Canada
Canadian data residency with PIPEDA, OSFI B-13, and Protected B support
Canadian financial institutions face OSFI B-13, Quebec Law 25 adds 72-hour breach notification obligations, and federal departments require Protected B cloud controls. ManySignal stores all Canada data in AWS Montreal or Calgary, with CCCS-aligned controls and PIPEDA breach tracking built in.
Canada data residency guarantees
Storage region
AWS CA-CENTRAL-1 (Montreal) or AWS CA-WEST-1 (Calgary). All customer data stored within Canada. No transfer to US or other regions under default deployment.
Public sector alignment
Government of Canada Protected B alignment under ITSG-33 and CCCS Cloud Security Control Profile. Assessment documentation available for GC departments.
Quebec Law 25 compliance
Deployment configuration supports Quebec's personal information protection requirements — 72-hour notification to CAI, privacy incident register, and privacy impact assessment support.
Canadian regulatory frameworks supported
PIPEDA / Bill C-27 (CPPA)
Federal privacy law — breach notification to OPC and affected individuals, service provider obligations
Quebec Law 25
72-hour notification to CAI for breaches creating risk of serious injury, privacy incident register
OSFI Guideline B-13
Technology and cyber risk management for federally regulated financial institutions
ITSG-33 / CCCS CSCF
Government of Canada information security — Protected B workload controls
OSFI Guideline E-21
Operational risk and resilience for OSFI-regulated institutions
PHIPA / Provincial Health Acts
Provincial health information protection — breach reporting to Information and Privacy Commissioner
Breach notification timelines — Canada
As soon as feasible
PIPEDA — Personal data breach notification to OPC and affected individuals for real risk of significant harm
72 hours
Quebec Law 25 — Confidentiality incident with risk of serious injury notification to CAI
Promptly
OSFI B-13 — Technology or cyber incidents notification to OSFI
Canada sales and support
Canada sales: [email protected]
Bilingual support available (English / French)
Canada deployment — common questions
Where is Canada customer data stored?
Canada customer data is stored and processed in AWS CA-CENTRAL-1 (Montreal). For customers in Western Canada, AWS CA-WEST-1 (Calgary) is also available. No Canada customer data is transferred outside Canada under default deployment, in compliance with the public sector requirements of provincial and federal privacy laws.
How does ManySignal support PIPEDA and the upcoming Bill C-27 (CPPA)?
Under PIPEDA (and the anticipated Consumer Privacy Protection Act under Bill C-27), ManySignal acts as a service provider processing personal information on documented instructions from the customer. Breach notification under PIPEDA requires notification to the Privacy Commissioner of Canada and affected individuals when a breach creates a real risk of significant harm. ManySignal's case management tracks PIPEDA breach reporting obligations and pre-populates the OPC notification form.
Does ManySignal support Government of Canada Protected B workloads?
ManySignal's Canada deployment in AWS CA-CENTRAL-1 (Montreal) is designed to meet the Government of Canada Cloud Security requirements for Protected B workloads under ITSG-33 and the CCCS Cloud Security Control Profil (CSCF). Our CCCS assessment documentation is available on request for GoC departments conducting security assessment and authorisation.
How does ManySignal address OSFI Guideline B-13 for federally regulated financial institutions?
OSFI Guideline B-13 (Technology and Cyber Risk Management, 2023) requires federally regulated financial institutions to maintain technology and cyber resilience. ManySignal addresses B-13's Outcome 4 (Cyber Security) — threat and vulnerability management, security event detection and response — and provides continuous monitoring evidence for OSFI examination purposes.
What Canadian privacy legislation does ManySignal monitor for, beyond PIPEDA?
ManySignal supports monitoring relevant to provincial privacy laws — Quebec Law 25 (Act to Modernize Legislative Provisions Respecting the Protection of Personal Information), which includes a 72-hour breach notification to the Commission d'accès à l'information (CAI) for incidents with risk of serious injury. For healthcare, ManySignal addresses provincial health information protection acts (PHIPA in Ontario, HIA in Alberta, PHIA in Manitoba).
Deploy ManySignal in Canada
Speak with our Canada team about PIPEDA, OSFI B-13, and Protected B cloud deployment — in English or French.