Storing Customer Data on Servers Outside Canada: Good or Bad Practice?

The issue: Can we send contact database files outside of Canada?
Pascale Guay
1 September 2013
Data Management
2 min 15
Conservation de données à l’extérieur du Canada : bonne ou mauvaise pratique ?

Over the past month, I’ve had to review several contractual clauses that organizations must follow under Canadian privacy laws. Research I conducted to verify if it was possible to use the services of third parties to process data. The issue: Can we send contact database files outside of Canada?

I will not give legal advice, but simply expose guideline rules that have helped us to determine if we could use the third party servers located outside of Canada. I invite you to consult your legal counsel for advice that applies to your organization and its territory. And, in the meantime, be immediately reassured, we keep our customers’ data in Canada.

To answer the question, I did some research on this subject.

The general conclusions that I take from my research are found on the website for the Office of the Privacy Commissioner of Canada. They give key recommendations that apply to all organizations in Canada:

The transferring organization is accountable for the information in the hands of the organization to which it has been transferred.

Organizations must protect the personal information in the hands of processors. The primary means by which this is accomplished is through contract.

No contract can override the criminal, national security or any other laws of the country to which the information has been transferred.

It is important for organizations to assess the risks that could jeopardize the integrity, security and confidentiality of customer personal information when it is transferred to third-party service providers operating outside of Canada.

Organizations must be transparent about their personal information handling practices. This includes advising customers that their personal information may be sent to another jurisdiction for processing and that while the information is in another jurisdiction it may be accessed by the courts, law enforcement and national security authorities.”

Because we are not able to ensure security and data access procedures, nor to discuss the contract with U.S. suppliers, we rejected the American solutions of cloud computing to prefer the use of data in Canada. Furthermore, even if the law is not formal in this regard, we will not take unnecessary risk of exposing ourselves to other acceptable data use practices, which are not permitted here in Canada at all, such as sharing contact lists.

Finally, to avoid any difficulties and meet the highest standards of safety, we prefer not to send or share any customer data on servers outside Canada. With all the controversy of the use of U.S. data with the Snowden case, I think it is a wise decision. What do you think?

Find out how your company can benefit from Dialog Insight.

Read also

Blog

Tracking Pixels in Emails: An Ethical Solution Exists

The CNIL seeks to regulate the use of tracking pixels in emails. Between legal obligations, marketing lobbying, and technical solutions like Dialog Insight, find out how to reconcile compliance, performance, and privacy.

Blog

Explicit Data vs. Implicit Data in Digital Marketing: How to Use Both to Boost Customer Experience

Customer data falls into two main categories: explicit data, voluntarily provided by the user, and implicit data, inferred from their behaviors. Understanding their complementary roles and knowing how to leverage them together makes it possible to personalize the experience, optimize marketing campaigns, and strengthen customer loyalty.

Blog

Email Marketing vs. SMS Marketing: Which One to Choose?

Email marketing or SMS marketing: Which is more effective to reach your customers? Discover the advantages, limitations, and uses of each channel, along with best practices to combine them and maximize your conversions.

Omni-Channel Marketing Campaign

Everything you need to know to succeed in your first SMS campaign

The SMS opening rate is 98%; it's huge! It would be foolish to do without this way of reaching your users. So many opportunities to connect with the consumer right at the fingertips...literally.

Blog

Data Security: The Legal and Strategic Responsibilities of Businesses  

With the increasing electronic sharing of personal information across various digital platforms, cybersecurity threats are becoming more frequent and their consequences more severe. Privacy incidents are no longer isolated events. It is essential to be prepared to face them in order to minimize their risks and impact.

Blog

Customer Loyalty: Turn Buyers into Brand Ambassadors 

Customer loyalty is no longer just about a points program: it's about building a consistent and personalized relationship at every post-purchase stage. This article explores how each interaction can foster engagement and turn a one-time customer into a loyal brand ambassador.

New at Dialog Insight

Every message, on the right channel, at the right time — automatically.

What if your campaigns could find on their own the ideal channel and the perfect moment to generate more impact?With Smart Channel and Omnichannel STO, your campaigns become more engaging and more effective: