After-hours coverage active Central Time (204) 312-8405

Canadian compliance · Contact Centre · 6 min read

Does your call centre have to be in Canada? A straight answer

Canadian privacy law rarely forbids sending customer data offshore. Procurement contracts and your own clients often do. Here is where the line falls.

There’s a persistent belief among Canadian businesses that PIPEDA prohibits sending customer information outside the country. Vendors selling onshore services rarely correct it, because the misunderstanding is good for business.

We’d rather be accurate. The belief is wrong — and the real picture is more interesting, because it turns out there are several situations where onshore genuinely is required, and they’re not the ones most people expect.

This is general information, not legal advice. Privacy law changes, and the specifics of your situation matter. Confirm anything material with counsel before you sign a contract.

What PIPEDA actually says

The federal Personal Information Protection and Electronic Documents Act does not contain a data residency requirement. There is no clause saying personal information must stay in Canada.

What it does say is that an organisation remains accountable for personal information it transfers to a third party for processing. If you hand customer data to a service provider — anywhere in the world — you’re still responsible for it. You’re expected to use contractual or other means to ensure a comparable level of protection while it’s in their hands.

The Office of the Privacy Commissioner has treated a transfer for processing as a use of information rather than a disclosure, which means you generally don’t need fresh consent to send data to a processor, provided it’s being used for the purpose it was originally collected for. What you do need is transparency: your privacy policy should make clear that information may be processed outside Canada and may therefore be accessible to foreign courts and law enforcement.

So the honest summary of federal law: offshore is permitted, but you own the consequences and you have to be upfront about it.

Where it gets stricter

Federal law is the floor, not the ceiling. Several things sit on top of it.

Quebec. Law 25 is the significant one. Before communicating personal information outside Quebec, an organisation must conduct a privacy impact assessment considering the sensitivity of the information, the purpose, the protections in place, and the legal framework of the destination jurisdiction. The transfer can only proceed if the assessment shows the information will receive adequate protection. This is a real procedural obligation, not a formality, and it applies to a transfer to Manila as readily as to Toronto.

Alberta. PIPA requires organisations to notify individuals when a service provider outside Canada will be handling their personal information, and to disclose the purposes and how to get more information. Again — not a prohibition, but a disclosure duty that many organisations discover after the fact.

Public sector. Several provinces have had residency or notification rules for public bodies and their contractors. British Columbia’s FOIPPA historically contained a strict in-Canada storage requirement; it was amended in 2021 to a more flexible standard, but public-sector procurement in multiple provinces still routinely specifies Canadian storage as a contract term regardless of what the statute strictly demands.

Health information. Provincial health privacy statutes — PHIPA in Ontario, PHIA in Manitoba, and their equivalents elsewhere — impose their own custodian obligations that are generally more demanding than PIPEDA. Anyone handling patient information on behalf of a custodian is operating in a different regime.

The thing that actually decides it: your customers’ contracts

Here’s what we see far more often than statutory prohibition.

A business goes to outsource its support line. The law permits offshore. The pricing favours offshore. And then someone reads the master services agreement with their own largest client, and finds a clause requiring that client data be stored and processed within Canada.

That clause is everywhere. It appears in:

  • Financial services vendor agreements, where the institution’s regulator expects control over third-party arrangements
  • Healthcare contracts, flowing down custodian obligations
  • Legal sector engagements, where privilege and confidentiality make the analysis fraught
  • Government procurement at federal, provincial, and municipal levels
  • Enterprise MSAs generally, often inserted by a procurement team applying a standard template

None of these are laws. All of them are binding on you. And breaching one doesn’t get you a regulator’s letter — it gets you a terminated contract with your biggest customer.

If you’re evaluating outsourcing, the practical order of operations is: read your own client contracts before you read the privacy statutes. That’s where the constraint usually lives.

The other consideration: foreign lawful access

The reason data residency clauses proliferated in the first place is that data stored in another country is subject to that country’s legal process.

Information held by a provider in the United States can be reachable by US legal instruments. The CLOUD Act extends this to data held by US-headquartered providers even when it’s physically stored elsewhere, which surprises a lot of people who assumed a Canadian data centre solved the problem. It doesn’t, if the operating company is American.

For most businesses this is a theoretical risk. For a law firm holding privileged communications, a clinic holding mental health records, or a company in litigation with a US counterparty, it isn’t theoretical at all.

What this means practically

Roughly, the tiers look like this:

Offshore is fine. General retail and e-commerce support, restaurant order taking, appointment scheduling, most B2C service where the information involved is a name, a phone number, and an order. If your privacy policy is transparent and your contracts don’t say otherwise, the legal analysis is straightforward.

Onshore is strongly indicated. Anything involving health information, financial account details, legal matters, or where you hold contracts with residency clauses. Also anywhere you’d be embarrassed to explain the arrangement to the customer whose data it is.

Onshore is effectively mandatory. Government contracts specifying it. Regulated financial services with explicit third-party requirements. Health custodians and their agents. Quebec transfers where your assessment can’t establish adequate protection.

Questions to ask any provider

Whoever you’re evaluating, onshore or off, these are the ones that surface real answers:

  1. Where is the data physically stored, and who owns the operating entity? A Canadian data centre run by a US company is a different legal position than a Canadian company. Ask both parts.
  2. Where are the agents located? Storage and access are separate questions. Data resident in Toronto that an agent in another country can view has left the country in every way that matters.
  3. Are calls recorded, where do recordings live, and for how long? Recordings are frequently the most sensitive artefact in the whole arrangement and the one nobody asks about.
  4. What’s in the subprocessor list? Your provider’s vendors are your vendors. Ask for the list and ask how you’re notified when it changes.
  5. What happens at termination? Return and deletion timelines, in writing.
  6. Can you produce evidence for an audit? If your client asks you to demonstrate compliance, can your provider give you something better than a verbal assurance?

Any provider who can’t answer these quickly and specifically is telling you something.

Where we sit

We deliver both, and we’ll tell you which one your situation calls for.

DNOTCH is a Canadian company. Your contract is Canadian, your account lead is in Manitoba, and your contract is with a Canadian company either way. What changes is where the agents are.

Our Canada tier staffs agents in Manitoba with data resident in Canada. It costs more, and it’s the right answer when you’re contractually bound, in a regulated sector, or handling information your customers would care about.

Our Global tier staffs agents across Asia-Pacific. It costs roughly half. For high-volume order taking, appointment booking, and general retail support, it’s frequently the correct choice, and we’d rather say so than sell you protection you don’t need.

The question that decides it is usually not in the privacy statutes. It’s in your own client contracts. Check those first — the answer is probably already written down.


DNOTCH provides inbound contact centre services on a Canadian contract, with a choice of Canadian or Asia-Pacific delivery. If you’re working through a vendor review or a residency clause, book a call — we’ll tell you honestly which tier you need.

Next step

Find out what this would look like for you

A 20-minute call. We ask what breaks, what it costs you, and who handles it now. If we are not the right fit we will say so.