Skip to content
Tusko

Canadian data residency for dental practices, explained

Data residency means the country where patient information is stored. Here is what Canadian privacy law says about it, and what to ask a software vendor.

By the Tusko team

Published

On this page

Data residency is the country where information is stored. For a dental practice or lab, it means where patient names, prescriptions and scans sit once they are in software.

The term comes up whenever a practice or a lab picks a new system. The law on it is less strict than many people expect, and more demanding in other ways.

This guide explains what the rules say, and what “stored in Canada” should mean when a vendor says it. It is general information, and no substitute for legal advice.

Three terms that get mixed up

Residency, sovereignty and localization

Three terms side by side. Data residency is the country where the data is stored. Data sovereignty is whose laws and courts can reach the data. Data localization is a legal rule that data must stay in a country.

Data residency

A fact about servers

  • The country where the data is stored

Data sovereignty

A consequence of residency

  • Whose laws and courts can reach the data

Data localization

A legal rule, where one exists

  • A rule that data must stay in a country
Only localization is a legal rule, and the federal law sets none for private practices.

Residency is a fact about servers. Sovereignty is a consequence of it.

Data stored in another country can be reached by that country’s courts and authorities, under that country’s rules.

Localization is the rule some people assume exists for all Canadian health information. For private practices under the federal law, it does not.

What the federal law says

The Office of the Privacy Commissioner published guidelines on this question. They are direct.

“PIPEDA does not prohibit organizations in Canada from transferring personal information to an organization in another jurisdiction for processing.”

Office of the Privacy Commissioner of Canada

The guidelines treat sending information to a processor as a use, and not as a disclosure. They say additional consent for the transfer is not required.

Two duties come with that freedom.

Comparable protection. The organization has to use “contractual or other means” to keep the information as well protected as it would be at home.

Openness. People should be told that their information may be sent to another jurisdiction, and that authorities there may be able to access it.

The practice or lab stays accountable throughout. Moving the data does not move the responsibility.

What the provinces add

The federal commissioner’s summary of PIPEDA notes that some provinces have their own laws in its place.

Alberta, British Columbia and Quebec have private-sector laws deemed substantially similar. Four other provinces have similar laws for health information.

So the rule that binds you depends on your province. Each law handles transfers in its own way, and some ask for more than the federal one.

British Columbia

A private practice or lab in BC falls under the province’s Personal Information Protection Act, known as PIPA.

BC’s privacy commissioner has written about storage outside Canada, comparing PIPA with the law for public bodies, FIPPA.

“Unlike FIPPA, PIPA does not restrict storage and access to personal information outside of Canada.”

Office of the Information and Privacy Commissioner for British Columbia

The same article reminds organizations that they must still protect the information with reasonable security.

It also recommends telling people if their information will be transferred out of Canada.

Where a stricter rule applied

For years, BC’s public bodies did work under a residency rule.

The province’s guidance on disclosures outside Canada explains the history.

Before amendments enacted on 25 November 2021, public bodies had to store and access personal information in Canada, with limited exceptions.

Since then, a public body must instead complete an added assessment when sensitive personal information is to be stored outside Canada.

Those rules were for public bodies such as health authorities and ministries. Private dental practices were never under them.

Why Canadian storage is still worth asking for

The law allows storage abroad. Many practices and labs still prefer to keep patient information in Canada, for four practical reasons.

  • One set of laws. Data kept in Canada by a Canadian company sits under Canadian law.
  • A simpler promise. “Your records are stored in Canada” is easier to say to a patient than a paragraph about foreign access.
  • Fewer questions later. A buyer, an insurer or a regulator may ask where records are kept.
  • Partners may require it. A practice can make Canadian storage a condition for its labs and vendors.

None of these is a legal duty under PIPEDA. They are reasons a careful owner might choose it anyway.

What “stored in Canada” should mean

The phrase can cover a lot or a little. Ask a vendor to confirm each of these in writing.

  • The main database is in a Canadian data centre, and which one
  • Backups are in Canada too
  • Files such as scans and photos are stored in Canada, and not only the text
  • Which other services handle the data: email, text messages, analytics, support tools
  • Whether the vendor’s staff or contractors can open records from outside Canada
  • Whether the company, or its host, is owned abroad
  • That you will be told before any of this changes

Look closely at the fourth line. A product can keep its database in Canada and still send every notification through a service elsewhere.

The sixth is about sovereignty. A foreign-owned host with a Canadian data centre may still answer to courts in its home country.

No answer has to be perfect. It has to be known, written down, and reflected in what you tell patients.

What to tell patients

Openness is the duty that applies wherever the data sits.

Say in your privacy policy where patient information is stored, in plain words. Name the country.

If any of it is stored or handled outside Canada, say so. Add that authorities in that country may be able to access it.

Keep the wording current. A change of vendor can make last year’s policy wrong.

Tell the front desk what the policy says. Patients ask the person in front of them.

What this means for labs

A lab is in the chain. Every Rx carries a patient’s name and details of their treatment.

The practice that sent it remains accountable for that information. Some will ask the lab the same questions they ask their own vendors.

Have the answers ready for each system the lab uses.

  • Lab management software
  • A doctor portal, if you offer one
  • The scanner makers’ cloud services that deliver files to you
  • Email, where scans and prescriptions still arrive
  • File transfer links

Do not leave email off the list. Messages and attachments sit wherever the mail provider keeps them.

Write the answers once and reuse them. The same page serves every practice that asks.

A lab that can answer in one page looks organized. How to choose a dental lab lists what else practices look for.

Keep a one-page record

For each system that holds patient information, write down five things.

RecordExample of what to note
What it holdsNames, prescriptions, scans, photos
Where it is storedCountry and data centre, including backups
Who else handles itHosting, messaging and support providers
What the agreement saysSafeguards, breach notice, export and deletion
When you last checkedA date, and who checked

Review it once a year, and whenever you add a system.

Keep the record with your privacy policy, so the two stay in step.

PIPEDA and dental software has the full list of questions to send a vendor, including breach notice and access.

Where Tusko stands

We make Tusko, and the same questions are fair to ask us. Our security page sets out how patient information on a case is handled.

See how a shared case works for labs and for practices.

Does Canadian law require dental patient data to stay in Canada?

The federal privacy commissioner’s guidance says PIPEDA does not prohibit transferring personal information to another jurisdiction for processing. Provincial laws and contracts can add their own conditions, so check the law that applies to your practice or lab.

What is the difference between data residency and data sovereignty?

Residency is where the data is stored. Sovereignty is whose laws can reach it. Data stored in another country can be subject to that country’s courts and authorities.

Do patients have to be told if their data is stored outside Canada?

The federal commissioner’s guidance expects organizations to be open about it, and to say that the information may be accessed by authorities in the other jurisdiction. A line in your privacy policy is the usual place.

Does a dental lab need to think about data residency?

Yes. An Rx carries a patient’s name and health details, so a lab holds patient information on behalf of its practices. Practices may ask a lab where its software stores it.

Sources