By

Adam Simmons

· Last checked

August 2026

Is my client data stored in Canada?

Is my client data stored in Canada?

Is my client data stored in Canada?

Usually the honest answer is 'partly, and you would have to ask.' Here is what the statutes actually say about where information may go, and the four questions that get you a real answer from a vendor.

Usually the honest answer is 'partly, and you would have to ask.' Here is what the statutes actually say about where information may go, and the four questions that get you a real answer from a vendor.

Usually the honest answer is 'partly, and you would have to ask.' Here is what the statutes actually say about where information may go, and the four questions that get you a real answer from a vendor.

For most practices the accurate answer is "partly, and you would have to ask the vendor to find out." Software that looks Canadian is frequently assembled from services hosted elsewhere, and the storage location is rarely on the pricing page.

Two separate things get confused here, and separating them makes the rest of the question tractable.

Where information is stored at rest — the database holding your notes, messages and call history.

Where information passes through in transit — the phone network, email delivery, push notifications to your phone. These touch infrastructure in other countries almost unavoidably, and they typically hold nothing for long.

A vendor can be entirely truthful saying "your records are stored in Canada" while text messages transit a carrier in the United States. Both statements can be true at once. So can "we are a Canadian company," which says nothing at all about where the servers are.

For most practices the accurate answer is "partly, and you would have to ask the vendor to find out." Software that looks Canadian is frequently assembled from services hosted elsewhere, and the storage location is rarely on the pricing page.

Two separate things get confused here, and separating them makes the rest of the question tractable.

Where information is stored at rest — the database holding your notes, messages and call history.

Where information passes through in transit — the phone network, email delivery, push notifications to your phone. These touch infrastructure in other countries almost unavoidably, and they typically hold nothing for long.

A vendor can be entirely truthful saying "your records are stored in Canada" while text messages transit a carrier in the United States. Both statements can be true at once. So can "we are a Canadian company," which says nothing at all about where the servers are.

Does the law actually require Canadian storage?

It depends on which law you are under, and the answer is more specific than the folklore suggests.

Ontario's health privacy statute has a section headed "Disclosure outside Ontario." It provides that a custodian "may disclose personal health information about an individual collected in Ontario to a person outside Ontario only if" one of six listed conditions is met — beginning with "the individual consents to the disclosure" (PHIPA, s. 50).

That reads alarming until you reach the regulation, which addresses the case of using a service provider. A custodian who uses services "for the purpose of using electronic means to collect, use, modify, disclose, retain or dispose of personal health information shall not be considered in so doing to make the information available or to release it to that person for the purposes of the definition of 'disclose'" — provided the provider complies with the restrictions the regulation sets out (O. Reg. 329/04, s. 6(4)).

Those restrictions are worth reading directly. The provider "shall not use any personal health information to which it has access in the course of providing the services... except as necessary in the course of providing the services," and "shall not disclose any personal health information to which it has access in the course of providing the services" (s. 6(1)).

Quebec is the clearest case in the other direction. Its private-sector privacy act provides: "Before communicating personal information outside Québec, a person carrying on an enterprise must conduct a privacy impact assessment," taking into account the sensitivity of the information, the purposes, the protection measures "including those that are contractual," and "the legal framework applicable in the State in which the information would be communicated." The section adds that "the same applies where the person carrying on an enterprise entrusts a person or body outside Québec with the task of collecting, using, communicating or keeping such information on his behalf" (Act respecting the protection of personal information in the private sector, s. 17).

None of the statutes quoted above requires client records to be physically stored in Canada. Where a Canadian-storage rule does exist, it comes from a College.

Nova Scotia's counselling therapy College publishes the strictest version: registrants providing telecounselling are responsible for ensuring that the electronic communication platforms they use are "hosted on servers housing data exclusively within Canadian jurisdiction" (NSCCT, Interjurisdictional Telecounselling).

Ontario's social work standards stop short of the border and set a test about the destination instead: client information must be "stored in a jurisdiction where the privacy laws are consistent with Ontario laws or, where applicable, Canadian federal laws" (OCSWSSW 5.3.1).

Which means the honest answer to "does the law require it" is: your College might, and yours is the one to read. That is a question for your College or your insurer rather than for a guide.

Then why does everyone care about it?

Because the question you will actually be asked is not "was this lawful." It is "where is your clients' information, and how do you know."

That question comes from a College reviewer, from an insurer, from a client who read something, and increasingly from an employer or agency doing vendor diligence. "Somewhere in the cloud" is not an answer to it. A named country, a named provider and a document you can hand over is.

The four questions that get a real answer

Ask them in writing, and keep the reply.

Where is the database that holds client records, by country and region? Not "North America." A region.

Which other companies touch client information to deliver the service, and where are they? Every product has a supplier list — telephony, email, hosting, payments. A vendor who will not enumerate it is telling you something.

How long is information held by each of them, and what deletes it? Retention at the telephony layer is a common blind spot: the recording of a call can outlive the transcript you kept.

Will you put that in writing in an agreement I can show a reviewer? This is the one that separates marketing from commitment. See what a data processing agreement is for.

What a good answer looks like

Specific, boring, and slightly unflattering. A vendor who says "records are in Canada, telephony is in the United States and recordings are deleted after thirty days" is being more useful than one who says "fully Canadian and secure," because the first can be checked and the second cannot.

If a vendor's answer is uniformly reassuring with no exceptions anywhere, that is worth a second question rather than relief.

About Rivet

Rivet is a Canadian practice line built for therapists — a separate number for calls, texts and voicemail, with video sessions and clinical tools in the same place. Your data stays in Canada, and transcription runs on Rivet's own hardware rather than a third-party AI service.

One plan, $65 CAD a month, everything included. Fourteen-day trial, no card.

See what's included · Start the trial

Where this comes from

Where this comes from

Where this comes from

See what’s included

See what’s included

See what’s included