Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Privacy

Cross-Border Compliance: When Your Partner Is in Another Country

The question is operational, not patriotic

Cross-border readiness engagements work, and they work often. A firm in another country may hold deeper experience in your vertical and be the best available team for the job. Location is not competence, and treating it as competence is lazy buying.

What location changes is a set of operational facts. When your readiness partner sits in a different jurisdiction from your data, four things move from background to foreground: where evidence lives during the engagement, which privacy statutes attach to sending it there, who must complete a documented assessment first, and which court hears it if the relationship goes wrong.

Each has an answer that belongs on paper before the kickoff call, and a cross-border partner with clear answers to all four is a better choice than a local one with none.

What actually crosses the border

Readiness work collects evidence that controls exist and operate, so someone outside your company holds:

  • Identity provider screenshots, showing user lists with names and email addresses
  • Access review exports, which are by definition lists of who has what
  • Offboarding records, which are lists of people who left and when
  • Incident and ticket records, often carrying customer names, affected record counts and free-text detail an engineer typed at 2 a.m.
  • Vendor inventories, cloud configuration exports, backup logs, key management settings
  • Occasionally, production data samples, where a control can only be shown by showing the data it guards

The last one is underestimated. Showing that field-level encryption works, or that a retention job actually deletes, sometimes requires showing a record. On a medtech engagement we ran to a SOC 2 Type I, the auditor's evidence request came to 84 items, and a handful could not be met with a policy document. The full account is published.

Where the evidence lands, under whose law, for how long

Where does it live. Not "in our secure portal": which platform, which region, which cloud account. Ask which subprocessors touch it too: a readiness firm runs on a compliance platform, a cloud drive, a ticketing tool and a chat tool.

Under whose law. The law attaching to evidence at rest is the law of the place it is stored, plus any law reaching the entity storing it. A firm incorporated in one country and storing in another may be exposed to both. This is a mapping exercise, not an accusation about anyone's legal process.

For how long. Readiness evidence has no natural expiry. It sits in a folder unless somebody deletes it, so ask for a retention period in writing, what starts the clock, and whether backups are in scope.

What happens at the end. Return, destruction, or certification of destruction. Pick one, name a deadline and name who signs. A partner comfortable committing to destruction 30 days after final deliverable has thought about this before.

PIPEDA and transfers for processing

Under the Personal Information Protection and Electronic Documents Act, sending personal information to a third party for processing is treated as a use by your organization rather than a disclosure. The obligation does not travel with the data. You stay accountable.

Principle 4.1.3 of the ten Fair Information Principles is the operative text. An organization is responsible for personal information in its possession or custody, including information transferred to a third party for processing, and must use contractual or other means to provide a comparable level of protection while that third party processes it. That comparable protection is something you must be able to evidence: if the Privacy Commissioner asks how you discharged Principle 4.1.3 for your readiness partner, the answer is a contract clause and a due diligence record, not a handshake.

Two further consequences. First, PIPEDA imposes no data residency rule: the obligation is accountability, not geography.

Second, openness applies. Principle 4.8 makes your policies and practices something individuals can ask for, and the Commissioner's long-standing position is that organizations should be transparent about transfers outside Canada and the exposure to foreign legal process that follows. A privacy policy silent on processing outside Canada is now inaccurate.

Quebec Law 25 and the assessment that comes first

If your organization holds personal information in Quebec, a procedural step applies that PIPEDA does not impose. Under the Act respecting the protection of personal information in the private sector (P-39.1), as amended by Law 25, an enterprise intending to communicate personal information outside Quebec must first conduct a privacy impact assessment covering the sensitivity of the information, the purposes, the protection measures that would apply, and the legal framework of the receiving jurisdiction, including whether it offers protection equivalent to the principles of Quebec law. The communication may proceed only if the assessment shows the information would receive adequate protection, and the transfer must be the subject of a written agreement taking those results into account.

The sequencing is the point. The assessment comes before the information moves. Not at the end of the engagement, not when the auditor asks. Before the first screenshot of your Quebec staff list lands outside the province.

Note the wording: outside Quebec, not outside Canada. A partner in Ontario triggers the same requirement as one in Texas. The content differs, because the framework being assessed differs, but the obligation is identical, and Canadian buyers working with Canadian partners miss it as often as anyone.

Quebec's penalty structure is two separate regimes, routinely conflated. Section 90.12 sets an administrative monetary penalty with a ceiling of $10,000,000 or 2% of worldwide turnover for the preceding fiscal year, whichever is greater ($50,000 for a natural person). Section 91 sets a penal offence carrying a fine of $15,000 to $25,000,000, or 4% of worldwide turnover, whichever is greater ($5,000 to $100,000 for a natural person). There is also a private right of action with minimum punitive damages. If you have seen Law 25 summarized as a single "$25M or 4%" figure, that is the penal ceiling, and quoting it as the administrative penalty is wrong.

We run Quebec work as a scoped sprint because the assessment and the agreement have to land in that order. The Law 25 Readiness Sprint is on the pricing page.

Alberta, British Columbia and Ontario health information

Alberta. Where an organization uses a service provider outside Canada to handle personal information on its behalf, the Personal Information Protection Act requires written policies covering that arrangement and notice to individuals of how to obtain information about them, including the countries involved and the purposes. It is a transparency obligation rather than a prohibition, and it is your privacy officer's to produce.

British Columbia. BC's private sector Personal Information Protection Act imposes no residency rule. The residency rules people remember from BC belong to the public sector statute, and those were loosened in 2021. For a BC private company the analysis is accountability and consent, not geography.

Ontario health information. For a health information custodian, or an agent or electronic service provider acting for one, the Personal Health Information Protection Act sits on top of everything else. Custodians must take steps reasonable in the circumstances to protect personal health information, and the electronic service provider rules constrain what a provider may do with what it handles. Readiness evidence for a health technology company often contains personal health information inadvertently, in a screenshot or an incident record. Decide in advance whether it may, and who may hold it.

SOC 2 covers none of it, so build the evidence once

SOC 2 is an attestation against the Trust Services Criteria: an independent licensed CPA firm examines your controls and reports on their design, and for a Type II on their operating effectiveness over a period. The privacy criteria, where a company elects to include them, come from generally accepted privacy principles. They are not PIPEDA, Law 25, Alberta PIPA, BC PIPA or PHIPA, and a clean report is not a statement that you comply with any of them. ISO 27001 certification is not a finding of statutory compliance either.

So somebody has to know which Canadian regimes apply to you, and be named for it. Ask directly: who owns the Canadian privacy analysis, and what have they done before.

The payoff is that the work then collapses. The evidence satisfying a SOC 2 access control criterion, a PIPEDA safeguards obligation, a Law 25 governance requirement and an ISO 27001 Annex A control is substantially the same evidence. One incident response record serves the SOC 2 examination, the PIPEDA breach records obligation and the Law 25 register. What varies is the framing, the retention period and who signs.

Design the evidence set once against the full map and the incremental cost of the second and third regime is small. Design it only against the audit framework and the work gets done two or three times, with different naming each time, until reconciliation becomes its own project.

It is also why we work in two phases: a gap assessment that sets scope and produces a findings register, then remediation priced from those findings. Remediation cannot be honestly priced before anyone knows the gaps, and a partner quoting a fixed price before assessing anything has priced a guess, wherever they sit.

Coordinating with the audit firm

The audit is performed by an independent licensed CPA firm, or for ISO 27001 the certification is issued by an accredited certification body. The readiness partner is not the auditor and must not be.

Time zones come up first and matter least. Fieldwork is mostly asynchronous evidence exchange with a few live sessions, so a six-hour offset costs a slower round trip, not a failed audit. Working calendars matter slightly more, since statutory holidays differ. The question that actually predicts how the audit goes is neither: has the readiness partner worked with this specific audit firm before, and do they know what it asks for?

Audit firms are not interchangeable in their evidence expectations. Two testing the same criterion will want different artifacts, different sample sizes, different population definitions, and will hold different tolerance for compensating controls. A partner who has been through fieldwork with your chosen firm knows which controls it will push on and what it accepts as proof. One who has not will build a defensible evidence set that still draws a long list of follow-ups, because it was built to the standard rather than to the firm.

That knowledge comes from repetition, not geography. A partner abroad with six engagements behind them at your audit firm knows more about it than a local one who has never met them. A documented readiness position can move the quote: on one engagement it took $11,000 off the number, because the audit firm could see how much work was already done.

Confirm two things alongside it: who selects the audit firm, and whether any referral or revenue arrangement exists between readiness partner and auditor.

Contracting, governing law and where you would bring a claim

Which entity signs. The entity on the proposal, the entity on the invoice and the entity employing the consultant are sometimes three companies in three places. The one that matters is on the signature line, because it holds the obligations and its balance sheet backs the indemnity. Ask for the full legal name and jurisdiction of incorporation, and check it matches the insurance certificate.

Which law governs. A clause naming a province or state you have never operated in is not automatically bad, but it has consequences: limitation periods differ, and so does the enforceability of limitation of liability clauses. For a Quebec enterprise, the written agreement Law 25 requires has to reflect your assessment results, easier to negotiate during contracting than after.

Where you would bring a claim. Governing law and forum are separate clauses pointing to possibly different places. The practical test: if evidence were mishandled or a deliverable never arrived, where would your counsel file, and what would that cost before anyone heard the merits. Arbitration in a distant seat is a real cost even when the arbitration never happens, because it shifts the bargaining position in every dispute short of one. Ask for professional liability and cyber liability certificates too, with limits, and check whether the policies respond to claims arising in Canada.

The checklist to run on any partner in any country

Run it on every candidate, including the one down the street. A local partner who fails it is worse than a distant one who passes.

Evidence and data

  1. Which platform and region will hold engagement evidence, named specifically.
  2. Which of your subprocessors touch it, and where are they.
  3. What is the retention period, what starts the clock, and are backups in scope.
  4. Will you sign a return or certified destruction commitment with a named deadline.
  5. May any evidence contain production personal information, and if so what handling applies.
  6. Who at your firm can access it, and how is that access reviewed.

Privacy law

  1. Which Canadian privacy regimes apply to us, and why.
  2. Who on your team owns that analysis, and what have they done before.
  3. For Quebec, will you support the privacy impact assessment required before information is communicated outside the province, and will the agreement reflect its results.
  4. For Alberta, can you provide what we need for our notification and policy obligations.
  5. Will our privacy policy need to change to describe this processing accurately.

Audit and delivery

  1. Have you worked with our chosen audit firm before, and on how many engagements.
  2. Can we speak to two Canadian references, ideally in our sector.
  3. Is remediation priced before or after the gap assessment.
  4. Who is the named practitioner, what credentials do they hold beyond a baseline certification, and will they still be here in month three.
  5. Is there any referral or revenue arrangement between you and any audit firm.

Contract

  1. Which legal entity signs, and where is it incorporated.
  2. Which province's or state's law governs, and where would a claim be brought.
  3. What are the professional liability and cyber liability limits, and does the policy respond to Canadian claims.

Nineteen questions, answerable in one call. A partner who answers them precisely has done this before, and one who deflects has told you something useful too.

What to do next

If part of your data or your people sit in Quebec, Alberta, BC or under Ontario health information rules, the privacy mapping is not a footnote to the audit project. It decides what evidence gets built, in what order, and what must be documented before anything moves.

TrazTech is a Canadian readiness partner and never the auditor, and we will tell you plainly where engagement data lives and which entity signs. Start with the gap assessment, and bring your jurisdiction map or let us build it in week one. See what a readiness engagement covers, or read the published case studies.

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on SOC 2 and compliance. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.