Resources

Compliance guides for Canadian organizations

Practical guidance on Alberta's POPA, Law 25, the CLOUD Act, Transfer Impact Assessments, and data sovereignty — written for privacy officers, IT leads, and compliance teams managing SaaS environments.

Sovereignty Compliance CLOUD Act 15 min read · March 2026

Canadian Data Sovereignty in 2026: What Organizations Need to Prove

Most Canadian organizations understand sovereignty risks. The problem is proof. When a regulator, procurement officer, or client asks how you manage cross-border data exposure, can you produce a defensible answer? A comprehensive guide to what’s required under Law 25, PIPEDA, and the CLOUD Act.

Read guide →
Buy Canadian Directory Sovereignty 131 tools · March 2026

Buy Canadian SaaS: 131 Canadian-Owned Software Tools

Every Canadian-owned SaaS tool in our Sovereignty Index, organized by category. No CLOUD Act exposure, no foreign jurisdiction. Searchable, filterable, and updated as the index grows.

Browse the directory →
Law 25 Compliance 12 min read

Law 25 and Your SaaS Stack: A Compliance Guide for Quebec Organizations

Quebec's Law 25 requires Transfer Impact Assessments for every cross-border SaaS tool. Learn which tools are affected, what's required, and how to start documenting compliance.

Read guide →
CLOUD Act Sovereignty 10 min read

The CLOUD Act and Canadian Data: What Every Organization Needs to Know

The US CLOUD Act gives American authorities the power to compel access to data held by US companies — regardless of where that data is stored. Here's what it means for Canadian organizations.

Read guide →
CLOUD Act Sovereignty Canada 12 min read · March 2026

Impact of the US CLOUD Act on Data Sovereignty for Canadian Organizations

Five specific ways the CLOUD Act undermines data sovereignty for Canadian organizations — and what to do about it. Covers compliance documentation, sector-specific exposure, contractual limitations, and migration options.

Read guide →
Law 25 TIA 14 min read

Transfer Impact Assessments Under Law 25: What's Required and How to Start

Every cross-border data transfer requires a documented TIA under Law 25. Here's what a TIA must include, when one is triggered, and a practical framework for completing them.

Read guide →
Law 25 Template Downloadable

Model TIA Template for Law 25

The CAI hasn't published a standard Transfer Impact Assessment template. We did. A complete, structured framework any Quebec organization can use to document cross-border SaaS compliance — covering jurisdictional assessment, CLOUD Act exposure, safeguards evaluation, and residual risk determination.

Access the template →
Loi 25 Modèle Français

Modèle d'ÉFVP pour la Loi 25

Version française du modèle d'Évaluation des facteurs relatifs à la vie privée pour la conformité à la Loi 25. Un cadre structuré pour documenter les transferts transfrontaliers de données SaaS, l'exposition au CLOUD Act et les mesures de protection.

Accéder au modèle →
Data Residency SaaS 11 min read

Canadian Data Residency: Which SaaS Tools Offer It (And Which Don't)

A practical breakdown of which popular SaaS tools offer Canadian data residency, which don't, and why residency alone doesn't solve the compliance question.

Read guide →
Data Sovereignty Data Residency 9 min read

Data Residency vs Data Sovereignty in Canada: What's the Difference?

These two terms are used interchangeably — but they describe fundamentally different things. One is a server configuration; the other is a legal and corporate structure question.

Read guide →
PIPEDA Law 25 11 min read

PIPEDA vs Law 25: Key Differences for Canadian Organizations

Both govern personal information — but Law 25 is significantly stricter on consent, cross-border transfers, penalties, and individual rights. A practical comparison for compliance teams.

Read guide →
Procurement Sovereignty 13 min read

Data Sovereignty Requirements for Canadian Government Procurement

Government RFPs increasingly require demonstrated data sovereignty. Here's what procurement teams are asking for and how to document your compliance posture.

Read guide →
Compliance Workflow 14 min read

How to Build a Defensible SaaS Inventory for Canadian Compliance

A step-by-step guide to building the documented SaaS inventory that Law 25, PIPEDA, and procurement sovereignty reviews require. Covers jurisdiction mapping, CLOUD Act exposure, and defensible record-keeping.

Read guide →
Compliance Checklist 12 min read

The Minimum Documentation Canadian Organizations Need for SaaS Compliance

A practical checklist of the six documents Canadian organizations must maintain — and what happens when regulators, auditors, or procurement officers ask for them and you can't produce them.

Read guide →
Sovereignty Action Guide 13 min read

What to Do When Your SaaS Vendors Are Under Foreign Jurisdiction

Your SaaS stack is US-controlled. Now what? A practical action guide covering exposure mapping, risk triage, documentation requirements, remediation options, and ongoing monitoring.

Read guide →
FIPPA BC Public Bodies 10 min read

FIPPA SaaS Compliance for BC Public Bodies

The 2021 FIPPA amendment changed the rules. BC public bodies can now store data outside Canada — but must complete privacy impact assessments evaluating jurisdictional risk. Here's what the new framework means for your SaaS stack.

Read guide →
FIPPA Template Downloadable

FIPPA PIA Template for SaaS Vendors

The BC Privacy Commissioner hasn't published a SaaS-specific PIA template for jurisdictional risk. We did. A structured framework for BC public bodies to assess vendor jurisdiction, CLOUD Act exposure, and safeguards under the amended FIPPA.

Access the template →
New Alberta POPA

Alberta's Protection of Privacy Act requires public bodies to complete PIAs using a mandatory OIPC template. The OIPC reviews your submission.

Alberta POPA PIA March 2026

Alberta POPA PIA Requirements for SaaS — What You Need

The OIPC released a mandatory PIA template. Alberta is the only province requiring template submission to a regulator. What public bodies need to do.

Read guide →
Tool $199 Interactive

PIA Research Tool — Auto-Fill Your OIPC Template

Select your SaaS tools from our 753-tool database. Get pre-written answers for Sections F, G, and H2 of the mandatory OIPC template. $199.

Start PIA Research Tool →
Alberta POPA

Do I Need a PIA Under Alberta's POPA?

When a PIA is required, which PIAs must be submitted to the OIPC, and what happens if you don't complete one.

Read guide →
CLOUD Act Alberta

CLOUD Act in Alberta PIAs — Section G & H2 Explained

How to address CLOUD Act exposure in the OIPC template. The template explicitly names it in Risk 7. Step-by-step guidance.

Read guide →
SaaS Alberta

Alberta PIA for Microsoft 365, Zoom & Slack

How to complete the OIPC template for the most common SaaS tools. CLOUD Act analysis for each vendor.

Read guide →
PMP Deadline

Alberta PMP Deadline — June 11, 2026

Every Alberta public body must implement a Privacy Management Program by June 2026. PIAs are a core component.

Read guide →
Comparison Provincial

Alberta PIA vs BC PIA vs Quebec TIA

Compare the three provinces' requirements. Alberta is the hardest — mandatory template and regulator submission.

Read guide →
By sector
Municipalities

Alberta PIA for Municipalities

From Edmonton to small towns — how municipalities complete PIAs for SaaS tools under POPA.

Read guide →
Education

Alberta PIA for School Boards & Education

Student data is highly sensitive under POPA. How school boards and charter schools complete PIAs.

Read guide →
Post-Secondary

Alberta PIA for Universities & Colleges

Research data, student records, and complex SaaS environments — PIA guidance for post-secondary institutions.

Read guide →
Health

Alberta PIA for Health Authorities

Patient data under both POPA and HIA. How health authorities address CLOUD Act exposure in PIAs.

Read guide →
Police

Alberta PIA for Police Services

Law enforcement data, body-worn cameras, and evidence management — PIA guidance for municipal police.

Read guide →
Government

Alberta PIA for Government Ministries

Enterprise SaaS deployments, data matching, and common programs — PIA guidance for provincial government.

Read guide →

Ready to map your exposure?

HarbourScan identifies jurisdictional risk across your entire SaaS stack — free, browser-based, in about 10 minutes.

Map Your Stack →

Need compliance documentation? TIA and PIA reports from $99 →