Fax.Plus
>
Data Sovereignty in Canada

Data Sovereignty in Canada

Data Sovereignty in Canada

What data sovereignty and data residency mean for Canadian healthcare teams that fax and sign documents, how PHIPA fits in, and what to check before you choose a provider.

Published on
October 6, 2026
Last updated on
October 7, 2026
Share
  • Data residency is where your data is physically stored. Data sovereignty is the wider question of whose rules and control that data falls under.
  • In Ontario, PHIPA sets the rules for personal health information, including when a service provider handles it on a custodian's behalf.
  • Before you choose a fax provider, ask where fax files and backups are stored, who owns and runs the provider, and which agreement you sign for health information.
  • Fax.Plus Enterprise can store fax files and their backups in Toronto or Montreal and comes with a signed PHIPA Service Provider Agreement, and Sign.Plus, Alohi's e-signature product, offers the same for the documents you sign.

Fax is still how a large share of Canadian health information moves. Referrals, lab results, prescriptions, and records requests arrive by fax every day in clinics, pharmacies, and hospitals. Many of those documents also need a signature before they go back, so the same records often pass through an e-signature tool as well. When fax and signing move to the cloud, a question follows quickly from privacy officers and procurement teams: where does this data live, and who controls it?

That question is what people mean by data sovereignty. This guide explains the term in plain language, how it relates to data residency and PHIPA, and what to check before you pick a fax or e-signature provider for health information.

What is data sovereignty in Canada?

Data sovereignty is the idea that data is subject to the laws and control of the place where it is collected, stored, or processed. In practice, Canadian organizations use the term to ask two things about any service that holds their data:

  • Where is the data? The country and data center where files and backups are kept.
  • Who controls it? The company that operates the service, and the rules that company has to follow.

Data residency answers the first question. It is the part you can name in a contract: a city, a data center region, a backup location. Data sovereignty takes in both questions, which is why it shows up in security questionnaires next to residency, encryption, and access controls.

For healthcare, the topic is not abstract. Health information is among the most sensitive data an organization holds, and in Ontario, PHIPA sets specific rules for how it is collected, used, disclosed, and protected, including when an outside provider handles it.

Data residency vs data sovereignty: why the difference matters

The two terms are often used as if they mean the same thing. They overlap, but they answer different questions, and a provider can be strong on one while saying little about the other.

Data residency is about location. It tells you the country, city, or data center region where your files are stored, and ideally where the backups are kept too. It is concrete and easy to verify: a good provider lets you choose the region, shows it in your account settings, and writes it into the contract.

Data sovereignty is about control. It covers residency, but it also asks who operates the service, which company signs your agreement, and what that company commits to in writing about how your data is handled.

For a Canadian healthcare team, that leads to a practical rule: start with residency, because it is the part you can confirm, then look at what surrounds it. Four details are easy to miss:

  • Backups. Residency should cover backup copies, not only the live files. Ask whether backups stay in the same region or can be placed in a second Canadian location.
  • Moving data later. If your requirements change, can you move stored data to another region yourself, or does it take a support ticket and a migration project?
  • Files in transit. Residency describes where stored files and backups live. Faxes that are being converted or transmitted are handled temporarily before they are stored, so ask each provider how it treats files in transit and how quickly temporary copies are deleted.
  • Retention. Data that is not kept cannot be exposed. Ask whether you can set how long faxes are stored, or turn storage off and keep faxes only in your own systems.

None of this replaces legal advice. It does give your privacy officer and IT team a shared vocabulary for comparing providers, and a short list of questions to put in writing.

How PHIPA applies when you fax health information

Ontario's Personal Health Information Protection Act (PHIPA) sets the rules for personal health information in the province. It is built around the health information custodian: the hospital, clinic, pharmacy, lab, or practitioner that is responsible for the information. PHIPA requires custodians to take reasonable steps to protect personal health information in their custody or control against theft, loss, and unauthorized use or disclosure, and to protect records against unauthorized copying, modification, or disposal.

Custodians rarely do everything themselves. PHIPA also defines an agent: a person or organization that, with the custodian's authorization, acts for or on behalf of the custodian in respect of personal health information, for the custodian's purposes and not its own. PHIPA also sets rules for electronic service providers that supply the technology custodians use to handle health information. A cloud provider that handles faxes on a custodian's behalf works inside this framework, which is why the agreement you sign with the provider matters as much as the technology.

Fax adds a few specific risks, because documents arrive outside your EHR:

  • Faxes sit in a separate inbox. Referrals and results wait in a fax account until someone files them, so that account needs the same access controls as the rest of your health records.
  • Copies multiply. Email notifications, downloads, and printouts can create extra copies of the same record, and so can a signing round that runs through a separate tool. Settings that keep attachments out of email, limit who can download, and keep signing inside the same platform help keep copies under control.
  • Retention is easy to forget. Faxes kept indefinitely in a provider's account are records you are still responsible for. A defined retention period, or no storage at all, keeps that footprint small.

PHIPA does not require personal health information to be stored in Canada. It focuses on safeguards and accountability. Many organizations add their own requirements on top, such as keeping health records and backups in Canadian data centers, and write them into their policies and vendor contracts. If you need the full comparison with US rules, see PHIPA vs HIPAA. For questions about your own obligations, the Information and Privacy Commissioner of Ontario publishes guidance for custodians.

What to check before choosing a fax provider

Use these eight questions in your vendor review. Ask for the answers in writing, and keep them with the contract.

  1. Where are fax files stored, and where are the backups? Get the region for both. "Canada" is a start; a named city or data center region is better.
  2. Can you choose the region yourself, and change it later? Look for a setting your admins control, and a documented way to move stored data if your requirements change.
  3. Who owns and operates the provider? Ask which company runs the service, where it is headquartered, and which legal entity signs your agreement.
  4. Which agreement do you sign for health information? For Ontario custodians, ask for an agreement that covers PHIPA and the provider's role as your agent, check which plan includes it, and confirm it also covers the tool you use to sign the documents you receive by fax.
  5. How long are faxes kept, and can you turn storage off? A configurable retention period, or the option not to store faxes at all, limits what the provider holds on your behalf.
  6. How is access controlled and logged? Look for role-based access, two-factor authentication, single sign-on, and an audit trail of who viewed or downloaded a fax.
  7. How are files encrypted? Ask about encryption at rest and in transit, and how email notifications are handled so health information does not travel as an attachment.
  8. Which independent audits back the security claims? Certifications such as ISO 27001 and a SOC 2 Type II report show that an outside auditor has checked the controls.

A provider that answers all eight clearly, and puts the answers in its agreement, gives your privacy officer what they need to sign off.

How Fax.Plus supports Canadian data residency

Fax.Plus Enterprise answers each question on the checklist, and puts the answers in writing. It starts at $79.99 per month billed annually ($99.99 billed monthly), with 4,000 pages a month and unlimited members, and every price is published.

  • Fax files and backups in Canada. Account owners and admins can store sent and received fax files in Toronto or Montreal, and choose the backup location separately, so live data and backups can sit in two different Canadian data centers.
  • Your choice, and you can change it. The region is set from the account settings. If your requirements change, stored faxes can be moved to another region from the same place, without switching providers.
  • An independent Swiss company. Fax.Plus is built by Alohi, a bootstrapped company founded in Geneva, with no US legal entity.
  • A signed PHIPA Service Provider Agreement. Enterprise includes PHIPA coverage with Advanced Security Controls and a signed PHIPA Service Provider Agreement, alongside HIPAA with a signed BAA for teams that also work with US partners.
  • Signatures under the same rules. Many faxed forms need a signature before they go back. Any fax can be forwarded to Sign.Plus, Alohi's own e-signature product, to sign it yourself or request signatures under the same account. Sign.Plus Enterprise offers the same Canadian data residency options and PHIPA coverage, so signed documents can be kept under the same terms as your faxes.
  • Retention you control. Admins can set how many days faxes are kept before they are permanently deleted, including zero days. Teams can also turn off fax storage and archive faxes in their own systems through the Fax.Plus API.
  • Access controls and an audit trail. Role-based access, two-factor authentication, single sign-on, and an audit trail of account activity.
  • Encryption and safer notifications. Fax files are encrypted at rest with 256-bit AES and protected in transit with TLS. With Advanced Security Controls, email notifications carry no fax attachment, and email to fax uses a dedicated TLS-enforced address.
  • Independently audited. Alohi holds ISO 27001 certification and a SOC 2 Type II report, both issued by EY CertifyPoint.

If your team handles health information in Ontario and needs it stored in Canada, talk to the Fax.Plus team about an Enterprise plan with Canadian data residency for Fax.Plus and Sign.Plus.

FAQs

What is the difference between data residency and data sovereignty?

Data residency is where your data is physically stored, such as a data center region in Toronto or Montreal. Data sovereignty is the wider question of whose rules and control the data falls under, which also depends on who operates the service and what they commit to in your agreement.

Does PHIPA require health information to stay in Canada?

No. PHIPA does not require personal health information to be stored in Canada. It requires health information custodians to take reasonable steps to protect it, including when an agent handles it on their behalf. Many Ontario organizations also require Canadian storage in their own policies and vendor contracts. For advice on your specific obligations, check the guidance from the Information and Privacy Commissioner of Ontario or your legal counsel.

Can I keep my fax data in Canada with Fax.Plus?

Yes. On Enterprise, you can store your sent and received fax files in Toronto or Montreal, and choose the location of backups separately. Admins set the region from the account settings and can move stored faxes later if requirements change.

Is Fax.Plus PHIPA compliant?

Fax.Plus supports PHIPA compliant faxing on the Enterprise plan, with Advanced Security Controls and a signed PHIPA Service Provider Agreement. See PHIPA compliant fax for details.

Can Fax.Plus avoid storing faxes at all?

Yes. Admins can set a retention period of zero days so faxes are permanently deleted after transmission, or turn off fax storage and archive faxes in their own systems through the Fax.Plus API.

Jump to section
H2 toc
Secure Online Fax Service
Fax.Plus