Pentest data residency in Canada
During a test, a stranger holds your credentials, screenshots of your data and a written map of your weaknesses. Where that material lives, and under whose law, is a question almost no Canadian buyer asks and several Canadian contracts answer for you.
Canadian federal private-sector privacy law does not require that your data stay in Canada. PIPEDA permits transfers to a third party for processing, including outside the country, provided you use contractual or other means to give the information a comparable level of protection and you remain accountable for it. The residency requirements that bind you come from three other places: British Columbia and Nova Scotia public-sector statutes, Quebec's Law 25 transfer assessment, and the contract your customer made you sign. Those are the ones to check before you shortlist a firm.
4 places Your data lives during a test
12 months Evidence retention to ask for, then deletion
Contract The most common real source of a residency rule
Where your data actually is during an engagement
| Location | What is there | The question to ask |
|---|---|---|
| The tester's workstation | Credentials, session tokens, captured requests and responses, screenshots | Where is the tester physically, and is the disk encrypted |
| The firm's testing infrastructure | Proxy logs, scan output, captured traffic, sometimes database extracts | Which country and which cloud region are those servers in |
| The reporting platform | Findings, evidence, the draft and final report | Is it self-hosted or a US SaaS product, and where does it store |
| The delivery channel | The finished report and the attestation letter | Encrypted portal or email, and how long the copy persists |
The reporting platform is the one buyers never think of and the one most likely to sit in the United States. A Canadian firm with Canadian testers and Canadian servers may still write your findings into a US-hosted collaboration tool, because that is what the industry uses. Ask about it by name. A firm that has thought about residency answers in one sentence.
What PIPEDA actually requires
PIPEDA treats a transfer for processing as a use, not a disclosure, so you do not need fresh consent to send personal information to a service provider, including one abroad. What you do need is to remain accountable: Principle 4.1.3 requires that you use contractual or other means to provide a comparable level of protection while the information is being processed by a third party. The Office of the Privacy Commissioner's long-standing guidance adds that individuals should be notified that their information may be processed in a foreign jurisdiction and may be accessible to that jurisdiction's courts and law enforcement.
For a penetration test: put the protections in the contract, know where the data is, and be able to answer the question if a customer asks. Breach reporting is separate: under PIPEDA a breach of security safeguards that creates a real risk of significant harm must be reported to the Privacy Commissioner and to affected individuals, and you must keep records of all breaches for 24 months. A penetration test is not a breach, but an incident during one involving real personal information can be.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
Quebec, and the assessment that is easy to miss
Quebec's Law 25 goes further than PIPEDA. Before communicating personal information outside Quebec, an organisation must conduct a privacy impact assessment considering the sensitivity of the information, the purpose, the protections in place and the legal framework of the receiving jurisdiction. If the assessment shows the information would not receive adequate protection, the communication must not happen. The transfer must also be the subject of a written agreement.
That is a document you produce, not one the testing firm produces for you. If you are a Quebec organisation testing a system holding personal information and the firm's evidence storage is outside Quebec, the assessment applies. The cheapest way out is not to do the assessment faster. It is to test against non-production data so that no personal information leaves in the first place, or to select a firm that keeps everything in province. Law 25 also carries its own confidentiality incident obligations, which run in parallel with PIPEDA rather than replacing them.
Ontario, and what PHIPA does here
Ontario has no general private-sector residency rule. PHIPA, which governs personal health information, does not prohibit storage outside Ontario either, but it makes a health information custodian responsible for the agent handling the information and requires a written agreement setting out the permitted use and the safeguards. If a test touches a system holding personal health information, the testing firm is acting as your agent and the agreement has to say so. The rest of what provincial health law changes about a test is on health tech penetration testing in Canada. Testing against de-identified or synthetic data is again the cheaper route.
Where residency is genuinely mandatory
| Where | The rule | Effect on a test |
|---|---|---|
| BC public bodies | FOIPPA once required storage and access in Canada. The 2021 amendments relaxed this, but public bodies must complete a privacy impact assessment and many contracts still impose the original requirement | Check the specific contract. Do not assume the old rule, and do not assume it is gone |
| Nova Scotia public bodies | The Personal Information International Disclosure Protection Act restricts storage and access outside Canada | Canadian testers and Canadian evidence storage, in practice |
| Quebec, any organisation | Law 25 assessment before personal information leaves the province, plus a written agreement | An assessment you must produce, or avoid the transfer entirely |
| Federal government suppliers | Contract-specific security requirements and personnel screening under the Contract Security Program | Cleared personnel, often Canadian-resident, named in the contract |
| Anyone with a customer contract that says so | Whatever the contract says | The most common source by a distance |
The provincial procurement detail is on public sector penetration testing in British Columbia, Quebec and Ontario. The last row of that table is the one that catches private companies: hospital agreements, bank supplier schedules and some enterprise master services agreements impose residency terms that flow through to your subcontractors, meaning your testing firm. Read your own customer contracts before you read anyone's privacy policy.
What to put in the contract
- Testing is performed by personnel located in Canada, or name the acceptable countries. Say whether this covers subcontractors, because otherwise it does not.
- All evidence, captured data and draft reporting are stored in Canada, naming the cloud region if the firm uses one.
- Personal information encountered during testing is not exported from the environment, is recorded only to the extent needed to demonstrate the finding, and is redacted in the report.
- Evidence is retained for a stated period, normally 12 months, and then destroyed, with written confirmation of destruction on request.
- Subcontracting requires prior written approval, and the same terms flow down.
- Notification if the firm receives a legal demand for your material, to the extent the firm is permitted to tell you.
All six belong in the rules of engagement or the statement of work, and all six are things to ask about on the call, per questions to ask a penetration testing vendor.
The counter-case: residency is often the wrong filter
Insisting on Canadian-only testers narrows a small market and can cost you the firm that is best at your surface. With no statutory requirement, no public-sector customer and no contract clause, the useful requirements are competence, evidence handling and a deletion commitment. A US-resident tester working against a Canadian-hosted staging environment seeded with synthetic data raises no residency question. There is no personal information to transfer. Solve it with data selection before you solve it with geography.
If you are Canadian and selling into the US or the EU
The question inverts. A US customer's security review rarely asks where your tester sat, and asks instead whether the test was independent, recent and scoped to the system they buy. A UK or EU customer may ask about CREST accreditation and, if personal data of EU residents is in scope, about how the testing firm is handled under your GDPR processor arrangements. In both cases the artifact they want is an attestation letter rather than the report, which is covered on report against attestation letter.
Tell us the residency constraint up front
If a contract or a statute requires Canadian testers or Canadian evidence storage, say so in the scope and we will only put it to firms that can meet it.
Get matchedCommon questions
Does Canadian law require a penetration test to be done in Canada?
No. PIPEDA permits transfers to service providers outside Canada as long as you use contractual means to give the information comparable protection and remain accountable for it. Mandatory residency comes from specific public-sector statutes, from Quebec's Law 25 transfer rules, from federal contract security requirements, and most often from a clause in your own customer's contract.
Where is our data stored during a penetration test?
In four places: the tester's workstation, the firm's testing infrastructure, the reporting platform, and wherever the finished report is delivered and kept. The reporting platform is the one most likely to be a US hosted product even at a Canadian firm, so ask about it by name rather than asking a general question about where the company is based.
Does Law 25 apply to hiring a penetration testing firm?
It applies if personal information will be communicated outside Quebec during the engagement. You must assess the transfer beforehand, considering sensitivity, purpose, protections and the receiving jurisdiction's legal framework, and the transfer must be covered by a written agreement. Testing against synthetic or de-identified data avoids the question rather than answering it, which is usually the cheaper path.
Should we require that testers be Canadian citizens?
Only where a contract or a security-clearance requirement says so. Citizenship and residency are different things, and most contractual clauses are about where the person and the data are located rather than nationality. Federal work under the Contract Security Program is the case where personnel screening genuinely applies, and it is spelled out in the contract.
How long should the testing firm keep our data?
Ask for a stated retention period with a deletion commitment, and 12 months is a reasonable ask. Firms keep evidence for a while so that a retest can reproduce the original finding, which is a real reason. Indefinite retention for unspecified quality purposes is not, and it means your credentials and screenshots of your data sit on their storage permanently.
Is a penetration test finding a reportable privacy breach?
Not by itself. A test conducted under a signed authorisation is authorised access, not a breach of security safeguards. It becomes reportable territory if real personal information is exfiltrated or exposed in a way that creates a real risk of significant harm, which is why the rules of engagement should limit what the tester copies out of the environment. Records of breaches must be kept for 24 months under PIPEDA regardless of whether they were reportable.