SOC 2 and Canadian data residency
No Trust Services criterion says where your data must live. Data residency arrives through contracts, procurement policies and two provincial statutes, and it is answered from your system description rather than from the auditor's opinion.
There is no SOC 2 data residency requirement. Not in the Security criteria, not in Privacy, not anywhere in the 2017 Trust Services Criteria as revised. An auditor will test that you host where your system description says you host, and will say nothing about whether that location is acceptable. The requirement, when it exists, comes from a contract clause, a public sector procurement rule, or one of two provincial statutes, and it is a commercial question you answer before the audit rather than through it.
The cost of getting it wrong is asymmetric. Committing to Canadian residency you do not need adds real money to your hosting bill forever. Discovering in a security review that you promised it in a signed agreement and did not deliver it is a contract problem an audit report will not help with.
2 Provinces with a statutory residency rule, and both are about public bodies
Who actually requires Canadian data residency?
A much shorter list than the sales objection suggests. Work down this table before you price a migration.
| Source | Binding? | What it really says |
|---|---|---|
| Nova Scotia PIIDPA | Yes, for public bodies and their service providers | Personal information in the custody of a public body must be stored in and accessed only from Canada, with narrow exceptions |
| British Columbia FIPPA | Yes, but relaxed since 2021 | The absolute storage-in-Canada rule was removed. Public bodies must now do a privacy impact assessment for disclosure outside Canada. Many BC entities keep the old rule as internal policy anyway |
| Quebec Law 25 | Yes, as a process duty | Not a residency rule. It requires a documented privacy impact assessment before communicating personal information outside Quebec |
| PIPEDA | No | Transfers for processing are permitted. You remain accountable, and you must be transparent about them |
| Ontario PHIPA | No hard rule | Health information custodians must take reasonable steps. Many hospital procurement teams impose Canadian hosting by policy, which is stricter than the statute |
| Federal government suppliers | Depends on the security categorisation | Protected B and above workloads carry Canadian hosting conditions in the contract. Unclassified usually does not |
| An enterprise customer's security schedule | Yes, if you signed it | The most common real source, and the easiest to negotiate before signature and impossible after |
| A prospect asking in a questionnaire | No | Often a checkbox inherited from a template. Ask whether it is a requirement or a preference before you concede anything |
There is no general Canadian law requiring private sector companies to keep personal information in Canada. Sales teams say there is, buyers repeat it, and it is not true. Some of your buyers are bound by the first two rows, and if you sell to them, their obligation becomes your contract term.
What does moving to a Canadian region cost?
The cloud bill is the small part. AWS ca-central-1, Azure Canada Central and Google's northamerica-northeast1 and northamerica-northeast2 regions typically price five to fifteen percent above the large US regions, and they carry a thinner service catalogue, which is the constraint that hurts. Newer managed services land in Canadian regions months or years after they land in us-east-1, so a migration can mean rebuilding a component around a service that is not available to you.
| Line | Range | Note |
|---|---|---|
| Cloud spend uplift, ongoing | 5% to 15% | Per year, forever, on the moved workload |
| Migration engineering | $25,000 to $150,000 | The spread is entirely about whether you have one region hard-coded in anything |
| Subprocessor replacement | $0 to $60,000 | The line people forget. Your analytics, error tracking and support tooling all process customer data somewhere |
| Audit scope change | $3,000 to $12,000 | A second production region is usually a scope increase at your next examination |
| First year, if you commit | $28,000 to $220,000 | Plus the recurring uplift |
Set that against the deal. A $40,000 CAD annual contract does not justify the top of that range. A public sector framework agreement often does.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
The subprocessor problem
Companies move their primary database to ca-central-1, tell the customer they are Canadian-resident, and leave personal information flowing to a US error tracker, a US support desk, a US analytics pipeline and a US email provider. That is not Canadian residency, and a competent reviewer finds it in ten minutes by reading your subprocessor list.
Your subservice organisations are part of the answer whether you list them or not. Before you make any residency commitment in writing, produce the full list of third parties that touch customer personal information and mark the country each processes in. If you cannot produce that list today, that is the project, and it is the same list your vendor management control needs.
Residency and sovereignty are different claims
Residency means the bytes sit in Canada. Sovereignty means no foreign government can compel access to them. Data in a US-operated cloud region inside Canada satisfies the first and does not fully satisfy the second, because the operator remains subject to US legal process. Sophisticated Canadian public sector buyers now ask the second question. If you answer it by repeating the first, you will be caught. Say which one you can offer.
How to write it in your SOC 2 report
This is where the audit does help you, and it is underused. The system description in Section 3 of a Type 2 report is yours to write, and a reviewer reads it more carefully than the opinion. Name the regions. Name the subservice organisations and their processing locations. State what is replicated where, including backups, which is where residency claims usually break.
Written that way, one document answers the residency question for every prospect and does it under an auditor's examination of whether the description is fairly presented. Written vaguely, every prospect asks separately and your sales engineer answers differently each time. Reading a report properly covers what else a reviewer looks for in that section, and the annotated example shows the shape of it.
What to say when a prospect asks
- Ask whether Canadian residency is a contractual requirement or a preference, and ask them to point at the clause. Half the time there is no clause.
- If there is a clause, ask what triggers it: their own statute, a customer of theirs, or an internal policy. A policy can be varied by the person who wrote it.
- Ask what they need residency to achieve. If the real concern is US government access, tell them so, because encryption with customer-held keys sometimes answers that better than a region move.
- Offer what you have today in writing, with the region names and subprocessor countries, rather than a yes or a no.
- If the deal genuinely needs it, price the migration against the contract value before anyone promises a date.
The case for moving anyway
Everything above argues against reflexive migration. If you sell into Canadian healthcare, Canadian public sector, or Quebec at all, residency questions arrive in almost every deal, and answering each one individually costs sales engineering time that eventually exceeds the migration. Being able to say yes in the first email is a real commercial asset, and the companies that moved early rarely regret it. The decision turns on the shape of your pipeline, not on the statute.
Get quotes from Canadian firms
Firms that have taken Canadian-hosted companies through a SOC 2 examination and know how the regions read in a system description.
Get matchedDoes SOC 2 require data to be stored in Canada?
No. No Trust Services criterion mentions a storage location. An auditor tests that your hosting matches what your system description says. Any residency requirement you face comes from a contract, a public sector procurement rule, or a provincial statute that applies to your buyer.
Is it legal to host Canadian customer data in the United States?
For private sector companies, generally yes. PIPEDA permits transfers for processing provided you remain accountable and are transparent about them. Quebec's Law 25 requires a documented privacy impact assessment before the transfer. Nova Scotia's PIIDPA restricts storage outside Canada for public bodies and their service providers, and British Columbia requires a privacy impact assessment for public bodies.
How much does moving to a Canadian cloud region cost?
Expect $25,000 to $150,000 CAD in engineering for the migration, a five to fifteen percent ongoing uplift on cloud spend, and a possible audit scope increase of $3,000 to $12,000 CAD. The subprocessor replacements are the line most companies leave out of the estimate.
Where does a SOC 2 report state where our data is hosted?
In the system description, usually Section 3 of a Type 2 report. You write that section and the auditor examines whether it is fairly presented. Name your regions, your subservice organisations and their processing locations, and say where backups are replicated.
Does hosting in ca-central-1 satisfy a data sovereignty requirement?
It satisfies residency, not sovereignty. A US-headquartered cloud operator remains subject to US legal process regardless of where the region sits. If a buyer's real concern is foreign government access, say which of the two you can offer rather than answering a sovereignty question with a residency answer.