Disclosure: DROZlegal publishes this guide and is itself hosted in AWS ca-central-1, the region discussed below. The regulatory and CLOUD Act facts cited here are sourced directly from Borden Ladner Gervais LLP, Osler, Hoskin & Harcourt LLP, the Law Society of British Columbia, and AWS's own published materials — fetched and verified for this article, not asserted as DROZlegal's own claims.
What “AWS ca-central-1” actually is
A region is a specific place, not a promise. AWS ca-central-1 is Amazon Web Services' Canada (Central) Region — a physical data-center cluster located near Montréal, Québec, built across three separate availability zones for redundancy. It sits alongside AWS's Canada West region (Calgary) as one of two Canadian options AWS offers customers who need to process data inside the country.
AWS's own published guidance says it will not move customer content to a different region without the customer's agreement, except as necessary to comply with the law or a binding order of a governmental body. That single exception is the seam this whole topic runs through — a firm can pick the right region in writing and still have a real question left open, which the CLOUD Act section below addresses directly.
Why the region has to be named in writing, not implied
“Hosted in Canada” is not a technical answer until it names a region. A software vendor can be Canadian-incorporated, headquartered in Toronto or Vancouver, and still route the actual AI-processing step of a document through infrastructure outside the country. Incorporation location and processing location are two different facts, and only one of them is enforceable once it's written into a contract.
Ask a vendor for the specific region — AWS ca-central-1, Azure Canada Central, or the equivalent — in the data-processing addendum itself, not a jurisdiction claim on a marketing page. DROZlegal's own architecture page states this claim at that level of specificity: stored client data is hosted in AWS ca-central-1 and never leaves Canada (see DROZlegal's security and residency architecture).
Why this matters specifically for a law firm's data
A law firm's data-residency decision carries three separate legal layers most general “cloud computing” guidance doesn't distinguish:
- Law-society due diligence. The Law Society of British Columbia's Cloud Computing Checklist frames data location as one of several due-diligence questions a lawyer must resolve before entrusting client records to any cloud vendor — alongside encryption, access controls, and what happens if the provider shuts down. Other provincial law societies, including the Law Society of Ontario, publish comparable cloud-computing guidance for their own members.
- PIPEDA accountability. Per the Office of the Privacy Commissioner of Canada's guidance, PIPEDA does not itself require Canadian data residency — a firm can send personal information to a processor anywhere, including outside Canada. But the firm stays fully accountable for what happens to it, and that accountability runs through a real contract, not a vendor's terms-of-service checkbox.
- Quebec's Law 25. Since September 22, 2023, any transfer of personal information outside Quebec has required a documented privacy impact assessment first. It applies based on whose personal information is involved, not where the firm's office sits — an Ontario firm with even one Quebec-connected file can trigger it.
For the fuller Canada-specific evaluation beyond hosting alone — PIPEDA, Law 25, and LSO vendor-selection duties across an entire AI-software purchase — see our AI legal software Canada buyer's framework.
The nuance most residency marketing skips — the U.S. CLOUD Act
A named region answers “where.” It doesn't fully answer “who can still compel access.” The 2018 U.S. CLOUD Act lets U.S. authorities compel a U.S.-based company — or a foreign subsidiary genuinely under that company's control — to produce data in its custody, regardless of which region physically stores it.
Data sovereignty is about control, not just location. Storing data in Canada does not, by itself, prevent access under foreign laws. — Borden Ladner Gervais LLP, April 13, 2026
That doesn't mean the risk is unlimited or imminent. Osler, Hoskin & Harcourt's October 2025 analysis is worth weighing alongside it: the CLOUD Act “did not create new authority” for U.S. law enforcement to obtain data, it requires comity protections that let a provider challenge a demand that would violate Canadian law, and — as of that writing — no documented cases existed of a foreign government actually accessing Canadian enterprise cloud data through it.
The practical question for a law firm isn't “is my data in Canada” alone — it's “who owns and controls the company processing it.” A Canadian-incorporated vendor using Canadian infrastructure, with no U.S. parent or controlling shareholder, sits outside the CLOUD Act's reach in a way a U.S.-controlled vendor with a Canadian data center does not.
Region vs. control: what a named AWS region answers, and what it doesn't
Bring these as separate questions into any vendor evaluation — a single “where is my data hosted” answer doesn't cover all of them.
| Question | Does a named region (e.g. ca-central-1) answer it? | What still needs a contract or disclosure |
|---|---|---|
| Where is data physically stored at rest? | Yes — verifiable, named region | — |
| Will the provider move my data to another region without consent? | Yes, per AWS's own regional commitment | Doesn't cover the vendor's own use of the data outside AWS |
| Is the vendor, or its parent company, subject to U.S. CLOUD Act jurisdiction? | No | Needs disclosure of corporate ownership and control structure |
| Who are the sub-processors, and where are they located? | No | Needs a published sub-processor list |
| What happens to my data if the vendor is acquired by a U.S. company? | No | Needs a contractual data-portability or termination clause |
If you want the region-versus-control distinction above as a standing reference for your firm's next vendor review — rather than re-deriving it on a demo call — join the DROZlegal newsletter; posts like this land there first.