WalledCare WalledCareLearn
Comparisons

Where is your parent's data stored? Canadian vs US-hosted senior monitoring

Where your parent's monitoring data goes is decided by the vendor, not by the law: Canadian privacy law usually allows it to leave the country. Stored in Canada helps, but it does not put data beyond US reach when a US-controlled company holds it.

Published by Moneli Automation, maker of WalledCare. Listings are not paid. How we evaluate and check listings.

Ask what the data is before you ask where it sits. Pendants collect location, call recordings and often medical notes; cameras collect video and audio; room sensors collect activity signals only. All of it is personal information under Canadian law. In the OPC's 2025 survey of 1,500 Canadians, nine in ten said they are concerned about their privacy and only 40% believe businesses respect their privacy rights (OPC, 2025).

Does Canadian law require the data to stay in Canada?

For most families buying from a private company, no.

PIPEDA: allowed, with conditions

The federal Personal Information Protection and Electronic Documents Act (PIPEDA) applies to private companies across Canada, with one carve-out: "Unless the personal information crosses provincial or national borders, PIPEDA does not apply to organizations that operate entirely within: Alberta, British Columbia, Quebec", which have substantially similar laws of their own (OPC, current 2026).

PIPEDA does not prohibit sending personal information abroad. The Office of the Privacy Commissioner (OPC) treats a transfer for processing as a "use", not a disclosure, so no extra consent is needed if the purpose does not change. But the company stays accountable. It must "use contractual or other means to provide a comparable level of protection while the information is being processed by the third party", and tell you the data "may be accessed by the courts, law enforcement and national security authorities" there. Two caveats in the same guideline matter: "comparable" is not identical, only protection "that can be compared to" what the information would get at home, and no contract can override foreign law (OPC, 2009). In 2019 the OPC kept "the status quo until the law is changed" (OPC, 2019).

Provinces with their own rules

  • Quebec. Section 17 of the private-sector Act (CQLR c. P-39.1) requires a privacy impact assessment before personal information is communicated outside Quebec, and a written agreement with the recipient (BLG, 7 May 2024). That is a law-firm summary; we could not load the statute itself.
  • Alberta. A business using a service provider outside Canada must tell you how to get its policies, which must name the country and the purposes (Alberta.ca, current 2026; PIPA, SA 2003 c P-6.5, s. 13.1, added 2009 c50 s7).
  • British Columbia. BC's own Personal Information Protection Act governs private companies operating entirely within the province (OPC, current 2026). BC's separate public-body law dropped its keep-it-in-Canada rule in November 2021; public bodies now need a privacy impact assessment before storing sensitive information outside Canada (Province of BC, 2021, updated 2025). That public-body rule does not bind a vendor selling to your family.

Ontario PHIPA: we found no geography rule, and the custodian stays responsible

You may see marketing that says Ontario's Personal Health Information Protection Act requires health data to stay in Canada. We found no such rule. PHIPA works through accountability: a long-term care home is a "health information custodian", a company it hires is an "agent", and the custodian "remains responsible for the personal health information collected, used, disclosed, retained or disposed of by an agent" (IPC Ontario presentation, 2016). That source is an IPC slide deck predating the 2020 PHIPA amendments, hosted on a third-party site, and the official e-Laws text is not machine-readable to us. Confirm before relying on it.

For operators: put PHIPA accountability for agents to privacy counsel before signing a US-hosted contract.

The federal government's own standard

Ottawa holds itself to a stricter rule than it sets for private companies: "Protected B, Protected C and classified Government of Canada electronic data must be stored on approved servers in Canada" or on government premises abroad (OPC Privacy Act bulletin, 27 June 2019).

Is "hosted in Canada" the same as "out of US reach"?

No, and this is the point most product pages skip. In March 2018 the United States passed the CLOUD Act. Covered providers must "preserve, backup, or disclose" records "within such provider's possession, custody, or control, regardless of whether such communication, record or other information is located within or outside of the United States" (18 U.S.C. s. 2713; Barry Appleton, "Whose Law Governs Canadian Data?", Balsillie Papers Special Report, 11 March 2026).

Two limits matter. Scope: the Act reaches providers of an electronic communication service (18 U.S.C. s. 2510(15)) or a remote computing service (18 U.S.C. s. 2711(2)), which the report describes as covering "cloud storage, data processing, and software-as-a-service providers". Whether a radar sensor vendor or a monitoring centre is either is not obvious; ask. Process: the Act "does not itself confer jurisdiction"; it works through US legal process once a US court finds jurisdiction.

Ottawa makes the same point. Its white paper defines residency as the "physical or geographical location" of data and sovereignty as the right to control access "subject only to Canadian laws", then warns: "As long as a CSP that operates in Canada is subject to the laws of a foreign country, Canada will not have full sovereignty over its data" (a CSP is a cloud service provider) (GC White Paper, 2018, updated 2026). In July 2025 CBC/Radio-Canada reported that millions of Canadians' medical records sit on US-owned cloud servers, reachable under the CLOUD Act even when stored here (Radio-Canada/CBC, 2025).

What actually limits access

Three things do more work than a postal code. Who controls the company: a Canadian-owned company with no US operations is harder to compel directly than a US cloud provider's Canadian region, though treaties still allow requests through Canadian courts. Who holds the keys: among the mitigations for CLOUD Act risk, Osler lists encryption at rest, in transit and in use, with organizations managing "their own encryption keys (customer-managed keys)" where possible (Osler, October 2025). How little is collected: "no movement in the bedroom since 02:10" is a much smaller thing to protect than video, audio or GPS.

For balance, a 2020 essay by a public servant in government technology calls data residency "security theatre" that "gives the impression of making things secure" (Sean Boots, 2020; the views are the author's alone).

Five questions to ask any monitoring vendor

  1. In which country is my data stored, and who owns the company that stores it? "Secure cloud servers" tells you nothing.
  2. What exactly leaves the house? Video, audio, location, or activity signals? For a pendant, ask how long call recordings are kept.
  3. Can staff outside Canada see it, and why? Many policies allow access from abroad for support.
  4. Who holds the encryption keys? If the cloud provider holds them, it can be compelled to decrypt.
  5. How long is it kept, and how do I have it deleted?

How do monitoring vendors answer today?

These are each vendor's own words, with the date checked. We assert none of them as fact.

Sold in Canada

  • Lifeline Canada: "Personal Data may be collected, accessed or transferred outside of Canada ... including in the United States or the Philippines in some circumstances" (Lifeline, August 2025).
  • TELUS Health: "Your Personal Information, including your Medical Record, is stored in Canada and may be accessed from outside Canada in limited circumstances." Service providers "may access or store Personal Information, including Personal Health Information, however, excluding your Medical Record, in the United States or other jurisdictions" — the examples given are a "marketing/communications platform provider and analytics platform provider" (TELUS Health, effective 13 October 2023). That page covers Care Centres, not the medical alert service.
  • Holo Alert: the homepage says "Canadian-owned and operated," with "Canadian monitoring centres". The privacy policy says systems and service providers "store and process personal information in Canada and the United States", and that abroad it "may be accessible to that country's courts and authorities under its laws" (Holo Alert, updated 2 September 2026).
  • Aqara Presence Sensor FP2: "Automations of FP2 are executed without sending to the cloud, and they will keep working even in case of no internet connection" (Aqara, checked September 2026). The policy at aqara.com/en/privacy-policy is a website-visitor policy for Lumi United Technology, not an FP2 or app policy; we could not locate the device policy or confirm Canadian retail availability.
  • Nomo Smart Care: "No cameras 100% privacy" (Nomo). Its policy does not say where data is stored, only that information "may be sent electronically to servers outside of the country where you originally entered the information". It is written to US law: it sets out California CCPA rights and never mentions Canada or PIPEDA (policy, September 2026).
  • WalledCare: we say "Sensing happens on the device; only activity signals and alerts leave the home — and they stay on Canadian infrastructure" (WalledCare, checked September 2026). Treat that as a claim, like the others: who owns that infrastructure and who holds the encryption keys is not published anywhere on our site. Put question 1 and question 4 above to us in writing, exactly as you would to any vendor on this page.

Not sold directly to Canadian families

  • Xandar Kardian sells to hospitals, long-term care and home-health providers, not families. It is "headquartered in Toronto, Canada" with its radar lab in Seoul (About); its policy says servers "may be located anywhere in the world (including the United States)" (policy, 2018).
  • Vayyar Care: the cited consumer page is headed "Vayyar Care: Fall Detection Exclusively with Alexa Together" and links only to amazon.com — no Canadian ordering path and no data-location statement (Vayyar, checked September 2026). We could not confirm the status of Alexa Together.
  • envoyatHome is "sold directly to families across the United States", with no data-location statement (envoyatHome, checked September 2026).

None of this makes one vendor "safe" and another "unsafe". Lifeline offers two-way voice and a monitoring centre; a room sensor does not. For dementia wandering, or a parent who needs to talk to someone, a pendant may be the better fit wherever the data lives.

Where WalledCare fits

WalledCare is a camera-free millimetre-wave radar presence sensor. It reports presence, movement, prolonged stillness and prolonged inactivity, room by room, with no image and no audio. Its honest advantage here is data minimisation: less to store, so less to worry about wherever it is stored. It does not detect falls, does not measure breathing, and is not a medical device. If your parent needs two-way voice help, a pendant is the better choice. See how WalledCare works.

This article is general information, not legal advice. Privacy laws differ by province and change; check with a privacy professional or the relevant commissioner's office. If your parent needs help right now, call 911.

Sources

  1. Guidelines for processing personal data across borders, Office of the Privacy Commissioner of Canada (2009). https://www.priv.gc.ca/en/privacy-topics/airports-and-borders/gl_dab_090127/
  2. Provincial laws that may apply instead of PIPEDA, Office of the Privacy Commissioner of Canada (current 2026). https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/02_05_d_15/
  3. Consultation on transfers for processing: conclusion, Office of the Privacy Commissioner of Canada (2019). https://www.priv.gc.ca/en/opc-news/news-and-announcements/2019/an_190923/
  4. Privacy matters to Canadians, Office of the Privacy Commissioner of Canada (2025). https://www.priv.gc.ca/en/opc-news/news-and-announcements/2025/nr-c_250508/
  5. Organization responsibilities for protecting personal information, Alberta.ca (page current 2026). https://www.alberta.ca/organization-responsibilities-for-protecting-personal-information
  6. Personal Information Protection Act, SA 2003 c P-6.5, s. 13.1 ("Notification respecting service provider outside Canada", added 2009 c50 s7), Alberta King's Printer. https://kings-printer.alberta.ca/documents/Acts/P06P5.pdf
  7. Cross-border transfers of personal information outside Quebec: Requirements for businesses, BLG (7 May 2024, originally December 2022). https://www.blg.com/en/insights/2022/12/cross-border-transfers-of-personal-information-outside-quebec
  8. Guidance on Disclosures Outside of Canada, Province of British Columbia (2021, updated 2025). https://www2.gov.bc.ca/gov/content/governments/services-for-government/information-management-technology/privacy/privacy-impact-assessments/guidance-on-disclosures-outside-of-canada
  9. Privacy and Personal Health Information in Ontario, IPC Ontario presentation (2016), hosted on transformsso.ca. https://www.transformsso.ca/wp-content/uploads/2023/10/IPC-Privacy-and-Personal-Health-Information-In-Ontario.pdf
  10. Consider privacy implications when outsourcing functions to a third party, OPC Privacy Act bulletin (27 June 2019). https://www.priv.gc.ca/en/for-federal-institutions/privacy-act-bulletins/pca_20190627/
  11. Barry Appleton, "Whose Law Governs Canadian Data? The CLOUD Act, Executive Agreements and Digital Sovereignty", Balsillie Papers Special Report (11 March 2026); primary text 18 U.S.C. s. 2713. https://balsilliepapers.ca/canadian-data/us-cloud-act/
  12. Government of Canada White Paper: Data Sovereignty and Public Cloud, Canada.ca (2018, updated 2026). https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/cloud-services/digital-sovereignty/gc-white-paper-data-sovereignty-public-cloud.html
  13. Canadians' health data at risk of being handed over to U.S. authorities, experts warn, Radio-Canada/CBC (2025). https://ici.radio-canada.ca/rci/en/news/2182863/health-data-cloud-servers-canada-us
  14. Data sovereignty in light of the CLOUD Act: back to the future?, Osler, Hoskin & Harcourt LLP (October 2025). https://www.osler.com/en/insights/updates/data-sovereignty-in-light-of-the-cloud-act-back-to-the-future/
  15. Data residency is security theatre, Sean Boots (2020). https://sboots.ca/2020/03/29/data-residency-is-security-theatre/
  16. Privacy Policy, Lifeline of Canada Holdings Ltd. (August 2025). https://www.lifeline.ca/en/privacy-policy/
  17. Care Centres privacy, TELUS Health (effective 13 October 2023). https://www.telus.com/en/health/about-telus-health/privacy/care-centres
  18. Privacy Policy, Holo Alert (effective December 2023, updated 2 September 2026). https://www.holoalert.ca/privacy-policy
  19. Presence Sensor FP2, Aqara (checked September 2026). https://www.aqara.com/en/product/presence-sensor-fp2/
  20. Privacy Policy for website visitors, Lumi United Technology / Aqara (checked September 2026). https://www.aqara.com/en/privacy-policy
  21. Nomo Smart Care. https://www.nomosmartcare.com/
  22. Privacy Policy, Nomo Smart Care (checked September 2026). https://www.nomosmartcare.com/pages/privacy-policy
  23. WalledCare product page, Moneli Automation (checked September 2026). https://walledcare.com/
  24. About, Xandar Kardian (checked September 2026). https://website.kardian.com/about/
  25. Xandar Kardian product and app privacy policy (28 December 2018). https://website.kardian.com/privacy-policy/
  26. Vayyar Care consumer documentation (checked September 2026). https://vayyar.com/care-docs/b2c/
  27. envoyatHome FAQs (checked September 2026). https://www.envoyathome.com/faqs/
Published Last reviewed By Moneli Automation editorialNext review 5 March 2027