M ManySignal

Canada

Canadian data residency with PIPEDA, OSFI B-13, and Protected B support

Canadian financial institutions face OSFI B-13, Quebec Law 25 adds 72-hour breach notification obligations, and federal departments require Protected B cloud controls. ManySignal stores all Canada data in AWS Montreal or Calgary, with CCCS-aligned controls and PIPEDA breach tracking built in.

Canada data residency guarantees

Storage region

AWS CA-CENTRAL-1 (Montreal) or AWS CA-WEST-1 (Calgary). All customer data stored within Canada. No transfer to US or other regions under default deployment.

Public sector alignment

Government of Canada Protected B alignment under ITSG-33 and CCCS Cloud Security Control Profile. Assessment documentation available for GC departments.

Quebec Law 25 compliance

Deployment configuration supports Quebec's personal information protection requirements — 72-hour notification to CAI, privacy incident register, and privacy impact assessment support.

Canadian regulatory frameworks supported

PIPEDA / Bill C-27 (CPPA)

Federal privacy law — breach notification to OPC and affected individuals, service provider obligations

Quebec Law 25

72-hour notification to CAI for breaches creating risk of serious injury, privacy incident register

OSFI Guideline B-13

Technology and cyber risk management for federally regulated financial institutions

ITSG-33 / CCCS CSCF

Government of Canada information security — Protected B workload controls

OSFI Guideline E-21

Operational risk and resilience for OSFI-regulated institutions

PHIPA / Provincial Health Acts

Provincial health information protection — breach reporting to Information and Privacy Commissioner

Breach notification timelines — Canada

As soon as feasible

PIPEDA — Personal data breach notification to OPC and affected individuals for real risk of significant harm

72 hours

Quebec Law 25 — Confidentiality incident with risk of serious injury notification to CAI

Promptly

OSFI B-13 — Technology or cyber incidents notification to OSFI

Canada sales and support

Canada sales: [email protected]

Bilingual support available (English / French)

Canada deployment — common questions

Where is Canada customer data stored?

Canada customer data is stored and processed in AWS CA-CENTRAL-1 (Montreal). For customers in Western Canada, AWS CA-WEST-1 (Calgary) is also available. No Canada customer data is transferred outside Canada under default deployment, in compliance with the public sector requirements of provincial and federal privacy laws.

How does ManySignal support PIPEDA and the upcoming Bill C-27 (CPPA)?

Under PIPEDA (and the anticipated Consumer Privacy Protection Act under Bill C-27), ManySignal acts as a service provider processing personal information on documented instructions from the customer. Breach notification under PIPEDA requires notification to the Privacy Commissioner of Canada and affected individuals when a breach creates a real risk of significant harm. ManySignal's case management tracks PIPEDA breach reporting obligations and pre-populates the OPC notification form.

Does ManySignal support Government of Canada Protected B workloads?

ManySignal's Canada deployment in AWS CA-CENTRAL-1 (Montreal) is designed to meet the Government of Canada Cloud Security requirements for Protected B workloads under ITSG-33 and the CCCS Cloud Security Control Profil (CSCF). Our CCCS assessment documentation is available on request for GoC departments conducting security assessment and authorisation.

How does ManySignal address OSFI Guideline B-13 for federally regulated financial institutions?

OSFI Guideline B-13 (Technology and Cyber Risk Management, 2023) requires federally regulated financial institutions to maintain technology and cyber resilience. ManySignal addresses B-13's Outcome 4 (Cyber Security) — threat and vulnerability management, security event detection and response — and provides continuous monitoring evidence for OSFI examination purposes.

What Canadian privacy legislation does ManySignal monitor for, beyond PIPEDA?

ManySignal supports monitoring relevant to provincial privacy laws — Quebec Law 25 (Act to Modernize Legislative Provisions Respecting the Protection of Personal Information), which includes a 72-hour breach notification to the Commission d'accès à l'information (CAI) for incidents with risk of serious injury. For healthcare, ManySignal addresses provincial health information protection acts (PHIPA in Ontario, HIA in Alberta, PHIA in Manitoba).

Deploy ManySignal in Canada

Speak with our Canada team about PIPEDA, OSFI B-13, and Protected B cloud deployment — in English or French.