MH in Brief MH in Brief

Every rule sourced. Every change dated.

Privacy & data residency

Two questions decide a practitioner’s privacy obligations, and neither is usually the one people ask. First: which statute actually governs you — which turns on how the legislation captures your profession, and that route is not the same for every discipline even inside one province. Second: what happens when client information leaves the province, whether through a hosted platform, a backup, or a colleague across a border.

The matrix below records both, per jurisdiction, with the operative provision quoted verbatim. Where an obligation is a strong reading of two provisions rather than something a source states outright, the row says that plainly rather than presenting inference as citation.

8 records traced and verified for Privacy, across 4 jurisdictions. Every row below carries its own source and last-verified date.

Privacy — obligations by jurisdiction and profession, each sourced to its primary text and dated to the last check against it.
Jurisdiction Applies to The rule Status Last verified Source & citation
Federal Psychologist, Psychotherapist, Counselling therapist, Clinical social worker PIPEDA applies to every organization in respect of personal information it collects, uses or discloses IN THE COURSE OF COMMERCIAL ACTIVITY (s. 4(1)(a)) — 'commercial activity' meaning any transaction, act or conduct, or regular course of conduct, of a commercial character (s. 2). A fee-charging private practice is such an organization. It does not apply to government institutions covered by the Privacy Act, to purely personal or domestic collection, or to journalistic, artistic or literary purposes (s. 4(2)). WHERE A PROVINCIAL LAW HAS BEEN DECLARED SUBSTANTIALLY SIMILAR, the Governor in Council may exempt organizations or activities from PIPEDA — BUT ONLY 'in respect of the collection, use or disclosure of personal information that occurs within that province' (s. 26(2)(b)). Four provincial HEALTH information laws are recognised for personal health information (Ontario PHIPA, Nova Scotia PHIA, New Brunswick PHIPAA, Newfoundland and Labrador PHIA), and Alberta, British Columbia and Quebec have general private-sector laws recognised. Nova Scotia's order is concrete: any PHIA custodian is exempt from PIPEDA Part 1 for personal health information 'that occurs in Nova Scotia' (SOR/2016-62). PIPEDA CONTINUES TO APPLY, even to organizations in those provinces, to personal information transferred ACROSS BORDERS (interprovincial or international), to federal works, undertakings and businesses, and to organizations in the NORTHWEST TERRITORIES, YUKON AND NUNAVUT, which are treated as federally regulated. BREACH OBLIGATIONS. Report to the Privacy Commissioner any breach of security safeguards involving personal information under the organization's control where it is reasonable in the circumstances to believe the breach creates a REAL RISK OF SIGNIFICANT HARM to an individual, as soon as feasible after determining the breach occurred (s. 10.1(1)-(2)); notify the affected individual on the same threshold unless otherwise prohibited by law (s. 10.1(3)); and notify any other organization or government institution that may be able to reduce or mitigate the risk of harm (s. 10.2(1)). Separately and regardless of threshold, KEEP AND MAINTAIN A RECORD OF EVERY BREACH of security safeguards (s. 10.3(1)), for 24 months after the day the organization determines the breach occurred, containing information sufficient to let the Commissioner verify compliance with the reporting and notification duties (SOR/2018-64, s. 6). The Commissioner may demand access to or a copy of that record at any time (s. 10.3(2)).

Vendor-facing: A vendor processing personal information on a clinician's behalf across a provincial or national boundary brings that transfer within PIPEDA even where the practice is otherwise covered by a substantially similar provincial law, because the s. 26(2)(b) exemption reaches only what occurs within the province.

In Force 2026-08-18 Personal Information Protection and Electronic Documents Act (PIPEDA), S.C. 2000, c. 5, ss. 2 (definitions), 4 (application), 10.1-10.3 (breach of security safeguards), 26(2)(b) (substantially similar exemption), 28 (offence)
Show statutory text
"4 (1) This Part applies to every organization in respect of personal information that (a) the organization collects, uses or discloses in the course of commercial activities" ... "26 (2) The Governor in Council may, by order, ... (b) if satisfied that legislation of a province that is substantially similar to this Part applies to an organization, a class of organizations, an activity or a class of activities, exempt the organization, activity or class from the application of this Part in respect of the collection, use or disclosure of personal information that occurs within that province" ... "10.3 (1) An organization shall, in accordance with any prescribed requirements, keep and maintain a record of every breach of security safeguards involving personal information under its control." — Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5. And: "6 (1) For the purposes of subsection 10.3(1) of the Act, an organization must maintain a record of every breach of security safeguards for 24 months after the day on which the organization determines that the breach has occurred." — Breach of Security Safeguards Regulations, SOR/2018-64, s. 6(1). And: "1 Any personal health information custodian to which the Personal Health Information Act, SNS 2010, c. 41, of Nova Scotia applies is exempt from the application of Part 1 of the Personal Information Protection and Electronic Documents Act in respect of the collection, use and disclosure of personal health information that occurs in Nova Scotia." — Personal Health Information Custodians in Nova Scotia Exemption Order, SOR/2016-62
Regulatory model
disclosure
Authority basis
privacy
Enforcement body
Office of the Privacy Commissioner of Canada
Enactment date
not traced
Effective date
2004-01-01
Penalties
Knowingly contravening s. 10.1 (breach reporting and notification) or s. 10.3(1) (keeping a record of every breach), or obstructing the Commissioner in an investigation or audit, is an offence: a fine up to $10,000 on summary conviction, or up to $100,000 on indictment (s. 28). Failing to KEEP THE BREACH LOG is therefore prosecutable in its own right, independently of whether any breach was reportable.
Consent required
Yes
Documentation required
Yes
Confidence
high
Regulation
Breach of Security Safeguards Regulations, SOR/2018-64, s. 6; Personal Health Information Custodians in Nova Scotia Exemption Order, SOR/2016-62
Record ID
ca-federal-privacy-pipeda
Nova Scotia Psychologist, Counselling therapist, Clinical social worker A custodian must notify the affected individual at the first reasonable opportunity where it believes on a reasonable basis BOTH that the information was stolen, lost, or subject to unauthorized access, use, disclosure, copying or modification, AND that as a result there is potential for harm or embarrassment to the individual (s. 69). Where the custodian instead determines that a breach is unlikely to have occurred, or that there is no potential for harm or embarrassment, it may decide not to notify the individual — but it MUST then notify the Review Officer (the Information and Privacy Commissioner) as soon as possible (s. 70). There is no threshold below which a custodian may simply record nothing and tell no one: either the individual is notified, or the regulator is. In Force 2026-08-17 Personal Health Information Act (Nova Scotia), S.N.S. 2010, c. 41, ss. 69-70 (reporting of a privacy breach)
Show statutory text
"69 Subject to the exceptions and additional requirements, if any, that are prescribed, a custodian that has custody or control of personal health information about an individual shall notify the individual at the first reasonable opportunity if the custodian believes on a reasonable basis that (a) the information is stolen, lost or subject to unauthorized access, use, disclosure, copying or modification; and (b) as a result, there is potential for harm or embarrassment to the individual." ... "70(2) Where a custodian makes the decision not to notify an individual pursuant to this Section, the custodian shall notify the Review Officer as soon as possible." — Personal Health Information Act, S.N.S. 2010, c. 41 (consolidation to April 1, 2026)
Regulatory model
disclosure
Authority basis
privacy
Enforcement body
Office of the Information and Privacy Commissioner for Nova Scotia (Review Officer)
Enactment date
not traced
Effective date
2013-06-01
Penalties
Consent required
No
Documentation required
Yes
Confidence
high
Regulation
Personal Health Information Regulations, N.S. Reg. 217/2012, as amended to N.S. Reg. 63/2026 (effective 2026-03-03)
Record ID
ca-ns-privacy-breach-notification
Nova Scotia Psychologist, Counselling therapist, Clinical social worker A 'custodian' includes a regulated health professional, or a person who operates a group practice of regulated health professionals, who has custody or control of personal health information in connection with their powers or duties (s. 3(1)(f)(i)). 'Regulated health professional' means a health professional licensed or registered to provide health care under a provincial Act specific to their profession, who provides health care (s. 3(1)(w)). TWO CARVE-OUTS DECIDE MOST REAL CASES. First, a regulated health professional who is NOT providing health care is not a custodian (s. 6(1)(d)). Second, and far more commonly: a person is NOT a custodian in respect of personal health information they collect, use or disclose while acting as an AGENT of a custodian (s. 6(2)). An 'agent' is anyone authorized to act for the custodian, for the custodian's purposes, whether or not paid — expressly including employees and volunteers (s. 3(1)(aaa)). So an employed clinician at a health authority is an agent, and the institution is the custodian; a clinician in private practice is the custodian themselves. A custodian must designate one or more contact persons to facilitate compliance, inform agents of their duties, respond to inquiries and to access and correction requests, receive complaints, train staff, and develop explanatory materials (s. 67(1)) — and a custodian who is a natural person and designates no one MUST perform those functions personally (s. 67(2)). A custodian must also make available to the public a written statement describing its information practices (s. 68). In Force 2026-08-17 Personal Health Information Act (Nova Scotia), S.N.S. 2010, c. 41, ss. 3(1)(f), 3(1)(w), 3(1)(aaa), 6, 67, 68
Show statutory text
"3(1)(w) 'regulated health professional' means a health professional who is licensed or registered to provide health care under an Act of the Province specific to his or her profession and who provides health care or who is a member of a class of persons prescribed as regulated health professionals" ... "6(2) Except as prescribed, a person described in subclause 3(f)(i) is not a custodian in respect of personal health information that the person collects, uses or discloses while performing the person's powers or duties when an agent of a custodian." — Personal Health Information Act, S.N.S. 2010, c. 41 (consolidation to April 1, 2026)
Regulatory model
clinician_restriction
Authority basis
privacy
Enforcement body
Office of the Information and Privacy Commissioner for Nova Scotia (Review Officer)
Enactment date
not traced
Effective date
2013-06-01
Penalties
Consent required
No
Documentation required
Yes
Confidence
medium
Regulation
Personal Health Information Regulations, N.S. Reg. 217/2012, as amended to N.S. Reg. 63/2026 (effective 2026-03-03)
Record ID
ca-ns-privacy-custodian-status
Nova Scotia Psychologist, Counselling therapist, Clinical social worker Nova Scotia imposes NO data-residency requirement on personal health information by statute or regulation. Neither PHIA nor the Personal Health Information Regulations require that personal health information be stored, hosted, or processed within Nova Scotia or within Canada. What the law does require instead is: (a) security safeguards — a custodian maintaining an electronic information system must implement the prescribed safeguards (PHIA s. 65), which the regulations set out as protection of network infrastructure including physical and wireless networks to ensure secure access, protection of hardware and supporting operating systems, and protection of the system's software including user authentication (Regulations s. 10(1)); and (b) control over DISCLOSURE across borders — a custodian may disclose personal health information to a person outside the Province only on one of the grounds in s. 44, including the individual's consent. One profession-specific exception overrides this at the college level: NSCCT requires its registrants' telecounselling platforms to be PIPEDA-compliant AND hosted on servers holding data exclusively within Canadian jurisdiction. That binds counselling therapists only, not psychologists or social workers.

Vendor-facing: No provincial residency obligation applies to vendors handling Nova Scotia personal health information. Vendors serving NSCCT-registered counselling therapists for telecounselling must host data on servers within Canada and be PIPEDA-compliant, per that College's policy.

In Force 2026-08-17 Personal Health Information Act (Nova Scotia), S.N.S. 2010, c. 41, ss. 44, 65 (and the absence of any residency provision)
Show statutory text
"10(1) The following safeguards are prescribed for an electronic information system maintained by the custodian: (a) protection of network infrastructure, including physical and wireless networks, to ensure secure access; (b) protection of hardware and its supporting operating systems to ensure that the system functions consistently and only those authorized to access the system have access; (c) protection of the system's software, including the way it authenticates a user's identity before allowing access." — Personal Health Information Regulations, N.S. Reg. 217/2012, s. 10(1). [No provision of the Act or the Regulations addresses storage, hosting or transfer of personal health information outside Nova Scotia or outside Canada.]
Regulatory model
none
Authority basis
privacy
Enforcement body
Office of the Information and Privacy Commissioner for Nova Scotia (Review Officer)
Enactment date
not traced
Effective date
2013-06-01
Penalties
Consent required
Yes
Documentation required
No
Confidence
high
Regulation
Personal Health Information Regulations, N.S. Reg. 217/2012, as amended to N.S. Reg. 63/2026 (effective 2026-03-03), s. 10 (prescribed electronic-system safeguards)
Record ID
ca-ns-privacy-data-residency
Ontario Psychologist, Psychotherapist, Counselling therapist, Clinical social worker Two different duties with two different triggers, and the asymmetry is the point. NOTICE TO THE INDIVIDUAL has NO threshold: on any theft, loss, or unauthorised use or disclosure of personal health information, notify the individual at the first reasonable opportunity and state in the notice that they may complain to the Commissioner (s. 12(2)). NOTICE TO THE IPC does have a threshold, set by O. Reg. 329/04 s. 6.3(1): theft is an automatic trigger, while other incidents run through a significance test weighing whether the information is sensitive, the volume involved, how many individuals are affected, and whether more than one custodian or agent was responsible. For a psychotherapy practice the sensitivity limb means even a single-client breach can clear that bar. In Force 2026-07-31 Personal Health Information Protection Act, 2004, S.O. 2004, c. 3, Sched. A, s. 12; s. 72 (offences)
Show statutory text
"(2) ... if personal health information about an individual that is in the custody or control of a health information custodian is stolen or lost or if it is used or disclosed without authority, the health information custodian shall, (a) notify the individual at the first reasonable opportunity of the theft or loss or of the unauthorized use or disclosure; and (b) include in the notice a statement that the individual is entitled to make a complaint to the Commissioner..." — PHIPA, s. 12(2)
Regulatory model
disclosure
Authority basis
privacy
Enforcement body
Information and Privacy Commissioner of Ontario
Enactment date
not traced
Effective date
not traced
Penalties
On conviction: a natural person is liable to a fine of not more than $200,000, imprisonment of not more than 1 year, or both; a non-natural person to a fine of not more than $1,000,000 (s. 72(2)). Most s. 72 offences require WILFUL conduct — ordinary negligence is not an offence, though it can still ground an IPC order. Prosecution requires the Attorney General's consent (s. 72(5)).
Consent required
No
Documentation required
Yes
Confidence
high
Regulation
O. Reg. 329/04, s. 6.3
Record ID
ca-on-privacy-breach-notification
Ontario Psychologist, Psychotherapist, Counselling therapist, Clinical social worker An Ontario private-practice behavioural-health clinician is a health information custodian (HIC) under PHIPA, and therefore carries the Act's full duties — not PIPEDA, which is displaced for activity within Ontario. But the ROUTE into custodian status differs by profession, and the difference matters: psychologists and Registered Psychotherapists qualify under the 'health care practitioner' definition at s. 2(a), by virtue of being members of a college under the Regulated Health Professions Act, 1991. Clinical social workers qualify under a SEPARATE paragraph, s. 2(c), which exists precisely because OCSWSSW is not an RHPA college. A practitioner using an unregulated title is captured only by the residual clause s. 2(d) — 'any other person whose primary function is to provide health care for payment' — which turns on facts about their practice rather than a college registry check, and is a materially weaker footing. In Force 2026-07-31 Personal Health Information Protection Act, 2004, S.O. 2004, c. 3, Sched. A, ss. 2, 3(1) para. 1
Show statutory text
"'health care practitioner' means, (a) a person who is a member within the meaning of the Regulated Health Professions Act, 1991 and who provides health care, (b) Repealed, (c) a person who is a member of the Ontario College of Social Workers and Social Service Workers and who provides health care, or (d) any other person whose primary function is to provide health care for payment;" — PHIPA, S.O. 2004, c. 3, Sched. A, s. 2 (e-Laws consolidation, currency date 2026-07-28)
Regulatory model
clinician_restriction
Authority basis
privacy
Enforcement body
Information and Privacy Commissioner of Ontario
Enactment date
not traced
Effective date
not traced
Penalties
Consent required
No
Documentation required
No
Confidence
high
Record ID
ca-on-privacy-custodian-status
Ontario Psychologist, Psychotherapist, Counselling therapist, Clinical social worker Using a US-hosted EHR, teletherapy platform, or cloud backup engages TWO regimes at once, and most practitioners know about neither. First, PHIPA s. 50(1) permits disclosure of PHI collected in Ontario to a person outside Ontario only on listed grounds — consent, statutory permission, reasonable necessity for the provision of health care, or payment/contractual administration. Ordinary EHR hosting is likely covered by the health-care-provision ground, but that is a ground the practitioner must be able to point to, not an automatic pass. Second, the federal order that exempts Ontario HICs from PIPEDA is scoped to activity 'within the Province of Ontario' — so PIPEDA re-attaches the moment personal health information crosses a provincial or national border. The practical effect: a solo Ontario practitioner on a US-hosted platform may have to satisfy PHIPA s. 50 and PIPEDA simultaneously for that same transfer. In Force 2026-07-31 Personal Health Information Protection Act, 2004, S.O. 2004, c. 3, Sched. A, s. 50(1)
Show statutory text
"Any health information custodian to which the Personal Health Information Protection Act, 2004, S.O. 2004, c. 3, Schedule A, applies is exempt from the application of Part 1 of the Personal Information Protection and Electronic Documents Act in respect of the collection, use and disclosure of personal information that occurs within the Province of Ontario." — Health Information Custodians in the Province of Ontario Exemption Order, SOR/2005-399, P.C. 2005-2224, registered 2005-11-28 (emphasis on the territorial scope is ours; the words 'within the Province of Ontario' are the order's own)
Regulatory model
clinician_restriction
Authority basis
privacy
Enforcement body
Information and Privacy Commissioner of Ontario
Enactment date
not traced
Effective date
not traced
Penalties
Consent required
Yes
Documentation required
No
Confidence
high
Regulation
Health Information Custodians in the Province of Ontario Exemption Order, SOR/2005-399
Record ID
ca-on-privacy-data-residency
Quebec Psychologist, Clinical social worker A clinician carrying on an enterprise (private practice) is responsible for the personal information they hold (a. 3.1). The person with the highest authority in the enterprise exercises the function of PERSON IN CHARGE of the protection of personal information — in a solo practice, the clinician themselves — and may delegate it in writing; the title and contact details of that person must be PUBLISHED ON THE ENTERPRISE'S WEBSITE, or made accessible by other appropriate means if there is no website (a. 3.1). The enterprise must establish and implement governance policies and practices for personal information that cover, among other things, RETENTION AND DESTRUCTION, staff roles and responsibilities across the information life cycle, and a complaints-handling process; they must be proportionate to the enterprise's activities and approved by the person in charge (a. 3.2). A privacy impact assessment (évaluation des facteurs relatifs à la vie privée) is required for any project to acquire, develop or overhaul an information system or electronic service delivery involving personal information, with the person in charge consulted from the outset (a. 3.3). CONFIDENTIALITY INCIDENTS: where there are grounds to believe an incident has occurred, take reasonable measures to reduce the risk of injury and prevent recurrence; and if the incident presents a RISK OF SERIOUS INJURY, promptly notify the Commission d'accès à l'information AND every person concerned (a. 3.5). Risk is assessed on the sensitivity of the information, the apprehended consequences of its use, and the likelihood of prejudicial use, in consultation with the person in charge (a. 3.7). A REGISTER of confidentiality incidents must be kept and a copy sent to the Commission on request (a. 3.8). OUTSIDE QUEBEC: before communicating personal information outside Quebec, the enterprise must conduct a privacy impact assessment considering the sensitivity of the information, the purposes of its use, the protection measures it would carry, and the legal framework of the destination. The same applies where the enterprise entrusts a person or body outside Quebec with collecting, using, communicating or KEEPING such information on its behalf (a. 17).

Vendor-facing: A service provider outside Quebec that collects, uses, communicates or stores personal information on an enterprise's behalf brings the enterprise within a. 17, requiring a privacy impact assessment before the arrangement proceeds and consideration of the destination's legal framework.

In Force 2026-08-17 Loi sur la protection des renseignements personnels dans le secteur privé (modifiée par la Loi 25), RLRQ c. P-39.1, aa. 3.1-3.8 (gouvernance, incidents), a. 17 (hors Québec), aa. 90.12, 91 (sanctions)
Show statutory text
"3.5. [...] Si l'incident présente un risque qu'un préjudice sérieux soit causé, elle doit, avec diligence, aviser la Commission d'accès à l'information [...]. Elle doit également aviser toute personne dont un renseignement personnel est concerné par l'incident" ... "17. Avant de communiquer à l'extérieur du Québec un renseignement personnel, la personne qui exploite une entreprise doit procéder à une évaluation des facteurs relatifs à la vie privée. [...] Il en est de même lorsque la personne qui exploite une entreprise confie à une personne ou à un organisme à l'extérieur du Québec la tâche de recueillir, d'utiliser, de communiquer ou de conserver pour son compte un tel renseignement." — Loi sur la protection des renseignements personnels dans le secteur privé, RLRQ c. P-39.1 (à jour au 1er avril 2026)
Regulatory model
disclosure
Authority basis
privacy
Enforcement body
Commission d'accès à l'information du Québec
Enactment date
not traced
Effective date
2023-09-22
Penalties
Administrative monetary penalties up to $50,000 for a natural person and, otherwise, $10,000,000 or 2% of worldwide turnover, whichever is higher (a. 90.12). Penal fines of $5,000 to $100,000 for a natural person and, otherwise, $15,000 to $25,000,000 or 4% of worldwide turnover, whichever is higher (a. 91), including for failing to report a confidentiality incident when required.
Consent required
Yes
Documentation required
Yes
Confidence
high
Bill
Projet de loi 64 (2021, c. 25) — « Loi 25 »
Record ID
ca-qc-privacy-law25
Not legal advice. This page states rules and quotes their sources; it does not apply them to your situation. Confirm anything that matters with your college or regulator, your accountant, or your insurer before acting on it.