org.tech / Pulse / Residency Analysis 9 min

Data residency is a choice with a price. Here is the price.

Keeping data in Canada is a legitimate and sometimes necessary decision. It is almost never a free one, and the part that costs is not the part most buyers are looking at.

Key takeaways
  • Federal privacy law does not require Canadian data to stay in Canada. It makes you accountable for it wherever it goes, which is a different and more demanding obligation.
  • Quebec is the real constraint. Law 25 requires a privacy impact assessment before personal information is communicated outside the province.
  • Residency is not immunity from foreign legal process, and foreign legal process is also narrower than alarmist copy suggests. Both halves are true.
  • Storage residency and inference residency are separate settings. Data at rest in Canada tells you nothing about where a prompt is processed.
  • The price is capability. In our generated catalogue of 104 models, 13 process in Canada and every current frontier model routes outside it.

Residency is the most common opening requirement in a first conversation and the one most often stated without a reason attached. "Our data has to stay in Canada" is sometimes a legal obligation, sometimes a contract term, sometimes a board preference, and sometimes an inherited assumption nobody has re-examined since 2018. Those four things have very different prices, so it is worth separating them before deciding anything.

What Canadian law actually requires

Context, not legal advice

This section describes published legislation, regulator guidance and government announcements, with sources. It is not legal advice and it is not a substitute for your counsel, who knows your sector, your contracts and your provincial exposure. Where a bill is before Parliament rather than in force, this article says so.

The operative federal private-sector privacy law is still PIPEDA, built on ten fair information principles and overseen by the Office of the Privacy Commissioner of Canada.1 The important point for this discussion is what it does not say. The OPC's own published guidance is explicit: "PIPEDA does not prohibit organizations in Canada from transferring personal information to an organization in another jurisdiction for processing."2

What PIPEDA does instead is attach accountability to the data rather than to the border. The same guidance says "An organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing," and that organizations should advise customers "that their personal information may be sent to another jurisdiction for processing and that while the information is in another jurisdiction it may be accessed by the courts, law enforcement and national security authorities."2

Read plainly, that is a transparency and accountability obligation, not a geography rule. You may transfer. You must remain answerable, and you must tell people.

Quebec is the real constraint

The closest thing in Canadian private-sector law to a residency-style obligation is Quebec's Law 25. It came into force in three stages, not one: first provisions in September 2022, the majority in September 2023, and data portability on 22 September 2024. Before communicating personal information outside Quebec, an organization must carry out a privacy impact assessment. Administrative monetary penalties can reach 2% of worldwide turnover or $10 million.3

Higher penal figures circulate widely in law-firm summaries. This article cites only the administrative penalty the regulator itself publishes, because that is what could be read directly from the source.

Federal AI legislation, as it actually stands

Bill C-27, which contained the Artificial Intelligence and Data Act and a replacement for PIPEDA's private-sector rules, was never voted down. It died on the Order Paper at committee stage when Parliament was prorogued on 6 January 2025.4 The live bill is C-36, introduced 15 June 2026, which would enact the Protecting Privacy and Consumer Data Act and amend PIPEDA. When checked on 20 September 2026 its status was second reading in the House of Commons.5

The government describes the proposed act as "the most significant change to Canada's private-sector privacy law in over 25 years," creating a new Digital Safety and Data Protection Commission, providing administrative monetary penalties up to $10 million or 3% of global revenue, whichever is greater, and fines up to $25 million or 5% of global revenue, and increasing transparency around automated decision systems including those powered by AI.6 Every verb in that sentence is conditional on purpose. It is a bill, not a law. PIPEDA remains in force.

Alongside it sits a national AI strategy announced on 4 June 2026, with priorities including public trust and Canadian sovereignty, committing the government to modernize privacy and online safety laws.7 A strategy, not a statute.

If you are federally regulated in financial services, one more date matters. OSFI Guideline E-23 on model risk management was published on 11 September 2025 and takes effect on 1 May 2027. It covers traditional actuarial models as well as AI and machine learning, and says that "the extensive use of advanced AI/ML techniques should have correspondingly mature governance and oversight."8 It is not in force today. It is close enough that designing for it now is cheaper than retrofitting.

Residency is not immunity

The strongest argument for keeping data in Canada is usually stated as protection from foreign legal process. It is worth being accurate in both directions here, because the loudest claims on each side are wrong.

The United States CLOUD Act, enacted in March 2018, lets US authorities compel a provider subject to US jurisdiction to produce data in its possession, custody or control regardless of where that data is stored, and allows executive agreements with qualifying foreign governments.9 Storing data in a Canadian region does not by itself place it beyond that reach, because the reach follows the provider's jurisdiction, not the disk.

The other half, from the provider's own published position: the Act "applies to any service provider with operations in the U.S., not just companies with U.S. headquarters"; it "Does not give the U.S. government or any government unfettered or automatic access to data"; the provider says it "will use every reasonable effort to redirect law enforcement to the customer and will notify the customer if legally permitted"; and it states it "has not disclosed any enterprise or government content data stored outside the U.S. to the U.S. government since we started reporting the statistic in 2020."10

Both halves belong in the same paragraph. Residency does not remove the exposure, and the exposure is narrower than the marketing on either side suggests. The honest mitigation to point at is not geography. It is keys: encryption with customer-managed keys under your own control changes what a compelled production can actually yield, which is why key custody is a posture-tier decision here rather than a footnote.

What Ottawa means by sovereign

Canada is spending real money on sovereign compute, and the way the government defines the word is more useful to a buyer than the dollar figures. Its infrastructure programme requires a "Canadian-located, Canadian-governed system that ensures data residency, operational control, and decision-making authority and agency remain in Canada."11

Three tests, and location is only the first. An organization that stores in Canada but cannot see its own configuration, cannot change its own policy and cannot leave its vendor has satisfied one of the three. That is a more demanding and more useful standard than a region setting, and it is the standard I would encourage any buyer to apply to a vendor claiming sovereignty.

On the money, one caution: the 2024 strategy committed $2 billion over five years across three streams, and Budget 2025 proposed $925.6 million over five years for large-scale sovereign public AI infrastructure, of which $800 million came from funds previously provisioned.11 Those figures overlap. Do not add them together, as a good deal of commentary has.

Two different residencies

Here is the distinction that most residency conversations skip, and it is the one that actually determines what you can use.

Storage residency is where your documents, indexes, user records and logs sit at rest. It is a per-deployment choice, it is easy to verify, and it is what most people mean when they say their data stays in Canada.

Inference residency is where a prompt is processed when a model answers it. It is a separate setting, it is invisible from the storage configuration, and by default across this industry it is not pinned at all. Managed model services commonly route requests across regions for capacity, and at least one provider documents the case plainly: prompts and responses are processed within the customer-specified geography "unless you are using a Global or DataZone deployment type," in which case they "may be processed in any geography where the relevant model sold by Azure is deployed."12 The same kind of distinction exists at the other providers.

So a deployment with data at rest in Canada, under a default profile, has inference wherever the provider routes it. That is not a scandal and it is not a secret, but it is very often not what the buyer believes they bought. Ask any vendor for the two settings separately, and ask which one their residency claim refers to.

What pinning actually costs

Our model catalogue is generated by script from the provider's live catalogue and classified by where inference actually runs. Nobody types model names into copy here: a hand-maintained list goes stale within weeks, and a stale list in a compliance conversation is worse than no list.

At the 5 September 2026 generation the catalogue held 104 active models from 18 labs. From the point of view of a Canadian deployment: 13 process in-region in Canada, 1 is routed within Canada only, 18 are reachable but processed outside Canada, and 72 are served from United States and global regions.

The thirteen are the whole story. The in-Canada generation set is previous-generation: Claude 3 Sonnet and Haiku, Llama 3 8B and 70B, Mistral Large 24.02, Mixtral 8x7B, and Mistral 7B. Every current frontier model routes outside Canada.

That is the price, stated as plainly as I know how. Pinning a deployment to Canada is a genuinely enforced control, and it costs you the models most people mean when they say AI. For classification, extraction, routine summarization and a good deal of internal drafting, a previous-generation model is adequate and the trade is easy. For the reasoning-heavy work that made somebody excited about this in the first place, it is not.

Say the quiet part

If a vendor tells you residency is available and does not immediately tell you which models you lose, they have either not measured it or they are hoping the question does not come up before signature. Ask for the list, generated on a date. The right answer to "which models can be pinned to Canada" is a file, not an adjective.

Refused in words, not rerouted

There is a second design decision hiding behind the residency toggle, and it matters more than the toggle itself: what should happen when someone selects a model that has no compliant route.

The convenient behaviour is to route the request to the nearest available region and return the answer. The user is happy, the product looks capable, and the control you sold has quietly not applied. The correct behaviour is to refuse the request with a reason, and to say which models are available instead.

residency pin · canada
REFUSED
invoke --model current-frontier --residency canada
[policy] endpoint regions restricted to Canada
Compliant route inside Canada✕ none published
Fall back to nearest region✕ denied by identity policy
In-region alternatives offered✓ 13 models
Reason returned to the user, not an error code
Refused in words. Nothing left the jurisdiction.
Illustrative outputexit 1
Residency behaviour·A refusal is a feature, a silent reroute is a defect

This is enforced rather than promised: with a residency pin in place, inference outside the configured endpoint regions is denied by cloud identity policy, so a code path that tried to reroute would fail rather than succeed quietly. If you only test one thing about a vendor's residency control, test this one. Ask them to pin a deployment and then ask for a model that cannot comply, and watch what comes back.

Deciding per workload

The mistake is deciding residency once, for the whole organization, at the sensitivity of the most sensitive thing anyone might ever do. That buys a previous-generation model set for the entire company because of one workload. Decide per workload instead.

Workload Reasonable position What you can use What it costs you
Personal information governed by a Quebec assessment Pin storage and inference The 13 in-region models Frontier reasoning quality
Records with government or banking identifiers Pin storage, assess inference In-region set, or a documented transfer An assessment and a written rationale
Internal drafting, summarization, extraction Storage in Canada, inference governed Most of the catalogue A transparency notice to your people
Reasoning over anonymized or public material No pin needed All 104 models Nothing, if the anonymization holds
Code, configuration and technical work Decide on secrets, not on geography Most of the catalogue Discipline about what goes in a prompt

These are starting positions for a conversation with your counsel, not determinations. The column that matters in a review is the last one: a residency decision with no stated cost has not been made, it has been assumed.

Two observations from doing this with real organizations. First, the set of workloads that genuinely require a Canadian inference pin is usually much smaller than the opening statement implies, and finding that out takes about an hour. Second, the transparency obligation the OPC describes is easier to meet than people expect, and meeting it explicitly is often what unblocks the workloads that do not need a pin.

The honest summary

Data residency is configurable, pinned to your region when you need it. That sentence is true and it is incomplete without the next one: pinning costs you the current frontier models, because at the last generation of our catalogue not one of them published a route inside Canada.

Anyone selling you residency as a free checkbox is selling you a setting they have not measured. Anyone telling you residency makes your data untouchable by foreign process is overstating it in the other direction. The defensible position is narrower than both: decide per workload, write down what each decision costs, keep the keys, and insist that a request with no compliant route is refused in words rather than quietly sent somewhere else.

There is a fuller treatment of the account-ownership argument in why your models run inside your cloud, and the product-side detail lives on data residency and posture tiers.

Sources

  1. Office of the Privacy Commissioner of Canada, "The Personal Information Protection and Electronic Documents Act (PIPEDA)," accessed 20 September 2026. priv.gc.ca
  2. Office of the Privacy Commissioner of Canada, "Guidelines for processing personal data across borders," 27 January 2009. Old, and still the OPC's published guidance on cross-border transfers. priv.gc.ca
  3. Commission d'acces a l'information du Quebec, "Principaux changements de la Loi 25," accessed 20 September 2026 (French original; accents dropped here). cai.gouv.qc.ca
  4. Parliament of Canada, LEGISinfo, "C-27 (44-1)," parl.ca; corroborated by Fasken, "Prorogation's Digital Impact: Canada's Digital Bills Set to Die on the Order Paper," January 2025, fasken.com.
  5. Parliament of Canada, LEGISinfo, "C-36 (45-1)," status checked 20 September 2026: at second reading in the House of Commons. parl.ca
  6. Innovation, Science and Economic Development Canada, "Backgrounder: Government of Canada introduces legislation to Protect Canadians' Privacy in the Digital Age," 15 June 2026. canada.ca
  7. Innovation, Science and Economic Development Canada, "Minister Solomon highlights Canada's National Artificial Intelligence Strategy," 5 June 2026. canada.ca
  8. Office of the Superintendent of Financial Institutions, "Backgrounder: Guideline E-23 - Model Risk Management," 11 September 2025, osfi-bsif.gc.ca; and "Guideline E-23 - Model Risk Management (2027)," osfi-bsif.gc.ca. Effective 1 May 2027.
  9. United States Department of Justice, "Promoting Public Safety, Privacy, and the Rule of Law Around the World: The Purpose and Impact of the CLOUD Act," white paper, 10 April 2019. justice.gov (PDF)
  10. Amazon Web Services, "AWS and the CLOUD Act," FAQ dated June 2025. A provider describing its own position, quoted here in full rather than selectively. aws.amazon.com
  11. Innovation, Science and Economic Development Canada, "AI Sovereign Compute Infrastructure Program," page modified 1 June 2026, ised-isde.canada.ca; "Canadian Sovereign AI Compute Strategy," page modified 4 June 2026, ised-isde.canada.ca; Government of Canada, Budget 2025, Chapter 1, budget.canada.ca. The 2024 strategy and the Budget 2025 figure overlap and must not be summed.
  12. Microsoft Learn, "Data, privacy, and security for Foundry Models sold by Azure in Microsoft Foundry," last updated 5 June 2026. learn.microsoft.com
S·H

Samuel Hebeisen is the founder of org.tech, a managed service provider for private AI operated by Mind Model AI Inc. in Ontario, Canada. He is not a lawyer, which is why this article cites regulators and statutes rather than paraphrasing them.

The rest of the argument.

PULSE · KEEP READING
⎯⎯ Book the strategic assessment ⎯⎯

Your private AI, inside your control ·

We will take your actual workloads and produce a residency position for each one, with the model set it leaves you, generated rather than asserted.