Guide · Sovereignty

Canadian data hosting: what it changes for a SaaS tool

Data residency has become a buying criterion in Quebec. Here is what 100% Canadian hosting means for a SaaS product and why it simplifies compliance.

"Where is my data hosted?" has become one of the first questions asked when buying software in Quebec — and rightly so. Since the Law 25 reform came into force, hosting data in Canada is no longer a mere marketing line: it directly affects how personal information moves and how much compliance work an organization faces. This guide explains what data residency covers, why it matters, what Canadian hosting actually means for a cloud service (SaaS), and why it must be paired with a no-routing architecture.

In short: data residency refers to the country where your data is physically stored and processed. Law 25 does not mandate hosting in Canada, but it requires an assessment before any transfer of personal information outside Quebec. Choosing a SaaS hosted in Canada — one whose architecture does not route email abroad — avoids that transfer and lightens compliance.

What is data residency?

Data residency refers to the country — sometimes the precise region — where your data is physically stored and processed. A cloud provider runs data centres spread across several continents; the region chosen determines which legal regime governs your information and who could, in theory, access it.

It should be distinguished from two neighbouring notions. Data sovereignty adds the dimension of applicable law: data stored in Canada but held by a company subject to a foreign law may, under certain regimes, be compelled by a foreign government. Processing residency concerns where data is not only stored, but also computed, indexed and backed up. A SaaS product can advertise Canadian storage while routing its backups or its processing elsewhere. For more, see our guide on email data sovereignty.

Why Canadian hosting matters for Law 25

Law 25 — Quebec's reform of personal information protection, administered by the Commission d'accès à l'information (CAI) — does not require organizations to host their data in Quebec or Canada. Many vendors imply otherwise; that is inaccurate. What the law imposes is more nuanced.

Before communicating personal information outside Quebec, an organization must carry out a privacy impact assessment. That assessment considers, among other things, the sensitivity of the information, the purpose of the communication, and above all the legal framework applicable in the destination territory, including the personal-information protection principles that apply there.

In other words, a transfer outside Quebec is not prohibited, but it triggers a duty to analyze, document and sometimes add contractual safeguards. Choosing a provider that hosts data in Canada — and does not move it out of the country — simply removes that trigger for the hosted portion. It is one of the few levers where a technical choice directly reduces the compliance burden.

This article is provided for information purposes and does not constitute legal advice. To assess your situation, consult a legal advisor or the Commission d'accès à l'information.

What "Canadian" hosting means for a SaaS

"Hosted in Canada" can mean a great deal — or very little. For a cloud service, the promise only has value if it covers the full data lifecycle, not just the primary database. The points to cover:

  • Primary storage: the database and files reside in a Canadian region (for example Canada Central or Canada East at the major cloud providers).
  • Backups: security copies also stay in Canada and are not replicated to a foreign region "by default".
  • Processing: indexing, logs and any computation on the data happen in the same region.
  • Subprocessors: the third-party services used (analytics, transactional email, monitoring) do not exfiltrate personal information out of the country.
  • Staff and access: knowing who can access the data and from where is part of the assessment, even though remote access is not strictly a "transfer".

A serious provider documents these elements and writes them into the contract. Without a written commitment, "hosted in Canada" remains an unverifiable claim.

Data residency and no-routing architecture

For an email signature management tool, the residency of the configuration data is not enough on its own. What matters just as much is whether the content of your emails passes through the vendor's servers. Two architectures stand in contrast:

CriterionServer-side (relay)Client-side (add-in)
Email pathEvery message passes through the vendor's serversThe message never leaves Microsoft 365
Content exposed to the third partyYes, to apply the signatureNo
Effect of Canadian hostingPartial: content can still leave the countryComplete: configuration AND content stay in Canada / Microsoft
Transfer outside CanadaPossible if relay servers are abroadAvoided

Canadian hosting combined with a foreign relay leaves a gap: the configuration data is in the country, but every email — often carrying personal information — is routed elsewhere. That is why data residency and a no-routing architecture are complementary safeguards, not interchangeable ones.

ATOM Signatures combines both: configuration data is hosted 100% in Canada, and the signature is inserted client-side by an add-in in Outlook, at compose time. The email is never routed through a third-party server — it never leaves your organization's Microsoft infrastructure.

How to verify where a vendor hosts your data

Before signing, ask precise questions and require written answers. A useful grid:

  1. In which exact region is the data stored? (A country is not enough: ask for the cloud region.)
  2. Where do backups reside, and for how long are they kept?
  3. Which subprocessors handle the data, and in which countries?
  4. Does email content pass through your servers (server-side architecture) or not (client-side)?
  5. Does the contract include a data-deletion clause at the end of the relationship (right to erasure)?
  6. Are these commitments written into the service contract, and not just on a marketing page?

Document these answers in your processing register: they are the evidence that you assessed how personal information moves, which is what Law 25 expects of a diligent organization.

Frequently asked questions

Does Law 25 require hosting data in Canada?

No. Law 25 does not mandate hosting in Quebec or Canada. It does, however, require a privacy impact assessment before communicating personal information outside Quebec. Choosing Canadian hosting avoids that transfer and lightens the compliance burden.

What is data residency?

Data residency refers to the country where data is physically stored and processed. A SaaS product can advertise Canadian hosting while still routing, backing up or processing data elsewhere. You must check the storage region, but also the full path the data travels.

Is Canadian hosting enough if email is routed abroad?

No. Canadian hosting of configuration data does not protect email content if the architecture routes every message through a foreign server to apply the signature. Data residency and a no-routing architecture are two complementary safeguards.

How do I verify where a vendor actually hosts my data?

Ask for the hosting region, the location of backups and subprocessors, and whether email content passes through their servers. Require these commitments in writing in the contract, with a data-deletion clause at the end of the relationship.

Your signature data, hosted in Canada. ATOM Signatures applies your organization's signature in Outlook, client-side, with 100% Canadian hosting — and never routes your email.

Discover ATOM Signatures

Go further: email data sovereignty, the no-routing architecture and Law 25 applied to signatures.

Sources