← Back to Insights
Insight

how-quebecs-law-25-interacts-with-the-us-cloud-act

By Augure·
Insight

Quebec's privacy law and the US CLOUD Act do not talk to each other. They just both apply, at the same time, to the same piece of data. If you store customer data with a US-based cloud or AI provider, Quebec law makes you responsible for what happens to it, while US law gives American courts a way to reach it anyway.

That is the whole problem in two sentences. The rest of this is what it means for a business that just wants to use AI tools without stepping on a landmine.

What does the CLOUD Act actually do?

The US CLOUD Act, passed in 2018, lets US law enforcement compel American companies to hand over data those companies control. It does not matter where the server sits. Microsoft, Google, OpenAI, Amazon: if the company is American, a US court order can reach data on their infrastructure whether that infrastructure is in Virginia or Montreal.

This surprises people because they assume "data centre in Canada" means "Canadian rules only." It does not. The CLOUD Act follows the company, not the country the server happens to be in. A Canadian data centre owned by a US company is still a US company's data centre for legal purposes.

It's worth being clear about what the order process looks like, because "a court can compel disclosure" sounds abstract until you see the shape of it. US law enforcement applies to a US court, the court issues an order or warrant addressed to the company, and the company is legally required to comply whether the data sits in Ohio or Ontario. The company can challenge the order if it believes the request conflicts with the law of the country where the data lives, but that challenge happens after the order is issued, not before. There's no requirement that the customer, or the business that owns the customer relationship, be notified first.

Why does Quebec's privacy law care about any of this?

Quebec's privacy law puts real obligations on any organization handling personal information about Quebec residents, no matter where that organization is headquartered. If you send customer data to a vendor outside Quebec, you're expected to assess the privacy protection that data will receive once it leaves.

That assessment gets harder when the vendor is American. You have to think about not just their privacy policy, but whether a foreign government can compel disclosure regardless of what that policy says. Most businesses never do this assessment. Most businesses also don't know they're supposed to.

There's a fine involved if you get this wrong at scale, into the tens of millions of dollars for serious violations by large organizations. For a nine-person shop, the realistic risk isn't a headline fine. It's a complaint, an investigation, and the time that eats.

The fix costs nothing to start and takes about twenty minutes: check where your AI tools actually process your data.

Does using a US AI tool put me offside Quebec's law right now?

Not automatically. Using American software isn't illegal. What Quebec's law asks for is that you know where the data goes, tell people when it leaves Quebec in a way that matters to their privacy, and make a reasonable judgment about the risk.

Most small businesses skip that step because their AI tool's terms of service don't make the data flow obvious. Read the sub-processor list, if there is one. If you can't find where inference actually happens, that's worth noting, because it means you can't currently answer the question either.

This is also where the Canadian AI conversation stops being abstract. A Canadian AI platform with no US parent and no US investors means customer content isn't sitting in a system a US court order can reach. That doesn't erase your Quebec compliance work — you still need your own assessments — but it removes one category of exposure.

What does a Canadian AI platform actually change?

It changes who can be legally compelled to produce your data, and under whose law. Augure is a Canadian company operating under Canadian jurisdiction. Customer conversations, documents, and AI inference run on Canadian infrastructure or with vetted EU partners under zero-data-retention terms, never on US-jurisdiction providers, so the CLOUD Act's reach over US-controlled providers doesn't extend to that content.

To be precise about it, because vague claims are worse than specific ones: some Augure model tiers run inference in Canada, others run on EU infrastructure, and the EU partners also handle failover. There's limited US processing too, for payment card networks and email delivery, the ordinary stuff every SaaS business runs on. All of that is documented in the privacy policy rather than buried. Disclosing it is the point — the comparison that matters is against tools that are fully US-hosted, not against some fictional standard of zero cross-border data ever.

A skeptical reader might ask: doesn't EU processing raise the same problem, just with a different foreign government? Not the same one. The EU partners operate under zero-data-retention agreements, and the legal mechanism that worries people about US providers, a domestic court ordering an American company to hand over data it controls, doesn't have an EU equivalent that reaches this setup. That's a difference in legal exposure, not a promise that EU law never touches anything.

Augure starts free, with 50 messages a day and 5 documents on the no-cost plan. Paid tiers start at $20 a month for a small team that wants persistent memory and no message caps. None of that buys you a compliance guarantee. No vendor can sell you one. But it does mean your customer content isn't sitting under a jurisdiction that can be compelled to hand it over on America's terms.

Do I need to rip out every US tool I have?

No, and anyone telling you that is selling something. What you need is a clear picture: which tools touch personal information, where that data actually lives, and whether you've documented a reasonable basis for using them. For high-sensitivity data — health records, financial details, anything about a minor — the calculus shifts toward Canadian or EU-based options. For a shared spreadsheet template, it probably doesn't matter much at all.

Most businesses have never mapped this out, and mapping it out is more useful than switching vendors reflexively. Some tools you'll keep. Some you'll swap. The map comes first.

What to do this week

  • List your AI and cloud tools. Write down every tool that touches customer or employee personal information, and note the vendor's country of incorporation.
  • Check one privacy policy. Pick your most-used tool and find its sub-processor or data-location section. If you can't find it in five minutes, that's your answer.
  • Try a Canadian AI tool for one task. Open an Augure account, free, and run a week's worth of document questions or drafting through it instead of your usual tool. See what changes.

None of this fixes Quebec compliance in an afternoon. But it turns a vague worry into three concrete facts you can act on, which is most of the work anyway.

Full details on how Augure handles data, models, and pricing are at augureai.ca.

Where this comes from: Quebec's privacy law allows administrative monetary penalties up to $10 million or 2% of worldwide turnover for organizations, whichever is higher, for serious breaches. The US CLOUD Act was enacted in 2018 and applies to data controlled by US-based companies regardless of storage location.

A

About Augure

Augure is a sovereign AI platform for regulated Canadian organizations. Chat, knowledge base, and compliance tools — all running on Canadian infrastructure.

Ready to try sovereign AI?

Start free. No credit card required.

Get Started