Skip to content
Small team, full backlog, zero orders dropped. Support replies are slower than we’d like. Read our status update → Zero orders dropped. Status → 📬 Check your spam folder — most of our replies land there. We do answer. Status update → 📬 Check your spam folder. Status →

CLOUD Act Business Checklist: Is Your Canadian Business Exposed? (Free Self-Assessment)

Under 18 U.S.C. §2713 (the US CLOUD Act, 2018), any cloud, SaaS, or AI provider subject to US jurisdiction can be compelled to hand over your data — regardless of whether it sits on a server in Montreal, Toronto, or Vancouver. This three-zone self-assessment maps your exposure in under five minutes: which of your vendors are US-controlled, what data categories flow through them, and where your Quebec Law 25 posture has gaps.

Orientation only — not legal advice

This tool is designed to surface questions for discussion with qualified counsel, not to constitute legal, regulatory, tax, or compliance advice. Every organization’s situation is different; factual claims on this page are attributed to primary sources (Borden Ladner Gervais LLP; Commission d’accès à l’information du Québec (CAI); 18 U.S.C. §2713; the published text of Quebec Law 25). Consult a licensed Canadian lawyer familiar with privacy and data-protection law before making procurement, architecture, or compliance decisions. Last reviewed: June 2026.

The checklist covers three dimensions of CLOUD Act exposure that Canadian businesses commonly underestimate. Each zone produces a risk indicator; combined, they produce a prioritized remediation path. Your answers are saved locally in your browser — no account, no email required.


0 / 20 answered

Zone 1

Vendor Inventory — US-Controlled Services

Answer Yes for each service category your organization currently uses, where the provider is incorporated in the United States or has a US corporate parent with access to your data.

Q1. Cloud infrastructure for hosting, compute, or storage (e.g., AWS, Microsoft Azure, Google Cloud Platform)


Q2. Email or productivity suite (e.g., Microsoft 365, Google Workspace)


Q3. CRM, sales, or marketing automation platform (e.g., Salesforce, HubSpot, Marketo, Zendesk)


Q4. Internal communications or collaboration tools (e.g., Slack, Zoom, Microsoft Teams, Webex)


Q5. AI APIs or cloud AI platforms (e.g., OpenAI API, Anthropic API, Google AI Studio, AWS Bedrock, Azure OpenAI, Cohere)


Q6. Payment processing or financial-data services subject to US regulation (e.g., Stripe, PayPal, Braintree, Adyen US entity)


Q7. Any other SaaS or cloud tools with a US-incorporated parent company that stores or processes your business data (e.g., Workday, ServiceNow, Snowflake, Databricks, GitHub, Jira)


Zone 2

Data Flow Assessment — What Categories Flow Through US-Controlled Systems?

Check every data category that your organization processes and that could pass through any US-controlled service identified in Zone 1. The weighting reflects regulatory sensitivity under Quebec Law 25 and the impact of a CLOUD Act disclosure.

Zone 3

Quebec Law 25 Posture — Compliance Readiness

Applies if your organization collects, uses, or discloses personal information of Quebec residents, or has operations in Quebec. Law 25 (Act respecting the protection of personal information in the private sector, in force September 2023) requires organizations to implement specific safeguards before sending personal information outside Quebec — including to US-controlled cloud providers subject to CLOUD Act reach. (Source: Commission d’accès à l’information du Québec, CAI.)

Answer Yes if your organization has implemented the measure; No if not yet done or uncertain. Each “No” is a compliance gap.

Q1. Have you appointed a Privacy Officer (personne responsable de la protection des renseignements personnels) as required by Law 25 section 3.1?


Q2. Does your website publish a privacy policy that meets Law 25’s requirements (data categories collected, purposes, retention, rights of data subjects, contact for the Privacy Officer)?


Q3. Have you conducted Privacy Impact Assessments (PIAs / évaluations des facteurs relatifs à la vie privée, EFVPs) for personal information sent or accessible outside Quebec, as required by Law 25 section 63.3?


Q4. Do you have written data processing agreements with all third-party service providers that receive or handle personal information on your behalf, covering their data security obligations under Law 25?


Q5. Have you established a privacy breach incident response plan and a breach register (registre des incidents) as required by Law 25 sections 3.5–3.7?


Q6. For every cross-border data transfer (including to US cloud providers), have you assessed whether the receiving jurisdiction’s legal framework — including the CLOUD Act — meets the Law 25 section 17 adequacy standard, and implemented required safeguards?




Answers are saved in your browser (localStorage). No data is transmitted to D-Central or any third party.

How the three zones interact

CLOUD Act exposure is multiplicative, not additive. A business with minimal US vendor usage but very high data sensitivity faces concentrated risk on the data that does flow through US-controlled systems. A business with heavy vendor exposure but only low-sensitivity data has a different — arguably more manageable — risk profile. The most dangerous combination is high vendor exposure, high data sensitivity, and weak Law 25 posture: a CLOUD Act disclosure in that scenario could compromise regulated data while simultaneously exposing the organization to CAI enforcement action.

The practical mitigation hierarchy, attributed to analysis by Borden Ladner Gervais LLP (BLG) on cross-border data-access risk for Canadian organizations, runs as follows:

  1. Architectural elimination — remove the US-provider jurisdiction hook entirely through self-hosted or Canadian-controlled infrastructure. No provider = no CLOUD Act compellable party. See replacing cloud AI with local LLM for implementation paths.
  2. Provider substitution — replace US-controlled services with providers that have no US corporate parent, no US employees with data access, and no US-held encryption keys. Legal review of specific provider structures is required before relying on this characterization.
  3. Technical mitigation — client-side encryption with Canadian key custody limits what a CLOUD Act disclosure yields (encrypted ciphertext only), but is not a complete legal solution if your organization is itself the subject of a US demand.
  4. Documented Law 25 compliance posture — if residual US-provider exposure remains, your Law 25 section 17 Transfer Impact Assessments must candidly document the CLOUD Act risk and the safeguards implemented. Boilerplate “data residency” clauses from US hyperscalers do not constitute adequate safeguards under Law 25.

For the full legal and technical background, see CLOUD Act and Canadian AI data: what organizations need to know.

What this checklist does not cover

This tool focuses on CLOUD Act and Quebec Law 25 exposure. It does not assess:

  • Federal PIPEDA / Bill C-27: Canada’s federal private-sector privacy law (PIPEDA) applies nationally; Bill C-27 (Consumer Privacy Protection Act / AIDA) was introduced as a comprehensive federal AI and privacy reform package but died when Parliament was prorogued in January 2025. It would need to be reintroduced in a new Parliament to proceed. As of June 2026, PIPEDA remains the applicable federal framework. Verify current legislative status before making compliance plans contingent on Bill C-27.
  • Sector-specific regulations: FINTRAC (financial transactions reporting), OSFI B-10 (financial institution outsourcing), PHIPA/HIPA (provincial health privacy), federal security clearance obligations, and ITAR/EAR export-control rules each add compliance layers beyond what this checklist covers.
  • Other foreign surveillance laws: The UK Investigatory Powers Act, China’s Data Security Law, and other national surveillance frameworks may reach your data via providers in those jurisdictions.
  • Contract-law obligations: Your agreements with clients, partners, or government counterparties may impose data-protection requirements beyond what privacy statutes require.

A comprehensive data-protection assessment requires qualified legal counsel with expertise in Canadian privacy law, applicable sectoral regulations, and cross-border data-access frameworks. This checklist is an orientation starting point, not a substitute for that assessment.


Frequently asked questions

Does the CLOUD Act apply to my Canadian business directly, or only to my cloud provider?

The CLOUD Act (18 U.S.C. §2713) compels the provider — not you as the customer — to disclose data. A valid CLOUD Act order is served on the US-jurisdiction cloud or SaaS provider that holds your data. You typically receive no advance notice of the demand (the statute permits gag orders in many circumstances). The practical impact on your business is that data you store in a US-controlled cloud environment can be disclosed to US law enforcement without your knowledge or a Canadian court order authorizing the disclosure. Your exposure as a Canadian customer is indirect but real: it is the data about your business, your employees, and your clients that gets disclosed.

Does storing data in a Canadian data centre eliminate CLOUD Act exposure?

No. As Borden Ladner Gervais LLP (BLG) has noted in their analysis of cross-border data-access risk, storing data in Canada does not prevent access under foreign laws when a US-incorporated entity controls that data. A US cloud provider operating a Canadian data centre (such as AWS ca-central-1, Azure Canada Central, or GCP northamerica-northeast1) remains subject to US jurisdiction because the provider — not the data centre’s physical location — determines CLOUD Act reach. The statute is explicit: obligations apply “regardless of whether such communication, record, or other information is located within or outside the United States” (18 U.S.C. §2713). Physical geography is irrelevant; corporate control is what matters. See the full CLOUD Act explainer for detail.

Is Quebec Law 25 enough to block a CLOUD Act disclosure?

No. Quebec Law 25 (the Act respecting the protection of personal information in the private sector) governs how organizations collect, use, and disclose personal information. It creates obligations on your organization and on your vendors — but it does not create a legal blocking mechanism against a US court order served on a US provider. The tension is that Law 25 section 17 requires you to assess whether the legal framework applicable to cross-border data transfers provides “adequate protection” — and a candid CLOUD Act analysis would typically conclude that US law does not provide equivalent protection to Quebec law for data held by US providers. This creates an obligation to implement safeguards, and where adequate safeguards cannot be implemented, to reconsider whether the transfer should occur at all. Consult the Commission d’accès à l’information du Québec (CAI) guidance on section 17 assessments, and seek legal advice. See also Quebec Law 25 and AI: on-premise LLM options.

What is the status of Canada’s federal AI law (Bill C-27 / AIDA)?

Bill C-27 — which included the Consumer Privacy Protection Act and the Artificial Intelligence and Data Act (AIDA) — was introduced in 2022 but died when Parliament was prorogued in January 2025 following the Prime Minister’s resignation announcement. It is defunct and would need to be reintroduced as new legislation in a new Parliament to have any legal effect. As of June 2026, Canada does not have a federal AI-specific statute in force. The applicable federal privacy law is PIPEDA (Personal Information Protection and Electronic Documents Act). Monitor Innovation, Science and Economic Development Canada (ISED) and Parliament for any new legislative initiatives. Do not build compliance plans around AIDA as if it were imminent.

What does a sovereign alternative actually look like for a Canadian SMB?

Sovereign infrastructure for a Canadian SMB typically means: (1) Email and productivity migrated to a Canadian-controlled provider or self-hosted open-source stack (Nextcloud, Proton for Business, or similar); (2) AI moved from US API calls to open-weight models (Llama, Mistral, Gemma) running on on-premise hardware or a Canadian-controlled server — see local AI vs cloud AI and local AI hardware guide; (3) Communications shifted to end-to-end encrypted tools with Canadian or European providers; (4) Business data stored in Canadian-controlled cloud infrastructure or on-premise. The total cost of ownership for sovereign infrastructure is often competitive with US cloud services at SMB scale once data-breach liability risk is factored in — see cloud vs local AI TCO comparison. D-Central can help scope this for your organization through our AI sovereignty consulting service.

Does Bitcoin or cryptocurrency data create additional CLOUD Act exposure?

Potentially yes. Transaction records, wallet addresses, exchange account data, and KYC/AML records held by US-incorporated exchanges or custody providers are stored communications or account records within the scope of the Stored Communications Act framework incorporated by CLOUD Act. US law enforcement has used SCA/CLOUD Act process extensively to obtain cryptocurrency exchange records. If your business processes or holds cryptocurrency-related data through US-incorporated platforms — including US-incorporated Canadian exchanges — those records may be within CLOUD Act reach. FINTRAC (Canada’s financial intelligence agency) has its own independent reporting obligations for virtual currency businesses; this is a separate (and parallel) compliance dimension. Consult legal counsel if your business involves cryptocurrency transactions. This area of law is evolving rapidly.


Related resources on D-Central

Legal and regulatory orientation only. This content is not legal, compliance, or tax advice. Attribution: 18 U.S.C. §2713 (CLOUD Act); Borden Ladner Gervais LLP (BLG) cross-border data-access analysis; Commission d’accès à l’information du Québec (CAI) Law 25 guidance; text of Quebec’s Act respecting the protection of personal information in the private sector. Verify all cited provisions and guidance at source before relying on them. D-Central Technologies is not a law firm and does not provide legal advice. Consult a qualified Canadian lawyer for guidance specific to your organization.