Skip to content
Financial institutions and securities registrants

Your regulator isn't asking you where your data is. It's asking you to know, and to prove it.

If you are a securities registrant or an institution regulated by the AMF, no text requires your data to stay in Quebec or in Canada — we checked text by text, including where the opposite is often asserted. If you are federally chartered, the answer changes: s. 239(1) of the Bank Act, and its mirrors in the Insurance Companies Act and the Trust and Loan Companies Act, require the records to be kept in Canada; Guideline B-10 adds that complete electronic copies must sit on a server located here; and s. 245(1) lets the Superintendent order that the PROCESSING of data stop abroad — which is exactly what an inference call routed outside the country is. For everyone, the rest of the requirement is more demanding than an address: document where the data is processed, keep the accountability, never obstruct an inspection, and report an incident within deadlines measured in hours.

Last reviewed:

Who regulates you

The bodies whose requirements apply to you.

  • AMFAutorité des marchés financiers

    Regulates Quebec financial institutions. It imposes a 24-hour incident report by regulation, and publishes guidelines — two of which, on AI and on third-party risk, were adopted in March 2026 and take effect in 2027.

  • CIROCanadian Investment Regulatory Organization

    Regulates investment dealers and mutual fund dealers. Its rules impose a cybersecurity incident report within three calendar days, an investigation report at thirty days, and seven years of retention.

  • CSACanadian Securities Administrators

    Regulation 31-103 and its companion policy govern the compliance system, recordkeeping and outsourcing. Notice 11-348, from December 2024, applies securities law to AI systems.

  • OSFIOffice of the Superintendent of Financial Institutions

    For a federally chartered institution. Guideline B-10 requires your data to be kept separate from other clients' data at all times; B-13 requires robust cryptography, including for data in use.

Requirement by requirement

Each requirement is quoted from its source, then answered.

AMF

Regulation respecting the management and reporting of information security incidents by certain financial institutions and by credit assessment agents, CQLR c A-8.2, r. 0.1, s. 5

doit aviser l'Autorité de tout incident de sécurité de l'information ayant un risque d'occasionner des répercussions négatives qui a été signalé à ses dirigeants ou, selon le cas, à ses gestionnaires au plus tard 24 heures suivant le moment auquel il a été signalé.
What it means
Twenty-four hours, and the clock starts the moment the incident is reported to management — not when it happened. The threshold is low: a mere risk of adverse impact is enough, with no proven harm. Section 3 adds that your policy must cover incidents occurring at a third party to which you have entrusted an activity.
What we answer
The contract obliges us to notify your privacy officer without delay, with the nature of the incident, the people affected, the period, and the measures taken (s. 14.9). We do not yet commit to a number of hours, and our response plan has never been exercised. For an institution subject to section 5, this is a clause to negotiate explicitly in the purchase order — a commitment to act "within a reasonable time" would leave you structurally unable to meet your 24 hours.

hard lawIn force since 23 April 2025Official source

AMF

Information and Communications Technology Risk Management Guideline, "Outsourcing and cloud computing" section

l'institution financière devrait maintenir, dans sa liste centralisée d'ententes d'impartition importantes, toute information utile à la gestion des risques de ses données (nature, sensibilité, emplacement(s) du traitement, de l'emmagasinage et de la circulation des données, etc.)
What it means
This is the AMF's explicit position on cloud computing, and it is written as expectations, not prohibitions: the passage uses "devrait" — should — from beginning to end. What the AMF expects is not that you host here, but that you KNOW and DOCUMENT where the data is processed, stored and moved, that you encrypt it in transit, in memory and at rest, and that the contract provide for a right of audit — "as well as that of the other competent authorities" — and access to premises. The same list also expects four things people forget: an exit plan, mitigation of chained subcontracting, monitoring of concentration risk, and identification of data "sovereignty" risk. And it refers twice to the Outsourcing Risk Management Guideline cited further down.
What we answer
On documentation, this page provides exactly that: the hosting region named — Azure Canada Central (Toronto) by default, a Quebec region under private hosting only —, a request's path described step by step, the distinction between what stays in Canada and what does not, and each model provider's published policies. Encryption in transit and at rest, per-user and per-group access, audit log. The right of audit exists in the contract (s. 14.10), on fifteen business days' notice, once every twelve months — but it is drafted for you alone and does not name your regulators. On the rest, no: no documented exit plan beyond full export, no contractual notice before a sub-processor is added, and neither concentration risk nor sovereignty risk is settled by us — inference runs at foreign providers, several of them in the United States. Nor do we have any SOC 2 or ISO certification to file in your record.

regulator expectationFebruary 2020 — in forceOfficial source

CIRO

Investment Dealer and Partially Consolidated Rules (IDPC Rules), section 3703, paragraph (2)(vii)

(vii) par avis écrit tout incident de cybersécurité, (a) dans les trois jours civils suivant la découverte de l'incident de cybersécurité
What it means
The threshold matters as much as the deadline: section 3703(1) only covers an incident that causes or is likely to cause material harm to a person, that has a significant impact on part of normal operations, that triggers the business continuity or recovery plan, or that requires notice to a government body or an authority. Three calendar days for the initial report, then a full report within 30 calendar days — both deadlines running from the DISCOVERY of the incident, and the second "unless otherwise agreed by the Organization". Scope: section 3703 belongs to the IDPC Rules, which apply to INVESTMENT dealers; the Mutual Fund Dealer Rules contain no cybersecurity incident reporting obligation at all. Finally, CIRO's guidance note specifies that the dealer's "information system" includes components supplied by outsourcers: an incident at your vendor is an incident you have to report.
What we answer
Same answer and same limit as above: notice without delay to your designated officer, with an enumerated content (s. 14.9), but no committed number of hours. For the thirty-day report you will need the root cause and the scope of the incident — these are things we commit contractually to help with, billable beyond our normal obligations unless the incident is attributable to us. Count both deadlines from your discovery, not from our notice: that is what makes the contractual notification deadline decisive for you.

hard lawVersion of 8 January 2026; requirement in force since 14 November 2019Official source

CSA

Regulation 31-103 respecting Registration Requirements, Exemptions and Ongoing Registrant Obligations, s. 11.6(1)

La société inscrite garde les dossiers prévus par la législation en valeurs mobilières : a) pendant 7 ans à compter de la date de leur établissement; b) en lieu sûr et sous une forme durable;
What it means
Seven years, in a safe location and in a durable form, producible to the regulator within a reasonable time and in a format it is able to read. Two points that get skipped too quickly. First, "safe location" has no geographic content — neither the CSA nor CIRO requires these records to be in Canada — but the companion policy does give it content: prevent any unauthorized access, and enter into a confidentiality agreement where a third party may access the documents, which is precisely the case of a hosted platform. Second, CIRO has its own rule, distinct from this one: section 3803 of the IDPC Rules requires an investment dealer to keep a copy of the documentation the Organization requires "in a safe location", "in an accessible and durable form", for at least seven years from its creation. The text served by the link is the New Brunswick FCNB consolidation; in Quebec the applicable instrument is Regulation 31-103, CQLR c. V-1.1, r. 10, whose wording is identical.
What we answer
No purge you can configure will break your seven years, and conversations, documents and attachments export in a readable format. But three automatic deletions apply all the same, and if one of them holds a piece of the regulatory record, it destroys it without regard to your seven years: you have to export it before the deadline. Three timers are hard-coded and reach a record directly — transcripts at 30 days, tool-produced files at 7 days, attachments never sent at 48 hours — and they cannot be switched off; there is no configurable retention and no certificate of destruction. If one of them holds a piece of the regulatory record — a client call transcript, for instance — it destroys it without regard to your seven years. On the "safe location" side: dedicated instance, per-user and per-group access, audit log, and a confidentiality clause in the contract (s. 14), which answers the expected confidentiality agreement. The regulatory record that has to live seven years belongs in your archive; the platform is where the work happens. Those are the timers that reach a record; other clocks exist elsewhere in the product, and the Confidentiality and compliance page publishes the full inventory.

hard lawConsolidation as of 1 January 2026Official source

CSA

Companion Policy to National Instrument 31-103, Part 11, "Business practices – outsourcing"

La société inscrite a la responsabilité de toutes les fonctions externalisées. Elle devrait conclure un contrat écrit ayant force exécutoire et énonçant les attentes des parties à la convention d'externalisation.
What it means
Regulatory responsibility cannot be delegated: it remains the registered firm's, in so many words. The rest of the heading is written as expectations — the firm "should" enter into a written, enforceable contract, carry out documented due diligence before contracting, verify confidentiality and disaster recovery, and review service quality on an ongoing basis. The heading ends with its most demanding paragraph: the regulator, the registered firm and its auditors should have the same access to the service provider's work product as if the activities were carried out in-house, and a clause to that effect should appear in the contract. On top of that comes CIRO Guidance Note GN-2300-21-003 ("Outsourcing arrangements", effective 31 December 2021): never enter into an arrangement that impedes the regulator's effective supervision or allows cascading subcontracting without your knowledge, and notify CIRO of any new arrangement covering a critical activity, under section 2246(2) of the IDPC Rules — that part is hard law. The same note places the management and maintenance of the dealer's information systems among the critical activities.
What we answer
A written, signed contract, with a right of audit (s. 14.10) — but read the limit: it is annual, on fifteen business days' notice, exercisable by you alone, and we may satisfy it with reports and questionnaires. That is less than the REGULATOR's access to the work product described in the heading's last paragraph, and we have no SOC 2 or ISO to offer in its place: the clause has to be extended in the order form. Our sub-processor list is published by role and the named entities are provided under a confidentiality agreement; the contractual notice before a sub-processor is added is dated on our roadmap, it does not exist yet. And if you conclude that the hosting of your information systems is a critical activity, the notice to CIRO is yours to give, before the change.

regulator expectationConsolidation as of 1 January 2026Official source

CSA

CSA Staff Notice and Consultation 11-348 — Applicability of Canadian Securities Laws and the Use of Artificial Intelligence Systems in Capital Markets

S'il est possible que des renseignements sur leurs clients soient saisis dans un système d'IA, il leur faudra prendre les mesures qui s'imposent pour en assurer la confidentialité.
What it means
The notice establishes two things. First, you can outsource support but never an activity that requires registration — suitability, for instance, remains yours. Second, governance must cover "the entire AI system supply chain", including third-party vendors, cloud services and data sources.
What we answer
The chain is described plainly on this page: your instance, our routing layer, the provider of the model selected. The models that can be used are restrictable by group, by named user, or reserved to administrators, with a refusal enforced at call time — it being understood that this refusal binds the models the user picks, and not the few calls the server issues itself, among them the extraction of the text of a document added to a knowledge base or pulled from a connector, and the Law 25 detector; the detail is on the Confidentiality and compliance page. The platform drafts and suggests; it does not render a suitability opinion, and the contract expressly prohibits treating an output as a final decision without human validation.

regulator expectation5 December 2024; consultation closed 31 March 2025, nothing further published as of 6 August 2026Official source

OSFI

Guideline B-10 — Third-Party Risk Management, Principle 7, §2.3.2.1

Le cas échéant, les contrats doivent également préciser que les documents et données de l'IFF doivent être constamment séparés de ceux des autres clients, y compris durant leur transfert ou dans des conditions défavorables (p. ex., interruption de service).
What it means
Here B-10 sets an equivalence test, not a localization one: your data must get the same protection at the third party as it would with you, be kept separate from other clients' data at all times — including in transit and in degraded conditions — and remain available and readily accessible, on request, to the FRFI and to OSFI. But the requirement quoted bears on what THE CONTRACT must specify, not on what the architecture allows. And the rule about place does exist: §2.3.2.2 refers to s. 239(1) of the Bank Act and its mirrors — see the next entry, which deals with it in its own right.
What we answer
The isolation exists in the architecture: each client gets a dedicated instance, with its own database. There is no shared application database across clients, so there is no degraded mode in which your data would sit alongside someone else's. But that is not what the quotation asks for. Our contract carries no continuous-separation clause: section 14 covers confidentiality, purposes, sub-processors, incident notice without delay, the annual right of audit and notice in the event of compelled disclosure — not the separation of records and data, including during transfer. For an FRFI, that is the gap, and it is exactly what B-10 means: the architecture makes the commitment easy to keep, it remains to be written into the contract before signing.

regulator expectationPublished 30 April 2023; in force 1 May 2024Official source

OSFI

Guideline B-13 — Technology and Cyber Risk Management, §3.2.2 and §3.2.5

L'IFF doit mettre en œuvre et maintenir de solides technologies cryptographiques pour protéger l'authenticité, la confidentialité et l'intégrité de ses actifs technologiques.
What it means
§3.2.5 is the one that matters for AI: it requires controls for data at rest, in transit AND in use. It is the regulatory recognition of the third state described on our security home page — the one no encryption protects and that comes down to the contract.
What we answer
At rest and in transit: encryption provided by the hosting platform, TLS 1.2 or higher everywhere, key vault with role-based control. In use: this isn't a cryptography problem but a contract and routing problem, and it's addressed in so many words on the main page — including the fact that we do not yet technically enforce zero-retention routing on every call.

regulator expectationPublished 31 July 2022; in force 1 January 2024Official source

AMF

Guideline on the use of artificial intelligence, section 2 — Scope and effective date

Il importe de préciser que les attentes de la présente portent sur toute utilisation des SIA par l'institution, qu'elle concerne ou non le traitement des dossiers des clients.
What it means
It is not in force — we say so because several vendors already present it as applicable law — and neither are two other texts: the AMF's Third-Party Risk Management Guideline (March 2026, taking effect in 2027 — a date we could not confirm on the AMF's site, which refuses non-browser clients), which will replace the outsourcing guideline cited further down, and OSFI's Guideline E-23 on Model Risk Management, whose final version was published on 11 September 2025 and which takes effect on 1 May 2027. What they announce: regularly inventorying every model and AI system, but entering in the central register only those whose risk the institution judges to be non-negligible; a risk rating; a "review of the AI system components supplied by a third party (platforms, models, data, etc.)" at validation; upstream and downstream isolation of the system; prominent labelling of generated content; and, at §8.3, telling the client they are dealing with an AI system, offering them timely access to a human being, and clearly explaining a decision made or recommended by an AI system. E-23 extends model risk to third-party models.
What we answer
What already exists and serves that preparation: an isolated instance, a model catalogue restrictable by group or by user, provider policies displayed, per-user attribution and audit logging, full export. What will still be missing in 2027 if nothing changes: prompt and model versioning exposed to the client, systematic labelling of generated content, an automatic notice to the client that they are talking to an AI system and an escalation path to a human being, bias-detection tooling, and validation documentation ready to file in your register. Of all of that, only one thing is on our roadmap today: the labelling of generated content. The other four — bias detection, client-exposed versioning, escalation to a human being and validation documentation — are neither shipped nor dated there, and we would rather write that down than leave you following an empty cross-reference. None of it is a matter of your internal policies: these are product features.

regulator expectationMarch 2026 — taking effect 1 May 2027Official source

OSFI

Bank Act, S.C. 1991, c. 46, ss. 239(1) and 245(1)

Les livres sont conservés au siège de la banque ou en tout lieu au Canada convenant au conseil.
What it means
This is the localization rule that genuinely exists in this sector, and it reaches only federally chartered institutions. The same words appear at s. 262(1) of the Insurance Companies Act and s. 244(1) of the Trust and Loan Companies Act, and OSFI's Guideline B-10 adds, at §2.3.2.2, that where the records are electronic, "complete copies must be kept on a server located in the places prescribed by the laws governing FRFIs". It bears on the records referred to in s. 238, not on every piece of data the institution holds. Two extensions matter for an AI platform. Section 245(1) targets PROCESSING and not storage alone: if the Superintendent is of the opinion that processing abroad the information relating to the keeping of the records obstructs his functions, he orders the bank to carry it on only in Canada — and an inference call routed outside the country is exactly that activity. And the exemption at s. 239(3.1), for the subsidiary of a foreign bank from a country covered by a Schedule IV treaty, comes at a price, set out at §2.3.2.2 of B-10: giving OSFI "immediate, direct, complete and ongoing access to the records kept abroad".
What we answer
On keeping the records, our default configuration answers: a dedicated instance hosted on Azure Canada Central (Toronto), a Quebec region under private hosting only, encryption in transit and at rest, per-user and per-group access, audit log, full export at any time. What sits in your instance therefore stays in Canada. On the processing, no, and we do not dress it up: inference runs at foreign model providers, several of them in the United States, and we do not yet technically enforce Canadian routing on every call. For a federally chartered institution the honest reading is this: the hosting satisfies s. 239, the inference leaves Canada, and the exposure under s. 245(1) is yours to assess before entrusting us with information relating to the keeping of your records. The master copy of those records belongs in your archive, not in the platform.

hard lawAct current to 17 June 2026; last amended 26 March 2026Official source

AMF, OSFI and CIRO

Regulation respecting the management and reporting of information security incidents by certain financial institutions and by credit assessment agents, CQLR c A-8.2, r. 0.1, ss. 8, 9, 10 and 11

Une institution financière ou un agent d’évaluation du crédit doit aviser l’Autorité de l’évolution de la situation au plus tard 3 jours suivant l’avis qui lui a été donné en vertu de l’article 5 et au plus tard tous les 3 jours suivant l’avis précédent jusqu’à la transmission à l’Autorité d’un avis confirmant que l’incident est maîtrisé et que les activités ont repris leur cours normal.
What it means
The 24-hour clock in section 5 is therefore not a single deadline, it is the start of a cadence: an update every 3 days until the notice of containment, then a report to the Authority within 30 days of that notice (s. 9: source and type of the incident, assessment of the risk of recurrence, measures taken), then a register (s. 10) that must name, for each incident, "the third parties concerned", the harm, the actions taken and planned, kept securely for at least 5 years (s. 11). Failing to notify within 24 hours and failing to follow up every 3 days are both punishable by an administrative monetary penalty (s. 12). And these are not the sector's only clocks. A federally chartered institution must notify OSFI "as promptly as possible, and no later than 24 hours after the incident" (Technology and Cyber Security Incident Reporting advisory, 13 August 2021), whose reporting criteria expressly include "third-party impacts with consequences for the FRFI", then report periodically until containment. An investment dealer has the 3 calendar days and 30 calendar days of section 3703(2)(vii) of the IDPC Rules, counted from DISCOVERY; a mutual fund dealer, for its part, has no cybersecurity incident reporting obligation at all.
What we answer
The contract obliges us to notify your privacy officer without delay, with the nature of the incident, the people affected, the period and the measures taken (s. 14.9). Three limits to know before signing. We commit to no number of hours, which makes your 24 hours — AMF or OSFI — structurally dependent on our goodwill. Nor do we commit to periodic updates: section 8 asks you to feed the Authority every 3 days with facts that, if the incident happens at our end, only we hold. Finally, our response plan has never been exercised. What we can supply for your register — source, type, third parties concerned, harm, actions taken — falls under contractual assistance, billable beyond our normal obligations unless the incident is attributable to us, and that register has to live five years in your systems: the platform offers neither configurable retention nor a certificate of destruction. Have a deadline in hours and an update cadence written into the order form.

hard lawIn force since 23 April 2025; current to 1 April 2026Official source

AMF

Outsourcing Risk Management Guideline, Principle 4 — Documentation of the outsourcing arrangement

De plus, dans le cas où le fournisseur de services recourt lui-même à l’impartition, l’institution financière devrait s’assurer que le contrat d’impartition identifie les responsabilités du fournisseur de services à cet égard.
What it means
This is the AMF outsourcing text that applies TODAY — the one the ICT guideline refers to twice — and it goes straight at an AI platform's weakest point: chained subcontracting. The expectation is not that your provider stop having subcontractors, it is that the contract identify its responsibilities in that respect. Around that principle, the guideline expects a written service contract whose level of detail follows the importance of the arrangement, the inclusion of risk-mitigation strategies involving the provider, and a clause allowing you to ask it for additional information about the arrangement. Principle 5 adds the monitoring: a centralized list of material arrangements kept up to date, performance indicators defined in the contract, periodic assessment of the provider's financial and operational capacity. All of it is written as "should": these are expectations, not hard law — but the AMF checks them on inspection.
What we answer
Our sub-processor list is published by role, and the named entities are provided under a confidentiality agreement; the contract (s. 14) governs confidentiality, purposes and the use of sub-processors. Two gaps, named plainly: the contract does not identify our responsibilities for the failures of our own sub-processors beyond the general regime, and it provides for no notice before a sub-processor is added — so no right for you to object. Those are the two clauses to have written into the order form if this arrangement goes into your centralized list. We also have neither SOC 2 nor ISO certification to file in your due diligence: this page, the contract and your own questions stand in their place.

regulator expectationApril 2009 — in force today; it will be replaced by the Third-Party Risk Management Guideline (March 2026), whose effective date is announced for 2027 — we could not confirm the exact date at source, the AMF's site refusing non-browser clientsOfficial source

OSFI

Guideline B-10 — Third-Party Risk Management, Principle 8, §2.3.3.3

Le contrat doit donner à l’IFF et au BSIF le droit d’évaluer les pratiques de gestion du risque lié au service fourni. Plus précisément, l’IFF et le BSIF doivent être en mesure d’évaluer les risques découlant de l’entente ou de nommer des auditeurs indépendants pour évaluer les pratiques de gestion du risque lié au service fourni et les risques découlant de la relation au nom de l’IFF ou du BSIF. L’IFF et le BSIF doivent également être en mesure d’accéder aux rapports d’audit du service fourni à l’IFF.
What it means
The right of audit that is expected is not yours: it is yours AND OSFI's, with the ability to appoint independent auditors and to access the audit reports on the service. A clause drafted for the client's sole benefit does not answer it. §2.3.2.2 sets the twin requirement for records: an FRFI that is not required to keep copies in Canada must give OSFI "immediate, direct, complete and ongoing access to the records kept abroad" — immediate and ongoing, which no annual pre-noticed audit provides. On the securities side the expectation is of the same nature: the companion policy to 31-103 wants the regulator, the registered firm and its auditors to have the same access to the provider's work product as if the activities were carried out in-house, and a clause to that effect in the contract.
What we answer
Our contract grants a right of audit (s. 14.10) once every twelve months, on fifteen business days' notice, exercisable by you and satisfiable with reports and questionnaires. It names neither OSFI nor the securities regulator, it is on a cadence, it is pre-noticed, and we have no SOC 2 report or ISO certification to produce instead. Of the three expectations above, it satisfies none as written: this is the clause to rewrite before signing, naming your regulator in it. What does exist and can be demonstrated: dedicated instance, a consultable audit log, per-user and per-group access, full export at any time, and contractual notice in the event of disclosure compelled by a foreign authority.

regulator expectationPublished 30 April 2023; in force 1 May 2024Official source

What stays yours to do

No vendor can carry these obligations for you.

  • Decide whether using the platform amounts to a material outsourcing arrangement or the outsourcing of a critical activity, enter it in your centralized list — and, if you are an investment dealer, notify CIRO before the change under section 2246(2) of the IDPC Rules.
  • Document your due diligence on us before contracting: this page and the contract are inputs to it, not the conclusion; we have neither SOC 2 nor ISO to file in the record.
  • Negotiate, in the purchase order, an incident notification deadline in hours AND an update cadence, both compatible with your own clocks: 24 hours to the AMF, then every 3 days until containment and a report at 30 days; 24 hours to OSFI if you are federally chartered; 3 calendar days and 30 calendar days to CIRO, counted from discovery, if you are an investment dealer.
  • Keep the incident register required by section 10 of the AMF regulation yourself, with the third parties concerned, and hold it five years outside the platform: we offer neither configurable retention nor a certificate of destruction.
  • If you are federally chartered: check that the records referred to in section 238 stay kept in Canada, and assess your exposure under s. 245(1), which targets processing abroad — our inference runs at foreign providers, several of them in the United States.
  • Have the audit clause extended to your regulator: B-10 wants the contract to give the right of assessment to OSFI itself, and the companion policy to 31-103 wants the regulator to have the same access to our work product as if the work were done at your own premises.
  • Name an internal accountable person for the use of AI: as of 1 May 2027, the AMF expects a member of senior management to be accountable for all of the institution's AI systems, and none of that transfers to the vendor.
  • Keep the master copy of your regulatory records in your own archiving system, for the seven years, rather than in the platform.
  • Never let a model output stand in for a suitability opinion or a decision: an activity that requires registration cannot be outsourced.

Questions to ask any AI vendor

Including us.

  • What contractual incident notification deadline will you accept, in hours, given that I have to notify the AMF within 24 hours and CIRO within 3 calendar days?
  • Will you accept, by contract, a right of audit by me or by an independent auditor, and access for the competent authorities?
  • Where exactly is the data processed, stored and routed, and will you notify me of a change of location or of subcontractor, with a right to object?
  • How do you demonstrate that my data is kept separate from your other clients' data at all times, including in transit and in degraded mode?
  • Can you provide me with the list of your system's third-party-supplied components — hosting, models, data — so I can file it in my register?
  • What does exit look like: format, timeline and cost of full retrieval, transition period, and attested deletion?
  • Do you hold a SOC 2 Type II report or an ISO 27001 or ISO 42001 certification, and can you hand it to me? If not, by when?
  • Has your incident-response plan ever been exercised — when, by whom, and with what result?

A vendor that answers yes to everything without evidence deserves more suspicion than one that names its limits.

Frequently asked questions

Does my data have to stay in Canada?
It depends on your charter, and the usual answer — "no" — is only true for part of the sector. For a securities registrant or an institution regulated by the AMF: no, no text requires it; what is required is to know where the data is, to remain accountable for the outsourcing, and to do nothing that obstructs an inspection. For a federally chartered institution: yes, for the records. Section 239(1) of the Bank Act — and its mirrors, s. 262(1) of the Insurance Companies Act and s. 244(1) of the Trust and Loan Companies Act — requires the head office or another place in Canada, and B-10 requires the complete electronic copies to sit on a server located in those same places. Our hosting is in Canada by default, so that point holds; the model's computation, however, leaves the country, and s. 245(1) lets the Superintendent order that it stop abroad. That is the exposure to assess before entrusting us with covered data.
What should be written into the contract before signing?
Three gaps concern you directly and are settled on the order form: we make no quantified commitment on incident notification time or on periodic updates; we provide no advance notice before a change of sub-processor; and our right of audit is drafted for you alone, whereas B-10 and the companion policy to 31-103 also want your regulator to have access. If you are a federal institution, add the continuous data-separation clause B-10 expects of the contract: it is true of our architecture, it is written nowhere.
I also distribute insurance. Is the analysis the same?
No. Section 88 of the Act respecting the distribution of financial products and services adds a rule locating the client record in Quebec, which the AMF, CIRO and CSA rules do not impose. Read the insurance page: it is the sector where location is a provincial obligation rather than an assessment — bearing in mind that if you are also federally chartered, the Bank Act and its equivalents already require the records to be kept in Canada.

Bottom line

No localization rule for you
Neither securities registrants nor institutions regulated by the AMF are caught. A federally chartered bank, on the other hand, must keep its records in Canada (s. 239(1)).
The computation leaves Canada
Dedicated instance and Canadian hosting by default, but the inference call goes abroad — and the Superintendent can prohibit it (s. 245(1)).
What the four regulators want
That you know where your data is, that you remain accountable, and that nothing obstructs their inspection.
The gaps to settle on the order form
No quantified incident-notification deadline, no advance notice of a change of sub-processor, and a right of audit drafted for you alone.
A fourth that is not negotiable
Automatic deletions can destroy a piece you must keep for seven years, with no certificate of destruction. Export before the deadline.

Other sectors

Back to the security pageRead the Law 25 guide