Immigration consultants hold an unusually concentrated set of sensitive personal information: passport numbers, UCIs, biometric appointment details, medical information, financial records, family relationships, and sometimes an account of persecution. It is difficult to think of a private-sector practice that routinely holds a more complete picture of a person's life.
PIPEDA — the Personal Information Protection and Electronic Documents Act — governs how you handle it. And the most common misconception about PIPEDA is worth clearing up first.
PIPEDA does not require Canadian hosting
There is no provision requiring personal information to be stored in Canada. Transferring data to a service provider in another country is permitted. What PIPEDA does require is accountability: when you transfer personal information to a third party for processing, it remains your responsibility, you must use contractual or other means to provide a comparable level of protection, and you must be transparent with individuals about the fact that their information may be processed outside Canada and may therefore be accessible to foreign courts and authorities.
In other words, the obligation is not location — it is knowing, controlling, and disclosing. Which is precisely why so many practices fail it accidentally: you cannot disclose what you do not know, and a surprising number of consultants cannot say which country their case data sits in.
So why does location still matter?
- It collapses the analysis. If data never leaves Canada, the foreign-access disclosure, the comparable-protection assessment, and the awkward client conversation all become straightforward.
- Foreign legal process is a real exposure. Data held in another jurisdiction can be subject to that jurisdiction's legal orders. For a client fleeing persecution, that is not an abstract risk.
- Your clients ask. People applying to immigrate to Canada are attentive to where their information goes. “Stored in Canada” is an answer that ends the conversation well.
- CICC expects you to know. The 2026 framework's attention to technology means being able to explain your data handling is part of a defensible practice.
The vendor questions that actually work
Vague marketing language — “enterprise-grade security,” “bank-level encryption” — tells you nothing. These questions do:
| Question | Why it matters |
|---|---|
| Which country and region hosts the database? | A vendor who hesitates has not thought about it |
| Where are uploaded documents stored? | Often a different service from the database |
| Where are backups stored? | The most common way data leaves the country unnoticed |
| Which sub-processors touch client data? | Email, analytics, and AI services all count |
| Is any data sent to AI providers, and where? | A newer path out of the country, often undisclosed |
| Can staff access client data, and is that logged? | Vendor-side access is part of your risk picture |
| Is there a Data Processing Agreement? | This is the “contractual means” PIPEDA expects |
| How do you support export and erasure requests? | Client access and deletion rights are yours to satisfy |
What you owe your clients regardless
- Tell them. Your retainer or privacy notice should say what you collect, why, who processes it, and whether it may be processed outside Canada.
- Collect only what you need. The instinct to gather everything up front creates risk you then have to manage for six years.
- Be able to produce it. A client can ask for access to their personal information. Meeting that request should take minutes.
- Be able to delete it. Once your retention obligation has run, erasure should be an operation you can actually perform — including in backups and audit logs, where identifying details should be scrubbed.
How Immicase answers those questions
Client data and uploaded documents are hosted in Canadian regions. Sensitive identifiers — passport numbers, UCIs, national IDs — are encrypted in the browser with AES-256-GCM before they reach our servers, so they never arrive in plaintext. Access is role-based and every action is written to an immutable audit trail. PIPEDA data rights are built in: export a client's complete record as portable JSON, or perform a permanent erasure that also scrubs identifying details from the audit log. Our Data Processing Agreement is public.
Know where your client data lives
Canadian hosting, client-side encryption of sensitive identifiers, an immutable audit trail, and built-in PIPEDA export and erasure.