Doing Business In..._2026

CANADA Trends and Developments Contributed by: Brent Arnold, Carole Piovesan, Tamara Adler, Michael Pascu and Dilan Brar, INQ Law

Cross-border data risks A pressing concern for multinational organisations is who can compel access to the data they have. Stor - age of data or transferring data to other jurisdictions means potentially being subject to foreign access laws. The US CLOUD Act allows American authorities to require disclosure of data in the possession, cus - tody or control of US-based companies, regardless of where that data physically sits. Information stored in a Canadian data centre may still be at risk of access if the provider is a US-parented cloud or technology firm. This creates a direct, unresolved tension in Canada. An honest assessment of a US-controlled provider may struggle to conclude that “equivalent protection” exists, because the data remains exposed to foreign legal process that Canadian law cannot override. This may add another legal consideration for vendor selec - tion. Artificial intelligence as a cross-border data engine Adopting AI is, almost always, a decision to move data, frequently offshore and under foreign jurisdic - tion. This is the area businesses most often overlook. The questions that matter most are practical: • Training data – Is Canadian personal information being sent abroad to train a model, and on what legal basis? • Where the model runs – Processing data through a foreign-hosted system is itself a cross-border transfer, even if the user is in Canada. • Automated decisions – Where AI informs decisions about individuals, transparency and human-over - sight expectations apply, and these are harder to meet when the system is operated abroad. • Vendor due diligence – The jurisdiction and corpo - rate ownership of an AI provider now carry direct privacy consequences. Using AI without asking where the data goes, and whose laws govern it, is a compliance problem wait - ing to happen. Upcoming changes and considerations The most significant upcoming change with possible cross-border data implications is the federal govern -

al information outside Canada, a flexibility that has suited businesses well. However, federal and provin - cial privacy laws, as well as the use of AI, do create requirements and considerations organisations should be aware of. For any organisation moving data into or out of Canada, understanding what requirements they are subject to is a necessity. The PIPEDA baseline Under PIPEDA, there is no general restriction on trans - ferring personal information outside Canada. Instead, the law follows a principle of accountability: organisa - tions that collect data remain responsible for it, wher - ever it travels. In practice, a business must ensure that any foreign service provider offers a comparable level of protection to that offered by PIPEDA, and it must be transparent in letting individuals know that their information may be processed and accessed outside the country. In practice, the limitation of this is enforcement. The federal privacy regulator has historically been able to investigate and make recommendations, but not to issue binding orders or significant penalties. This has led to the real pressure on cross-border transfers increasingly coming from the provinces rather than from Ottawa. Provincial requirements Businesses often assume cross-border rules are a federal matter, but that is not exclusively the case. Quebec, Alberta and British Columbia each have their own private-sector privacy laws which supplant PIPE - DA, and Alberta is expected to strengthen its regime in 2026 based on their 2025 review of their privacy laws. Quebec’s Act Respecting the Protection of Personal Information in the Private Sector (Law 25) is one of the most stringent privacy laws in Canada. Law 25 treats a transfer from a Quebec office to one in Ontario in much the same way as a transfer overseas, with obligations applying the moment the data leaves the province. Before transferring personal information out of Quebec, an organisation must carry out a PIA and satisfy itself that the receiving jurisdiction offers equivalent protection. For any company with a Que - bec footprint, this has become the practical national standard.

157 CHAMBERS.COM

Powered by