Where your documents actually live when you upload them
Where your documents actually live when you upload them
"The cloud" is a physical building, in a country, subject to that country's laws. When you upload a passport scan, that file comes to rest on a specific disk in a specific jurisdiction — and that jurisdiction's legal process is the one that applies to it.
Most people never check which one. For a photo of a birthday party, that is reasonable. For an identity document, it is worth two minutes.
Why jurisdiction matters
Three practical consequences follow from where a file is stored:
- Which privacy law protects it. Data stored in Canada is governed by Canadian privacy law — PIPEDA federally, plus provincial legislation. Data stored elsewhere is governed by that jurisdiction's rules, which may give you fewer rights, a shorter retention limit, or none.
- Which authorities can compel disclosure, and how. Every country has legal processes by which authorities can require a provider to produce data. Those processes differ in what notice you get, what threshold applies, and whether you can challenge them.
- Where you complain when something goes wrong. The Office of the Privacy Commissioner of Canada can act on personal information handled by organizations subject to Canadian law. Its reach over a foreign provider with no Canadian presence is more limited.
This is not about assuming bad faith by any provider. It is about knowing which rulebook applies.
The nuance worth stating honestly
"Stored in Canada" is a meaningful protection, not a force field.
A provider that stores data in Canada but has a corporate presence in another country may still face legal demands in that country. Cross-border legal cooperation exists. Some frameworks give authorities in one country a route to data held by companies subject to their jurisdiction, wherever the servers sit.
So the accurate statement is: Canadian residency means Canadian law governs your data and Canadian process applies to it, and it removes the most direct foreign routes. Anyone claiming more than that is overselling.
How to find out where a service stores your data
In order of reliability:
- The privacy policy. Look for "data residency", "storage location", "where we store your information", or "international transfers".
- A trust or security page. Services that take this seriously usually publish one, often naming their sub-processors — the third parties who also touch your data.
- The data-processing agreement, if there is one.
- Ask support directly, and get the answer in writing.
A service that cannot or will not tell you where your data is stored has answered the question.
The questions worth asking
Before uploading identity documents anywhere:
| Question | Why it matters |
|---|---|
| Where is the data physically stored? | Determines the applicable law |
| Who else touches it? | Sub-processors inherit your data; each is another jurisdiction and another breach surface |
| Is it encrypted at rest, and who holds the keys? | Provider-managed keys mean the provider can technically decrypt |
| Is content used to train AI models? | A materially different question from "is it encrypted" |
| Is content sent to third-party AI providers? | An AI feature can move your document to another company entirely |
| How long is it retained after deletion? | Backups and recycle bins outlive the delete button |
| Can I export everything, and at what cost? | Export friction is lock-in |
| Is there a record of what I shared and with whom? | Essential after any incident |
The AI question is newer and larger than people realize
Many document services have added AI search, summarization, or extraction. A significant number implement this by sending your document contents to a third-party model provider — a different company, often in a different country, with its own terms.
Your file may be stored in Canada and still have its contents transmitted elsewhere every time you use the search box.
So ask two separate questions:
- Where is my file stored?
- Where is my file's content processed when I use an AI feature?
The second is the one most services answer least clearly.
Encryption, briefly
"Encrypted at rest" means the data on disk is unreadable without a key. The question that matters is who holds the key.
- Provider-managed keys — the provider can decrypt, which is what makes search, previews and recovery work. This is the common model, and it is fine, provided it is disclosed.
- Customer-managed / zero-knowledge — only you can decrypt. Stronger, but search, previews and password recovery generally stop working, which is why few consumer document services offer it.
Neither is dishonest. What matters is that the provider says which one they use rather than leaving "bank-level encryption" to do the work.
A general cloud drive is not a bad tool, it is a different tool
Major cloud drives are well engineered and defended. They are simply not built for this specific job. For identity documents they typically leave four things unanswered:
- residency — often not selectable on consumer plans
- content scanning and AI training — governed by broad consumer terms
- sharing records — link sharing exists; an audit trail of who opened what usually does not
- structure — a drive holds files, so finding the right one remains your problem
How my-id.ca answers these questions
We built the product around this page, so here are the answers directly:
- Storage location: Canadian servers. Backups stay in the same jurisdiction.
- Encryption: encrypted at rest; keys are managed by my-id.ca — which is what makes search and previews work, and we say so plainly rather than implying zero-knowledge.
- AI processing: runs on my-id.ca's own infrastructure in Canada. Your document contents are not sent to OpenAI, Google, Anthropic, or any third-party AI provider, and are not used to train third-party models.
- Sub-processors: listed individually on Trust and security.
- Sharing record: sharing history records what you shared and with whom.
- Export: export everything at any time — no fee, no waiting period.
- What we do not have: no third-party attestation or SOC 2 report at this time. It is on the trust page, because a security page that only lists good news is not a security page.
Apply the same eight questions to us that you would apply to anyone else, and hold the answers against the trust page.
Next steps
- Your data was in a breach — what to do now
- How to send sensitive documents securely in Canada
- Your data and privacy in my-id.ca
- Export, correct, or delete your data
Important: this is general information, not legal advice
This article is general information — it is not legal, privacy, or security advice, and my-id.ca does not provide legal or professional consultation. my-id.ca is not a government agency, law firm, lawyer, or licensed advisor, and is not affiliated with or endorsed by the Office of the Privacy Commissioner of Canada, the Government of Canada, or any cloud provider named or implied.
Privacy legislation, cross-border legal frameworks, and any given provider's storage and processing practices change over time. Confirm the current position with the Office of the Privacy Commissioner of Canada and directly with each provider, in writing. Statements about my-id.ca on this page describe our practices at the date shown and are set out in full in our privacy policy and trust page, which govern. For advice about your individual circumstances, consult a qualified professional.
Frequently asked questions
- What does data residency mean?
- The country where your data is physically stored. It matters because the laws of that country apply to the data — including the legal processes by which authorities there can compel a provider to produce it — regardless of where you live or which country you signed up from.
- Does storing data in Canada mean foreign governments cannot access it?
- It means Canadian law governs the data and Canadian legal process applies. It does not create absolute immunity — a provider with a corporate presence in another country may face legal demands there. Residency is a meaningful protection, not an impenetrable one.
- How do I find out where a service stores my data?
- Check the privacy policy and any trust, security or data-processing page for the words data residency, storage location, or sub-processors. If it is not stated, ask support directly and get the answer in writing. A service that will not answer has told you something.
- Is my data safe in a general cloud drive?
- Major cloud drives are well engineered against ordinary attack. The questions they answer less well for identity documents are where the data lives, who at the provider can access it, whether contents are scanned or used to train models, and whether you get a record of what you shared.
- Does encryption mean the provider cannot read my files?
- It depends on who holds the key. If the provider manages the encryption keys, the provider can technically decrypt. If only you hold the key, they cannot — but then features like search and previews usually stop working. Most services choose the first model and should say so.
- Are my documents used to train AI models?
- That depends on the service and its terms, and this is a question worth asking explicitly. Look for a clear statement about whether content is sent to third-party AI providers and whether it can be used for model training.