Where your payments data lives: data residency questions for Canadian platforms

Ask a Canadian software platform where its merchants' payment data lives and the usual answer is "in the cloud." Under Quebec's Law 25 that answer no longer holds up. These are the questions that do.

Ask a Canadian software platform where its merchants' payment data lives and you'll usually hear "in the cloud," sometimes "with our processor." Neither is an address. For years that vagueness cost nothing. Quebec's Law 25 changed that, and platforms that run payments inside their product are now holding exactly the kind of data regulators ask about: merchant banking details, owner identity documents collected at onboarding, and a transaction history for every customer those merchants serve.

This is a short guide to what the rules actually require, where payments data tends to travel, and what to ask a payments partner before you sign.

What the law says, in plain terms

Canada has no general rule that personal information must stay in the country. Federally, PIPEDA lets a business send data abroad for processing, as long as it stays accountable for it, protects it with contracts and controls, and tells people their information may be handled in another jurisdiction.

Quebec goes further. Under Law 25, before personal information is communicated outside Quebec, the business has to complete a privacy impact assessment. That assessment weighs how sensitive the information is, why it is being sent, how it will be protected, and the legal regime where it will end up. The transfer then needs a written agreement that reflects what the assessment found. "Outside Quebec" means outside the province, so a server in Toronto counts as well as one in Virginia.

Law 25 also gave individuals a right to data portability from September 2024, and the penalties are real: administrative fines of up to $10 million or 2% of worldwide turnover, and penal fines of up to $25 million or 4%. If your platform onboards merchants in Quebec, their data and their customers' data sit inside that regime.

Where payments data actually goes

Most platforms haven't mapped this part. A single card payment touches more systems than the checkout screen suggests.

  • Onboarding data, meaning legal names, addresses, bank account numbers and ID documents, sits with whoever runs underwriting and compliance.

  • Card data is tokenized and stored by the payment processor, often in more than one region.

  • Authorization travels over the card networks, which are global by design. A Visa or Mastercard transaction between a Montreal merchant and a Montreal customer can still be routed through infrastructure outside Canada.

  • Fraud screening, dispute handling and reporting frequently run on separate subprocessors, each with its own hosting footprint.

Interac Debit is the notable exception, since it runs on domestic rails. Everything else is a chain, and each link has its own answer to "where."

Five questions to ask a payments partner

Where does each category of data sit? Onboarding records, stored card tokens, transaction logs and backups can each live somewhere different. A good partner answers by category, not with a single country.

Which transfers cross a border, and what assessment backs them? If data leaves Quebec or Canada, ask whether a privacy impact assessment exists and whether the written agreements Law 25 expects are in place.

Who are your subprocessors? Ask for the list and where each one hosts. A partner that can't name its own subprocessors can't answer a regulator on your behalf.

Who handles access, portability and deletion requests? When a merchant's customer asks for their data, you need to know whether the request lands with you, with the processor, or somewhere in between, and how quickly it can be met.

What happens in a breach? Law 25 requires notifying the regulator and affected people when an incident carries a risk of serious injury. Ask how fast your partner will tell you, and what they will give you to work with.

How ValPay answers

We won't tell you that every byte stays in Canada. ValPay's rails include global processors such as Adyen and a Fiserv facilitator, and card networks route transactions the way card networks do. What we can do is show you which systems touch a transaction, where they are, and why, so the assessment Law 25 asks for rests on facts instead of guesses. That is also the honest standard to hold any provider to, Canadian-owned or not.

Keeping payments close to home starts with knowing where they go. If you want a quick read on your own setup, the free Payments Health Score on valpay.com takes about two minutes.

This article is general information, not legal advice. Talk to privacy counsel about your platform's specific obligations.

Want to go deeper on this topic?

Talk to our team about embedded payments for your platform.