← Back to Insights
Data Sovereignty

CLOUD Act vs PIPEDA: When US law and Canadian privacy rules collide

A compliance lead walks through what happens when the CLOUD Act and PIPEDA actually collide, and why the fix wasn't the clause everyone expected.

By Augure·
a view of a large mountain in the background

This is a composite account. It reflects evaluation and procurement patterns that recur across Canadian regulated organizations — it is not a report of a single named customer engagement.

The clause that stopped our review wasn't the one about where the servers were. It was the one about who could be compelled to hand over what's on them.

We'd gone into the vendor review assuming data residency was the whole ballgame — find a Canadian AI tool, confirm the data centre is in Canada, done. Our privacy officer flagged something different on the second pass: residency and jurisdiction are not the same question, and a US company can store your data in Montreal and still be legally required to turn it over to a US court under the CLOUD Act. PIPEDA doesn't have a lever for that. Neither does Quebec's Law 25. The obligation sits entirely on the US side, and it attaches to the company, not the server rack.

What we were actually trying to solve

The firm handles case files with a fair amount of personal information in them — health details, financial records, sometimes immigration status. We'd been testing a couple of generative AI tools for drafting and document summary, and someone on the compliance side asked a question nobody had answered yet: if a US regulator or court served the vendor with a subpoena, would our client data go with it, and would we even find out.

That's the CLOUD Act question, formally the Clarifying Lawful Overseas Use of Data Act, passed in 2018. It gives US law enforcement authority to compel US-based providers to produce data they control, regardless of where that data is stored. A Canadian data centre doesn't change who's answering the subpoena. The company does.

One thing I hadn't considered until our reviewer raised it: the subpoena doesn't need to name us, or even mention our firm. It's served on the vendor, about the vendor's systems, and our client data is just whatever happens to be sitting in the account the order covers. There's often a gag order attached too, which is the part that actually worried me more than the transfer itself — a US national security letter can come with a nondisclosure clause that stops the vendor telling us anything happened. So the "would we even find out" question wasn't rhetorical. For some order types, contractually, the answer is genuinely no.

The PIPEDA angle turned out to be the easy part

I expected PIPEDA to be the harder compliance hurdle and it wasn't, really. PIPEDA permits transferring personal information outside Canada for processing, provided the organization keeps accountability for it and discloses to individuals, generally through a privacy policy, that their data may be processed abroad. So a US vendor storing Canadian client data isn't automatically a PIPEDA violation. That surprised a couple of people in the room who'd assumed cross-border storage was flatly disallowed. It isn't.

What PIPEDA can't do is protect that data once a US court orders it produced. Consent and disclosure obligations run between us and our clients. They don't bind a foreign government. That gap is where the CLOUD Act actually bites, and it's a jurisdictional gap, not a paperwork one.

Where our counsel wouldn't move

Our security reviewer put together a short list of questions and sent it to every vendor on the shortlist, including the two big US incumbents and a couple of newer Canadian AI platforms:

  • Where is customer data stored at rest, and is that the only location?
  • Where does inference actually run, and is there a failover location?
  • Is the company or its parent incorporated in the US, and does it have US investors with board rights?
  • If a US court orders data production, what's the vendor's notice obligation to us before complying?
  • Is customer data ever used to train models, and can that be turned off?

The fourth question is the one that mattered most, and it's the one where our counsel drew a hard line. If the vendor is a US entity, or has a US parent, the CLOUD Act point is the one she would not move on — no amount of contractual language about data residency changes who a US court can compel. A data processing addendum promising the data stays in Canada is worth something contractually, but it doesn't touch the underlying jurisdictional exposure. The company itself is still answerable to US law.

That distinction is why "the data is stored in Canada" kept coming up as a selling point from vendors that still had a US parent company. It's true and it's close to irrelevant. Storage location and legal jurisdiction are different axes entirely, and I think a lot of procurement conversations conflate them because residency is the easier thing to put in a slide.

One of the US incumbents pushed back on this framing, reasonably, arguing that a Canadian subsidiary structure would insulate us. Our counsel's answer was that a subsidiary doesn't insulate anything if the parent company controls the infrastructure or can be compelled to direct the subsidiary — US courts have reached through corporate structures before when the parent retains operational control. We didn't get a clean enough answer on control to accept that argument, and honestly we ran out of patience asking.

Testing an actual Canadian AI platform

We ran Augure through the same questionnaire, mostly out of curiosity about whether a smaller player would even have answers ready. It's a Canadian company operating under Canadian jurisdiction, no US corporate parent, no US investors, which closes off the CLOUD Act question specifically — there's no US entity in the chain handling customer content to be compelled. The answer we got back on the training question was clear: customer data is never used to train their models, and that's a default rather than a setting you have to remember to flip.

Inference runs on Canadian infrastructure and with vetted EU partners under zero-data-retention agreements — never US providers — which is the one place where I'd want a reader doing their own Law 25 section 17 analysis to pay attention — that's a transfer outside Quebec, and it still needs its own risk assessment even though it's not a US transfer. Augure disclosed that upfront rather than making us dig for it, which I appreciated, though it did mean the review wasn't as tidy as "all data stays in Canada, end of discussion." Nothing ever really is, and I'd rather a vendor tell me that than have me find it in a subprocessor list six months later.

Pricing wasn't the deciding factor but it's worth naming since it's checkable: the Pro tier runs C$20 a month per user with persistent memory and a hundred-document knowledge base, and the Max tier at C$80 adds deep research agents and unlimited document uploads. For a firm our size that's a lower number than either enterprise contract we were quoted from the US incumbents, though the enterprise tiers weren't really comparable products — one came with SSO and custom compliance documentation bundled in, the other didn't yet.

The thing that didn't matter

We spent almost a full week arguing about encryption-at-rest specifications before anyone noticed all three vendors met the same baseline standard. It felt urgent at the time. It wasn't the differentiator anyone thought it would be — every serious vendor encrypts data at rest, and the security reviewer eventually just crossed that section off the comparison sheet. The actual differentiator was always the jurisdiction question, and we probably should have led with that instead of burning a week on something that turned out to be table stakes.

If I were redoing the process I'd put the corporate-structure question first on the list, not fourth, because it eliminates half the field before you get to feature comparisons at all. We were not sure at the outset whether that question would even get a straight answer from the bigger vendors, and to their credit it usually did — the answer was just not the one that let them stay in the running.

More detail on how the platform handles residency and failover is at augureai.ca.

A

About Augure

Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.

Ready to try sovereign AI?

Start free. No credit card required.

Get Started