Canadian data residency means that your client files are stored and processed on servers physically located in Canada, rather than in another country. It matters because once information sits in a foreign jurisdiction, it can become subject to that country's laws, including access by its courts and government, no matter how careful you were on your end.
I'm not a clinician, so I won't tell you how to run your practice. But data residency is one of those quiet technical details that clinicians keep asking me to explain in plain language, so here it is, with the sources that back it up.

A lock only protects what stays on your side of the border.
What does Canadian data residency actually mean?
Data residency is about where your data physically lives and gets processed, not just who owns the software. A vendor can be a Canadian company and still run its servers, backups, or AI processing in another country. Residency means the actual storage and processing happen inside Canada.
That distinction matters because the physical location of data determines which country's laws can reach it. A file stored in Canada is governed by Canadian law. The same file copied to a server abroad is exposed to the rules of wherever it landed.
Why do Canadian clinicians care where client files live?
Because client files are among the most sensitive records you hold, and the moment they cross a border, a different legal system can gain a claim on them. The Office of the Privacy Commissioner of Canada is explicit that organizations should be advising people "that while the information is in another jurisdiction it may be accessed by the courts, law enforcement and national security authorities" of that country.
The OPC also notes a hard limit that no vendor contract can paper over: "No contract can override the criminal, national security or any other laws of the country to which the information has been transferred." So even a well-drafted agreement can't fully insulate data that physically lives abroad. Keeping the data in Canada is the cleaner answer.
What does PIPEDA say about sending client data across the border?
PIPEDA doesn't forbid cross-border transfers, but it holds you accountable for them. The OPC's guidelines on processing personal data across borders state that "PIPEDA does not distinguish between domestic and international transfers of data." A transfer to a processor in another country isn't automatically prohibited, but it isn't a free pass either.
The accountability stays with you. As the OPC puts it, "an organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing." Choosing Canadian data residency is one straightforward way to reduce how much of that cross-border exposure you have to manage and disclose in the first place. This connects directly to whether an AI report tool can fit your PHIPA obligations.
Does a Canadian company automatically keep my data in Canada?
No. This is the assumption that trips people up. A Canadian name, a .ca domain, and a Toronto address tell you nothing about where the servers are. Plenty of Canadian-branded tools process or back up data in another country because that's where their infrastructure provider happens to run.
So "we're a Canadian company" is not the same claim as "your data stays in Canada." They're different statements, and only one of them is about residency. Ask for the second one, specifically.

The quiet questions are worth asking before the files ever leave the room.
What should I ask a vendor about data residency?
Keep it concrete and make them answer with facts, not reassurance:
- Are storage, backups, and any AI processing all done in Canada?
- If any step happens abroad, which country, and what protections apply there?
- Is data encrypted in transit and at rest, wherever it sits?
- What is retained after processing, and is anything used to train models?
- Will you put the residency answer in writing?
A vendor that keeps everything in Canada can say so in one sentence. If the answer wanders, that's your signal to keep digging. Many of the same instincts clinicians bring to this come up in what I've learned talking to psychologists about AI.
Where does Soma store client data?
Since I'm the one making the point, I'll be plain about our own posture, and I'll stick to facts. Soma keeps client data in Canada. It's encrypted in transit and at rest, de-identified before processing, and handled on a zero-retention basis; where sessions are transcribed, we keep the text, not audio.
I'm not going to tell you that satisfies your legal obligations for you, because that's your assessment to make. What I can tell you is that data residency is a factual, checkable property, and it's one worth confirming for any tool that touches client files. If you'd like to see how that plays out for reports specifically, Soma drafts a report you review and sign.
Thanks for reading. The people your clients are is exactly why the boring infrastructure questions deserve a straight answer, and I'm grateful for the clinicians who hold me to that.
— Ian
