Skip to main content

Growing beyond Canada

Canada Cyber-Safe — independent cyber and AI governance for Canadian organisations

The obligations you pick up without noticing

A Canadian company selling into Europe, the United Kingdom or the United States picks up obligations it did not have at home — usually without noticing, and usually before anyone in the business has thought about it. A customer in Berlin, a user in California, a contract with a British firm. None of them feel like a regulatory event at the time.

This page sets out what actually attaches in each of the three, what your Canadian work already covers, and where the common assumptions are wrong.

Where personal information can move from the EU without extra paperwork

The European Commission has decided that these countries and territories offer adequate protection. A transfer to one of them needs no standard contractual clauses and no transfer impact assessment.

Andorra
Argentina
Canadacommercial organisations only
Faroe Islands
Guernsey
Isle of Man
Israel
Japan
Jersey
New Zealand
Republic of Korea
Switzerland
United Kingdom
Uruguay
United Statescertified organisations only

The assumption that costs Canadian companies most

Canada is on that list. That does not mean you are covered.

The EU adequacy decision for Canada — reaffirmed by the Commission in January 2024, with no expiry date — applies only to organisations subject to PIPEDA. Four gaps swallow a great many real Canadian organisations: public bodies and provincial authorities; non-commercial activity, which takes in charities, universities and research institutes; employee data outside federally regulated sectors, so a Canadian subsidiary receiving HR records from a European parent needs standard contractual clauses unless it is a bank, an airline or a telecom; and any processing that falls outside commercial activity altogether.

And adequacy governs data coming to you. It does nothing about the GDPR applying to you directly under Article 3(2) when you sell into the EU. Those are two different questions and they are constantly confused.

EU

The European Union and EEA

Regulation (EU) 2016/679 — the GDPR

The GDPR reaches you directly under Article 3(2) the moment you offer goods or services to people in the EU, or monitor their behaviour. It does not matter that you have no office there, no entity there, and no staff there.

  • An EU representative. Article 27 requires most organisations caught by Article 3(2) to designate a representative established in a Member State where the people whose data you handle are located.
  • A lawful basis, and the transparency to match. Consent is one of six, and rarely the right one for a business relationship.
  • Data subject rights on a one-month clock, which is tighter than anything in Canadian law.
  • Breach notification within 72 hours to the supervisory authority. PIPEDA says “as soon as feasible”; the GDPR gives you a number, and it is a small one.
  • Records of processing under Article 30, which is close enough to an ISO 27001 asset inventory that the work carries over.
  • The AI Act, already live in the part that catches most people. Article 50 transparency has applied since 2 August 2026: tell people they are talking to a machine, mark synthetic content machine-readably, label deepfakes. Systems deployed before that date have until 2 December 2026. The expensive high-risk obligations were deferred to December 2027, so the cheap part is the part that is due now.

The trap: a UK office cannot be your EU representative. Since Brexit the UK is a third country, so Article 27 has to be satisfied inside a Member State. Anyone offering you EU representation from London is selling you something that does not work.

UK

The United Kingdom

UK GDPR and the Data Protection Act 2018

Since Brexit the UK runs its own regime, and in 2026 it stopped merely being a copy. The Data (Use and Access) Act 2025 came fully into force — most of it on 5 February, the rest on 19 June — and moved UK law away from the EU GDPR in twelve places. The obligations now stack rather than overlap, and in one important respect the UK is looser than Europe rather than stricter.

  • A separate UK representative under the UK’s own Article 27, if you are caught and have no UK establishment. An EU representative does not cover you here, and vice versa.
  • Its own regulator, the Information Commissioner’s Office, with its own reporting route.
  • Its own adequacy findings. The UK recognises Canada on broadly the same partial basis the EU does. — and the European Commission renewed both UK adequacy decisions on 19 December 2025, running to 27 December 2031, with a review at the four-year mark. Data moves EU–UK freely for now.
  • PECR for electronic marketing, which is stricter than CASL in some respects and looser in others. — and whose maximum fine rose from £500,000 to £17.5 million or 4% of global turnover. A thirty-five-fold increase, and the reason your UK consent evidence now deserves real attention.
US

The United States

No federal privacy law. Twenty state laws in effect.

The United States is the hardest of the three, not because any single rule is severe, but because there is no single rule. There is no federal comprehensive privacy statute. Instead there are twenty state laws in effect during 2026, with more enacted and waiting, plus sectoral regimes that cut across all of them.

  • Most states catch you on a threshold. Texas and Nebraska catch you on presence. Most set a count — tens of thousands of residents’ data, or a lower count where you make money from selling it. Montana now bites hardest, at 25,000 residents or 15,000 if you sell data, after its thresholds were lowered in October 2025. But Texas and Nebraska set no number at all: doing business there and processing personal data is enough, unless you are a small business under the US federal definition. For a mid-sized Canadian firm those two are usually the first laws to apply and the last to be noticed. You can be caught in a state you have never visited.
  • Sectoral law sits on top. HIPAA for health, GLBA for financial, COPPA for children. These apply regardless of the state regime.
  • Consumer rights vary by state — access, deletion, correction, opt-out of sale and of targeted advertising, and in several states a right to opt out of profiling.
  • Attorneys General enforce, and several now do so actively rather than theoretically.

What this means practically: the answer is almost never “comply with all twenty”. It is to work out which states your data actually reaches, build to the strictest of those, and revisit it as you grow. Our state applicability tool does the first part from your own numbers, and the SOC 2 crosswalk is free.

The documentation for both, already written

EU overlay pack — CAD $450

Eight documents for the European half: a Statement of Applicability with a European obligation column across all 93 ISO 27001 controls, a legal register arriving populated with fifteen instruments, Article 30 records, a breach register that calculates the 72-hour clock, an AI Act obligations register carrying the dates above, and the Article 27 representative, transfer assessment and DPIA.

See what is in it · Word and Excel, one organisation, perpetual.

UK overlay pack — CAD $450

Eight more for Britain, including a divergence register naming all twelve points where the Data (Use and Access) Act moved UK law away from the EU GDPR — the document that exists because this page is now describing two separate legal regimes rather than one with a footnote.

Both overlays are CAD $795 · sold as two packs on purpose, because merging them would mean pretending the regimes are the same.

The good news, and it is real

Most of the work travels with you.

An organisation that can already evidence a defined control set, a data inventory, a supplier register, tested incident response and a breach register is most of the way to Article 30 records, GDPR accountability and the reasonable-security standard every US state law expects. The regimes differ in their rights, their clocks and their regulators. They agree almost entirely on what good practice looks like. What you built for PIPEDA and Law 25 is not wasted when you cross a border — it is the foundation.

Maya Chen

Practical tip

Maya Chen

Ask where your cloud region physically is. The cloud has a postcode, and the postcode decides which law applies to it.

Cross-border data governance · the people who do the work

What we do, and what we do not

We assess your governance against the regimes you are entering and tell you plainly what would not hold up — the same independent assessment we do at home, scoped to where you are going. Through our United Kingdom office we can act on UK matters directly.

What we will not do is pretend to be something we are not. We are not your EU Article 27 representative, we do not practise United States state law, and where you need local counsel or a designated representative we will say so and help you find one. If you would like to see the standard first, the control set and the ISO 27001 crosswalk are published in full.

Tell us where you are expandingSee what we do

Standards we assess against

ISO/IEC 27001:2022 · ISO/IEC 27701:2025 · ISO 9001:2015 · ISO/IEC 42001:2023 · ISO/IEC 23894:2023 (guidance) · ISO/IEC 42005:2025 (guidance)

Français : La première heure — rédigé en français, pas une traduction automatique.

Canada Cyber-Safe is an independent assessment practice. We are not a certification body and we do not issue certificates.