Nearshore for United States buyers
Data residency and cross-border transfer, in plain terms
For most US buyers the security review is where a nearshore decision is won or lost. This page sets out where the data physically sits, how PIPEDA meets your own privacy expectations, how a cross-border transfer is structured and what your questionnaire will ask.
Where the data physically sits
The plain answer is that data handled by Canadian delivery stays in North America. It is processed by teams in Ontario, Quebec and Alberta, and where you require it, Quebec engagement data stays in Quebec. It does not cross an ocean and it does not transit jurisdictions your customers would object to. That single fact removes the objection that ends many offshore conversations, because the data has not left the continent your business and your customers sit on.
Physical location is not only about the country on a map. It is about which laws govern the data, which courts have reach over it and who can compel its disclosure. Because Canadian delivery keeps the data in Canada under Canadian law, the answer to each of those questions is a familiar and predictable one for a US buyer, rather than an unknown that a security team has to investigate from scratch.
PIPEDA and how it meets US expectations
The Personal Information Protection and Electronic Documents Act, PIPEDA, is Canada's federal private-sector privacy law. It governs how organisations collect, use and disclose personal information in the course of commercial activity. Its core requirements will read as familiar to any US privacy or security professional: obtain consent, limit collection and use to identified purposes, protect information with safeguards proportionate to its sensitivity, keep it accurate, allow individuals to access their own data, be accountable for information handled by a service provider on your behalf and report breaches that pose real risk.
This familiarity is the practical advantage. A US security questionnaire is built around consent, purpose limitation, safeguards, breach handling and vendor accountability, and PIPEDA is built around the same ideas. Alignment is therefore a matter of documenting how the Canadian operation meets each expectation, not reconciling two incompatible legal worlds. Where your own sector adds requirements, such as payment, health or financial data rules, the relevant framework is applied on top of the PIPEDA baseline and its scope is confirmed on request.
Quebec adds a second layer. Quebec Law 25 is the most demanding privacy law in the country and applies to engagements delivered from Quebec. It strengthens consent, requires privacy impact assessments in defined circumstances, tightens breach notification and adds obligations around automated decision making and the transfer of information outside Quebec. Where Law 25 applies we apply it, and Quebec-facing work is designed to meet it rather than retrofitted to it.
How a cross-border transfer is structured
Some engagements are delivered entirely in Canada and no transfer question arises. Others use the hybrid blend, where a Canadian core team handles the sensitive work and global-network capacity handles high volume work that does not need to be Canadian. Where any data is supported from outside Canada, the transfer is structured and documented before go-live rather than left to chance.
Structuring a transfer means being explicit about four things: what categories of data leave Canada, to which locations, under what contractual safeguards and with what limits. Adjudicative and regulated tasks stay in Canada. High volume, low-sensitivity work can be supported from the network under written safeguards that bind the receiving location to the same standard. The position is written down, shared with your team and reflected in the contract, so there is no gap between what was agreed and what happens in practice. Under PIPEDA the accountability for personal information stays with the organisation that holds the relationship, which is why the transfer position is documented to your review rather than assumed.
What your security questionnaire will ask
A US buyer's security and privacy questionnaire is predictable, and Canadian delivery is designed to answer it cleanly. These are the questions that come up on almost every review, with the shape of the answer.
Where is our data stored and processed?
In Canada for Canadian delivery, in Quebec where you require it, and never across an ocean without a documented transfer position. Locations are named, not left vague.
Which privacy laws apply?
PIPEDA by default, and Quebec Law 25 for Quebec engagements, plus any sector framework your data requires layered on top.
Do you transfer data outside the country, and how is it safeguarded?
Only where the engagement design calls for it, with the categories, destinations and contractual safeguards documented before go-live and regulated tasks kept in Canada.
How is access controlled and least privilege enforced?
Access is role-based and limited to the data a task requires, within your platforms and under your governance rather than ours.
What is your breach notification process?
Breach handling follows PIPEDA reporting obligations, and Quebec Law 25 where it applies, with notification timelines and responsibilities agreed in the contract.
Are you accountable for subcontractors and network locations?
Yes. Accountability stays with the operation holding your relationship, and any network location is bound to the same standard by written safeguards.
What this is and is not
This page is general information to help a US buyer scope the data question early, not legal advice and not a substitute for your own privacy counsel or a signed data processing agreement. The specifics of any engagement, including the exact residency, transfer and safeguard commitments, are set out in the contract and its schedules and reviewed by both sides. What we commit to here is transparency: the position is documented and shared before go-live, never assumed after it.
Frequently asked questions
Does our data leave North America with Canadian delivery?
No. Data handled by Canadian delivery stays in North America, processed in Ontario, Quebec and Alberta, and in Quebec specifically where you require it. It does not cross an ocean. Where a hybrid engagement supports some work from the global network, the transfer is documented before go-live and regulated tasks stay in Canada.
What is PIPEDA and will our US security team understand it?
PIPEDA is Canada's federal private-sector privacy law. It requires consent, purpose limitation, proportionate safeguards, access rights, vendor accountability and breach reporting, which are the same ideas a US security questionnaire tests for. Alignment is a matter of documenting how the Canadian operation meets each expectation rather than reconciling two different regimes.
What is Quebec Law 25 and when does it apply?
Quebec Law 25 is the most demanding privacy law in Canada and applies to engagements delivered from Quebec. It strengthens consent, requires privacy impact assessments in defined cases, tightens breach notification and adds rules on automated decisions and transfers outside Quebec. Where it applies we design to it rather than retrofit it.
How is a cross-border transfer handled if we use a blend?
It is structured and written down before go-live. We specify what categories of data leave Canada, to which locations, under what contractual safeguards and with what limits. Adjudicative and regulated tasks stay in Canada, and any network location is bound to the same standard, with the position reflected in the contract you review.
Who is accountable for data handled by a subcontractor or network hub?
Under PIPEDA accountability stays with the operation that holds your relationship. Any global-network location supporting the work is bound by written safeguards to the same standard, and the transfer position is documented to your review rather than assumed, so responsibility does not diffuse across the chain.
Is this legal advice we can rely on?
No. This is general information to help you scope the data question early. The specific residency, transfer and safeguard commitments for an engagement are set out in the contract and its schedules and reviewed by your own privacy counsel and ours. What we commit to here is that the position is documented and shared before go-live.
Bring us your security questionnaire
We will walk your privacy and security team through where the data sits, how PIPEDA meets your expectations and how any cross-border transfer is documented before go-live.