VSaaS and Data Residency in Canada

Where cloud video data lives, what Canadian privacy law expects, and the questions to ask a VSaaS provider before you sign.

Cloud video (VSaaS) moves recorded footage, and often faces and licence plates, into a provider’s data centre. Video of identifiable people is personal information, so where that data lives and who can reach it becomes a privacy question, not just a technical one. For Canadian sites, a few rules and a short list of questions cover most of it.

What data residency means

Data residency is the physical location where data is stored and processed. A VSaaS provider may keep footage in Canada, in the United States, or spread across regions, and it may fail over between them. Residency matters because data stored in another country can be subject to that country’s laws, including lawful access by its authorities. Knowing the region is the first step in assessing risk.

What Canadian law expects

Federal private-sector privacy law, PIPEDA, does not ban storing personal information outside Canada, but it holds the organization accountable for protecting it wherever it goes and expects transparency about cross-border transfers. Quebec’s Law 25 sets stricter expectations, including an assessment before sending personal information outside the province. Public-sector rules in provinces such as British Columbia and Nova Scotia go further and can require that certain data stay in Canada. The right answer depends on who the client is and which province they operate in.

Questions to ask a provider

Ask where footage is stored and processed, and whether it ever leaves Canada, including for backups and failover. Ask who can access the data, including the provider’s staff and any sub-processors, and how access is logged. Ask how footage is encrypted in transit and at rest, and who holds the keys. Ask how long data is retained and how deletion is proven. And ask what happens to the footage if the contract ends.

Put it in the contract

Verbal assurances are not enough. The agreement should state the storage region, the sub-processors, the retention and deletion terms, and the breach-notification commitment. For public-sector and Quebec clients, confirm the provider can meet the residency and assessment requirements before selecting the platform. The Canadian Centre for Cyber Security’s cloud guidance is a useful checklist for the security side of that review. Sorting this out before signing is far easier than migrating footage after a privacy review flags it.

References

  1. The Personal Information Protection and Electronic Documents Act (PIPEDA)Office of the Privacy Commissioner of Canada · retrieved 2026-07-07
  2. Law 25, protection of personal informationCommission d'accès à l'information du Québec · retrieved 2026-07-07
  3. Guidance on cloud securityCanadian Centre for Cyber Security · retrieved 2026-07-07

Last updated 2026-07-07.