Canadian data residency for dental practices, explained
Data residency means the country where patient information is stored. Here is what Canadian privacy law says about it, and what to ask a software vendor.
By the Tusko team
Published
On this page
Data residency is the country where information is stored. For a dental practice or lab, it means where patient names, prescriptions and scans sit once they are in software.
The term comes up whenever a practice or a lab picks a new system. The law on it is less strict than many people expect, and more demanding in other ways.
This guide explains what the rules say, and what “stored in Canada” should mean when a vendor says it. It is general information, and no substitute for legal advice.
Three terms that get mixed up
Residency, sovereignty and localization
Three terms side by side. Data residency is the country where the data is stored. Data sovereignty is whose laws and courts can reach the data. Data localization is a legal rule that data must stay in a country.
Data residency
A fact about servers
- The country where the data is stored
Data sovereignty
A consequence of residency
- Whose laws and courts can reach the data
Data localization
A legal rule, where one exists
- A rule that data must stay in a country
Residency is a fact about servers. Sovereignty is a consequence of it.
Data stored in another country can be reached by that country’s courts and authorities, under that country’s rules.
Localization is the rule some people assume exists for all Canadian health information. For private practices under the federal law, it does not.
What the federal law says
The Office of the Privacy Commissioner published guidelines on this question. They are direct.
“PIPEDA does not prohibit organizations in Canada from transferring personal information to an organization in another jurisdiction for processing.”
Office of the Privacy Commissioner of Canada
The guidelines treat sending information to a processor as a use, and not as a disclosure. They say additional consent for the transfer is not required.
Two duties come with that freedom.
Comparable protection. The organization has to use “contractual or other means” to keep the information as well protected as it would be at home.
Openness. People should be told that their information may be sent to another jurisdiction, and that authorities there may be able to access it.
The practice or lab stays accountable throughout. Moving the data does not move the responsibility.
What the provinces add
The federal commissioner’s summary of PIPEDA notes that some provinces have their own laws in its place.
Alberta, British Columbia and Quebec have private-sector laws deemed substantially similar. Four other provinces have similar laws for health information.
So the rule that binds you depends on your province. Each law handles transfers in its own way, and some ask for more than the federal one.
British Columbia
A private practice or lab in BC falls under the province’s Personal Information Protection Act, known as PIPA.
BC’s privacy commissioner has written about storage outside Canada, comparing PIPA with the law for public bodies, FIPPA.
“Unlike FIPPA, PIPA does not restrict storage and access to personal information outside of Canada.”
Office of the Information and Privacy Commissioner for British Columbia
The same article reminds organizations that they must still protect the information with reasonable security.
It also recommends telling people if their information will be transferred out of Canada.
Where a stricter rule applied
For years, BC’s public bodies did work under a residency rule.
The province’s guidance on disclosures outside Canada explains the history.
Before amendments enacted on 25 November 2021, public bodies had to store and access personal information in Canada, with limited exceptions.
Since then, a public body must instead complete an added assessment when sensitive personal information is to be stored outside Canada.
Those rules were for public bodies such as health authorities and ministries. Private dental practices were never under them.
Why Canadian storage is still worth asking for
The law allows storage abroad. Many practices and labs still prefer to keep patient information in Canada, for four practical reasons.
- One set of laws. Data kept in Canada by a Canadian company sits under Canadian law.
- A simpler promise. “Your records are stored in Canada” is easier to say to a patient than a paragraph about foreign access.
- Fewer questions later. A buyer, an insurer or a regulator may ask where records are kept.
- Partners may require it. A practice can make Canadian storage a condition for its labs and vendors.
None of these is a legal duty under PIPEDA. They are reasons a careful owner might choose it anyway.
What “stored in Canada” should mean
The phrase can cover a lot or a little. Ask a vendor to confirm each of these in writing.
- The main database is in a Canadian data centre, and which one
- Backups are in Canada too
- Files such as scans and photos are stored in Canada, and not only the text
- Which other services handle the data: email, text messages, analytics, support tools
- Whether the vendor’s staff or contractors can open records from outside Canada
- Whether the company, or its host, is owned abroad
- That you will be told before any of this changes
Look closely at the fourth line. A product can keep its database in Canada and still send every notification through a service elsewhere.
The sixth is about sovereignty. A foreign-owned host with a Canadian data centre may still answer to courts in its home country.
No answer has to be perfect. It has to be known, written down, and reflected in what you tell patients.
What to tell patients
Openness is the duty that applies wherever the data sits.
Say in your privacy policy where patient information is stored, in plain words. Name the country.
If any of it is stored or handled outside Canada, say so. Add that authorities in that country may be able to access it.
Keep the wording current. A change of vendor can make last year’s policy wrong.
Tell the front desk what the policy says. Patients ask the person in front of them.
What this means for labs
A lab is in the chain. Every Rx carries a patient’s name and details of their treatment.
The practice that sent it remains accountable for that information. Some will ask the lab the same questions they ask their own vendors.
Have the answers ready for each system the lab uses.
- Lab management software
- A doctor portal, if you offer one
- The scanner makers’ cloud services that deliver files to you
- Email, where scans and prescriptions still arrive
- File transfer links
Do not leave email off the list. Messages and attachments sit wherever the mail provider keeps them.
Write the answers once and reuse them. The same page serves every practice that asks.
A lab that can answer in one page looks organized. How to choose a dental lab lists what else practices look for.
Keep a one-page record
For each system that holds patient information, write down five things.
| Record | Example of what to note |
|---|---|
| What it holds | Names, prescriptions, scans, photos |
| Where it is stored | Country and data centre, including backups |
| Who else handles it | Hosting, messaging and support providers |
| What the agreement says | Safeguards, breach notice, export and deletion |
| When you last checked | A date, and who checked |
Review it once a year, and whenever you add a system.
Keep the record with your privacy policy, so the two stay in step.
PIPEDA and dental software has the full list of questions to send a vendor, including breach notice and access.
Where Tusko stands
We make Tusko, and the same questions are fair to ask us. Our security page sets out how patient information on a case is handled.
See how a shared case works for labs and for practices.
Does Canadian law require dental patient data to stay in Canada?
The federal privacy commissioner’s guidance says PIPEDA does not prohibit transferring personal information to another jurisdiction for processing. Provincial laws and contracts can add their own conditions, so check the law that applies to your practice or lab.
What is the difference between data residency and data sovereignty?
Residency is where the data is stored. Sovereignty is whose laws can reach it. Data stored in another country can be subject to that country’s courts and authorities.
Do patients have to be told if their data is stored outside Canada?
The federal commissioner’s guidance expects organizations to be open about it, and to say that the information may be accessed by authorities in the other jurisdiction. A line in your privacy policy is the usual place.
Does a dental lab need to think about data residency?
Yes. An Rx carries a patient’s name and health details, so a lab holds patient information on behalf of its practices. Practices may ask a lab where its software stores it.
Sources
- Office of the Privacy Commissioner of Canada: Guidelines for processing personal data across borders
- Office of the Privacy Commissioner of Canada: PIPEDA requirements in brief
- Office of the Information and Privacy Commissioner for British Columbia: In the clouds and beyond, navigating access and storage outside of Canada
- Government of British Columbia: Guidance on disclosures outside of Canada
Related guides
Under the Canadian Dental Care Plan, lab fees are reimbursed when they are reasonable and customary. Here is what that means for practices and labs.
FDI notation names each tooth with two digits, the quadrant and the position. Here is how to read it, write it on a lab Rx and avoid mix-ups.
Choosing a dental lab in Metro Vancouver comes down to driver routes, licensing and how the lab communicates. Here is what to check before you send a case.