Skip to main content

Where Does Your Accreditation Data Live?

You probably don't think about it much. Your accreditation evidence lives in spreadsheets on your departmental server, or in a shared drive, or in the cloud service your IT department approved three years ago. The question of where the data physically sits seems like someone else's problem. Until the procurement committee asks, "Where does this tool host our data?" and suddenly the question is yours.

For Canadian engineering programs, data residency is not a nice-to-have. It is a compliance requirement. And the landscape has gotten more complicated in 2026, with new provincial privacy laws, AI tools that process your evidence on foreign servers, and a US law called the CLOUD Act that gives American authorities access to data held by US companies — even when that data belongs to Canadians.

This post breaks down what data residency actually means for accreditation evidence, what the laws require, and why the choice of tool matters more than most coordinators realize.

Data servers in a secure facility — representing where accreditation data lives and the importance of data residency


What Is Data Residency, and Why Should a Coordinator Care?

Data residency is the physical and legal location where your organization's data is stored and processed. It is not the same as data sovereignty, which is the broader question of which country's laws apply to your data. But the two are related: where data lives determines which government can access it.

For accreditation, the data in question includes:

  • Student assessment scores and learning outcome data
  • Faculty teaching evaluations and course outlines
  • Continuous improvement reports and corrective action plans
  • Self-study documents and evidence of Graduate Attribute coverage
  • Visitor team reports and compliance findings

All of this is personal information under Canadian privacy law. Student names linked to assessment data, faculty performance information, course-level outcomes — it all falls under the Personal Information Protection and Electronic Documents Act (PIPEDA) at the federal level, and under provincial laws in Quebec, Alberta, and British Columbia.

The law does not just say "keep data safe." It says you must identify the purposes for collection, limit use to those purposes, and apply appropriate safeguards. When you choose a cloud-based accreditation tool, you are handing your personal information to a third party. Where that third party stores and processes the data determines your compliance exposure.


What PIPEDA Actually Requires

PIPEDA is built on ten Fair Information Principles. The ones most relevant to data residency are:

Safeguards (Principle 8): Personal information must be protected by security safeguards appropriate to the sensitivity of the information. The principle does not prescribe specific technical measures, but the Office of the Privacy Commissioner has made clear that cross-border data transfers require the same level of protection as domestic storage.

Accountability (Principle 1): Organizations are responsible for personal information under their control, even when that information is transferred to third parties for processing. You cannot outsource your compliance.

Canada does not impose a blanket federal data localization requirement. PIPEDA allows cross-border transfers. But the Privacy Commissioner has published guidelines for processing personal data across borders that make the practical requirements clear:

  • You must conduct a privacy impact assessment for significant cross-border transfers
  • You remain accountable for the data even after it leaves Canada
  • Contractual safeguards with the foreign processor must be documented
  • Individuals must be able to exercise their access rights regardless of where the data sits

In short: PIPEDA does not forbid US-hosted tools, but it puts the burden on you to justify the risk. If a US-based accreditation tool stores Canadian student data on US servers, your institution's privacy officer needs to be comfortable with that arrangement.


The CLOUD Act Problem

Here is the part that most software vendors don't tell you. In 2018, the US passed the Clarifying Lawful Overseas Use of Data Act — the CLOUD Act. It gives US law enforcement the authority to compel any US-based company (or foreign subsidiary under US control) to produce data stored on its systems, regardless of where that data is physically located.

This means: even if a US company stores your data in a Canadian data centre, US authorities can still access it under the CLOUD Act. The company's corporate structure matters more than its server location. A Canadian entity wholly owned and managed by a US parent can still be compelled to produce data under US law.

This is not theoretical. The Office of the Privacy Commissioner of Canada has acknowledged this risk. In their 2023 report on cross-border data flows, they noted that "the legal framework in Canada does not provide equivalent protections against extraterritorial access by foreign authorities" and recommended that organizations "consider data localization as a risk mitigation strategy for sensitive personal information."

Accreditation evidence — student outcomes, faculty assessments, program evaluations — qualifies as sensitive personal information.


Quebec's Law 25 Raises the Bar

If your institution is in Quebec, the rules are stricter. Quebec's modernized privacy law (Law 25, formerly Bill 64) came into force in stages through 2023 and 2024, and it adds specific requirements that most provincial privacy laws do not have:

  • Privacy impact assessments (PIAs): Mandatory before implementing new information systems or transferring personal information outside Quebec
  • Designated privacy officer: Every organization must designate a person responsible for personal information protection
  • Cross-border transfer disclosure: You must tell individuals when their data is transferred outside Quebec and explain why
  • Breach notification: Mandatory reporting of confidentiality incidents to the Commission d'accès à l'information
  • Penalties: Administrative monetary penalties up to CAD 10 million or 2% of worldwide turnover for organizations

For a Quebec-based engineering program evaluating a new accreditation tool, this means a privacy impact assessment is a prerequisite. The tool's data residency and cross-border transfer practices are not optional due diligence items — they are legal requirements.


AI Tools Add Another Layer

The accreditation software market has a new category of tools that use AI to analyze evidence — mapping syllabi to learning outcomes, drafting self-study sections, identifying gaps. These tools introduce a data residency question that goes beyond storage: where does the AI processing happen?

Many AI services process data on cloud infrastructure controlled by US companies. When you upload a syllabus to an AI-powered accreditation tool, that document may be transmitted to a US server for analysis, stored temporarily in a US jurisdiction, and potentially used to improve the AI model itself. Even if the final output is returned to you, the intermediate processing has occurred under US jurisdiction.

This raises two distinct compliance questions:

1. Is the AI processing itself a cross-border transfer? If your evidence document crosses the border for AI analysis, that is a transfer of personal information. Under PIPEDA and especially Law 25, this requires documented safeguards and, in Quebec, a privacy impact assessment.

2. Is the AI using your data for model training? Some AI providers include customer data in their training sets unless you opt out. For accreditation evidence, this could mean your institution's assessment data — including student performance information — is being used to train a model that serves other organizations. Under PIPEDA's principle of limiting use, this would require explicit consent.

When evaluating AI accreditation tools, ask these questions before you upload anything:

  1. Where is the AI processing hosted?
  2. Is the processing covered by a Canadian data processing agreement?
  3. Is your data used to train the underlying AI model?
  4. Can you delete all traces of your data after processing?
  5. Does the provider have a Canadian subsidiary or entity that takes legal responsibility for the data?

What Canadian Universities Actually Do

Most Canadian universities have IT procurement policies that address data residency. The specifics vary by institution, but the common themes are:

  • Preference for Canadian hosting: Many institutions require or strongly prefer that SaaS tools host data within Canada. This is often a formal policy requirement, not just a preference.
  • Data processing agreements (DPAs): If data must leave Canada, a legally binding DPA is required. This document specifies the processor's obligations, security standards, and cross-border transfer safeguards.
  • Privacy review for sensitive systems: Tools handling student or faculty data typically go through a privacy review before procurement approval. The privacy officer will ask about data residency, cross-border transfers, and security certifications.
  • Government of Canada alignment: Universities often align with federal guidance. In 2025, the Government of Canada published its Sovereign Cloud Initiative, which prioritizes Canadian cloud infrastructure for government data. While universities are not bound by this policy, many reference it in their own procurement standards.

The bottom line: if your institution has a data residency policy (and most do), the accreditation tool you use must comply. A US-hosted tool may not pass procurement review, regardless of its features.


Three Questions to Ask Before You Choose

When evaluating accreditation software, these are the data residency questions that matter:

1. Where is the data stored? Not just the production database, but backups, logs, analytics, and any AI processing infrastructure. Ask for a data map: where each category of data lives, and whether any category crosses borders.

2. Who owns the data? Your evidence, your mappings, your assessments — you should own them outright. The tool should provide full data export on demand, in a structured format. If the vendor retains copies for "service improvement" purposes, that should be opt-in, not default.

3. What is the legal jurisdiction? A Canadian company hosting data in Canada means Canadian law applies. A US company — even with Canadian data centres — means the CLOUD Act can apply. A Canadian subsidiary of a US company may mean both jurisdictions apply. Ask about corporate structure, not just server location.


The Practical Bottom Line

Data residency is not a checkbox on a feature comparison sheet. It is a legal and procurement requirement that can block a software purchase at the final stage. We have seen institutions fall in love with a tool's features, only to have the privacy office reject it because the data crosses the border.

For Canadian engineering programs, the simplest path is a Canadian-hosted tool that handles CEAB accreditation natively, keeps all data within Canadian jurisdiction, and provides a DPA that aligns with your institution's policy. That is what MapOutcomes was built for. Canadian-hosted. PIPEDA-compliant. CEAB-native from day one.

The alternative is building a business case for cross-border data transfer. That means a privacy impact assessment, a legal review of the provider's terms, a DPA negotiation, and a procurement exception if your institution's policy requires Canadian hosting. If the features of a US-hosted tool are worth all that effort, go for it. But know what you are signing up for.


Further Reading


See how Canadian-hosted accreditation management works.

MapOutcomes keeps your evidence in Canada, maps it to CEAB Graduate Attributes, and gives you a compliance dashboard that updates in real time. No cross-border data transfers. No privacy impact assessment required.

Request a Demo    Talk to Us

← Back to Blog Connect Demo