it incorporated?
  6. Will you sign the agreement our province requires: a PHIPA agreement, an Alberta HIA information manager agreement, or a Law 25 written agreement?
  7. Will you supply what we need for a privacy impact assessment?
  8. Where do devices and mobile apps connect for updates and registration?
  9. What data does the product create at all, and can we turn features off to collect less?

What good vendor answers look like

  • PointClickCare, a long-term care records vendor headquartered in Mississauga, Ontario, says it hosts a customer's production database in the customer's country of residence, and that for Canadian customers "backup data may be hosted in the United States in encrypted form, and within an encrypted environment." That is honest disclosure, and it is also a transfer. Its privacy policy also states that "Alberta's Health Information Act requires that our Alberta customers enter into an Information Manager Agreement (“IMA”) with us," and that "PointClickCare is a health information network provider (HINP) in Ontario" — the company's own description of its status. (PointClickCare Privacy Policy, accessed 2026)
  • AWS states: "For customers who wish to process their data in Canada, the AWS Canada (Central) Region near Montreal and the Canada (West) Region near Calgary are available," and "We will not move your content outside of your chosen AWS Region(s) without your agreement, except in each case as necessary to comply with the law or a binding order of a governmental body." (AWS, 2025) That carve-out is exactly the CLOUD Act exposure. Region choice is a real control, not a promise about legal compulsion.
  • AlayaCare says each client record is "hosted in your region," and that "AlayaCare maintains independent SOC 1 Type II, SOC 2 Type II, HITRUST i1, and annual HIPAA audits." (AlayaCare Security, accessed 2026) "Your region" is not "Canada." Ask which region yours is.
  • Vayyar Care and Xandar Kardian, two radar-sensor vendors, do not state on their public pages where data is stored. (Vayyar Care; Xandar Kardian, both accessed 2026) Not a red flag by itself, but a question to ask.

"We are PIPEDA compliant" is not an answer. PIPEDA does not require in-Canada storage, so the phrase says nothing about location.

Frequently asked questions

Does PHIPA require personal health information to be stored in Ontario or Canada?

We could not verify Ontario's statute text and found no reported in-Canada storage clause. Have a privacy professional confirm the current sections for your situation.

Is an AWS or Azure Canadian region enough for compliance?

Region choice is one input, not compliance. Read AWS's sentence above in full: the promise not to move your content has a carve-out for legal orders. Compliance still depends on your agreements, access controls, subprocessors and the vendor's ownership.

Where WalledCare fits

The residency question is easiest when a product creates little personal data. WalledCare is a camera-free millimetre-wave radar presence sensor. It reports presence, movement, prolonged stillness and prolonged inactivity, room by room. It creates no video and no audio, so the data to be hosted, backed up and supported is small — fewer subprocessors, a simpler assessment. Its product page describes it as "Built & hosted in Canada" (WalledCare, accessed 2026); ask for the same nine answers you would ask any vendor. WalledCare does not detect falls, does not measure breathing, and is not a medical device, and where its data lives does nothing to change that.

Read more in the Canada hub, compare hosting choices in Canadian vs US-hosted senior monitoring, or see how WalledCare works.

Sources

  1. Guidelines for processing personal data across borders, Office of the Privacy Commissioner of Canada, 2009. https://www.priv.gc.ca/en/privacy-topics/airports-and-borders/gl_dab_090127/
  2. 18 U.S. Code 2713, Required preservation and disclosure of communications and records, Cornell LII, 2018. https://www.law.cornell.edu/uscode/text/18/2713
  3. Sénat français, compte rendu de la commission d'enquête sur la commande publique, 10 juin 2025. https://www.senat.fr/compte-rendu-commissions/20250609/ce_commande_publique.html
  4. Personal Information International Disclosure Protection Act, S.N.S. 2006, c. 3, s. 5. https://nslegislature.ca/sites/default/files/legc/statutes/persinfo.htm
  5. Freedom of Information and Protection of Privacy Act, RSBC 1996, c. 165, ss. 30.1 and 33.1. https://www.bclaws.gov.bc.ca/civix/document/id/complete/statreg/96165_03
  6. Bill 64 (2021, chapter 25), Assemblée nationale du Québec. https://www.assnat.qc.ca/en/travaux-parlementaires/projets-loi/projet-loi-64-42-1.html
  7. Health Information Act, RSA 2000, c. H-5, ss. 60 and 66, consolidated 2026. https://kings-printer.alberta.ca/documents/Acts/H05.pdf
  8. Provincial laws that may apply instead of PIPEDA, Office of the Privacy Commissioner of Canada, modified 2020. https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/r_o_p/prov-pipeda/
  9. PIPEDA Findings #2019-001, Investigation into Equifax Inc. and Equifax Canada Co., Office of the Privacy Commissioner of Canada, 2019. https://www.priv.gc.ca/en/opc-actions-and-decisions/investigations/investigations-into-businesses/2019/pipeda-2019-001/
  10. Canada privacy laws, Azure Compliance, Microsoft Learn, updated 2024. https://learn.microsoft.com/en-us/compliance/regulatory/offering-canadian-privacy-laws
  11. Canada Data Privacy, Amazon Web Services, 2025. https://aws.amazon.com/compliance/canada-data-privacy/
  12. Long-term care homes in Canada: How many and who owns them?, CIHI, 2021. https://www.cihi.ca/en/long-term-care-homes-in-canada-how-many-and-who-owns-them
  13. Digital sovereignty, Government of Canada cloud services, 2025. https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/cloud-services/digital-sovereignty.html
  14. PointClickCare Privacy Policy, accessed 2026. https://pointclickcare.com/privacy-policy/
  15. AlayaCare Security, accessed 2026. https://alayacare.com/security/
  16. Vayyar Care, accessed 2026. https://www.vayyar.com/care/
  17. Xandar Kardian, accessed 2026. https://www.xkcorp.com/
  18. WalledCare, accessed 2026. https://walledcare.com/
Last reviewed By Moneli Automation editorialNext review 6 September 2027