Skip to content
Back to perspectives

Perspective

Reconciling cloud computing with Québec law

At present, Québec case law remains silent on the interpretation of the statutes applicable to cloud computing, and there is little written on the subject. Although the questions are many, we will try to set out here the main provisions applicable to the private sector, after raising certain risks arising from the outsourcing of data abroad.

What is cloud computing?

The Office québécois de la langue française defines cloud computing as a “[c]omputing model which, by means of remote servers interconnected over the Internet, provides on-demand network access to a shared pool of configurable, outsourced and non-localizable computing resources, offered in the form of scalable, dynamically adaptable services billed on usage”[1]. Cloud computing thus rests on “the exploitation of the Internet and of the notions of virtualization to create an environment in which people and organizations can acquire storage and processing capacity”[2]. Put another way, cloud computing is a concept of “offloading onto remote servers the computing operations traditionally carried out on local servers[3]”.

The main cloud deployment models include the public, private (internal or external), community and hybrid service. Among the service models currently in use are software as a service (SaaS), platform as a service (PaaS) and infrastructure as a service (IaaS). As cloud computing is a notion in constant evolution, new types of model are emerging[4].

The U.S.A. Patriot Act and other problems

Unless the location of data stored in the cloud is expressly provided for by contract, the very nature of these services most often means that the information is transferred to and kept in a foreign jurisdiction[5]. The information may then be subject to the laws of the country where it is kept, with no certainty that the foreign legislation offers an adequate regime for protecting personal and confidential information.

By way of example, the surveillance procedures expanded by the USA Patriot Act[6] in the United States would allow the American government to access our data stored in a cloud system belonging to an American company, or to one doing business on American territory. Section 215 of the USA Patriot Act allows the Federal Bureau of Investigation (“FBI”) to gain access to records held in the United States or by an American company, “by requesting an order from the Foreign Intelligence Surveillance Act Court of review”[7].

American “extraterritorial jurisdiction”[8] therefore means that all cloud service providers operating anywhere in the world must comply with requests for data falling within the application of American law. The data need not, then, be stored on servers physically present on American territory for the government to be able to access it.

Note that Canadian organizations may be subject to orders equivalent to those of the USA Patriot Act, obliging them to disclose to the federal government personal information held in Canada[9]. Canada’s Anti-terrorism Act, S.C. 2001, c. 41 likewise contains certain provisions that “strengthen the investigative powers of public authorities with a view to ensuring national and, correspondingly, international security”[10].

Among the other risks, it is entirely possible that cloud users are not informed of the existence of “secondary data generated by interactions with a cloud computing infrastructure”[11]. Note too that there are several risks associated with unwanted interactions between a provider’s various customers[12]. Furthermore, the uncertainty over where data is located makes cloud computing particularly exposed to jurisdictional problems[13], for instance as regards potential disputes.

The normative framework applicable to cloud computing in the private sector

The Act respecting the protection of personal information in the private sector (“Private Sector Act”) provides that “no person may communicate to a third person the personal information contained in a file he holds on another person, or use it for purposes not relevant to the object of the file, unless the person concerned consents thereto or this Act provides for such communication or use”[14].

Consistently with section 13, section 17 of the Private Sector Act provides that, before transferring information outside Québec, a person carrying on an enterprise must first take all reasonable steps to ensure that the information will not be used for purposes not relevant to the object of the file, nor communicated to third persons without the consent of the persons concerned (except in cases similar to those provided for in sections 18 and 23 of the Act).

If the person carrying on an enterprise considers that the information referred to in the first paragraph will not benefit from the conditions set out in section 17, they must “refuse to communicate the information or refuse to entrust a person or a body outside Québec with the task of holding, using or communicating it on his behalf”.

It should be made clear that any employee, agent or representative of the operator, or any party to a service or enterprise contract, may have access to the personal information held by the business without the consent of the individual concerned only on the condition that the information is necessary for the performance of their duties or the carrying out of their mandate or contract[15]. A business that entrusts personal information to a third party in the performance of a contract may therefore do so without the consent of the individual to whom the information belongs, if this remains relevant to the purpose for which the personal information was collected.

It should be noted, however, that a business which communicates the information it holds to a service provider, whether for hosting, analysis or processing, remains responsible for ensuring its security, even where the information is in another country[16]. The Private Sector Act provides that **“**a person carrying on an enterprise must take the security measures necessary to ensure the protection of the personal information collected, used, released, kept or destroyed and that are reasonable given the sensitivity of the information, the purposes for which it is to be used, the quantity and distribution of the information and the medium on which it is stored”.

The Act to establish a legal framework for information technology[17] (“LCCJTI”) also imposes on anyone who entrusts a technology-based document to a service provider for safekeeping the obligation to inform that provider of the protection the document requires as regards the confidentiality of the information, and as to which persons are authorized to have access to it. (…)[18]. It also obliges the service provider who has custody of the documents to see that the agreed technological means are put in place to secure them, preserve their integrity, protect their confidentiality and bar access to them by anyone not authorized to have access. An organization, whether public or private[19], should therefore provide by contract for the security measures required by the information it entrusts to a third party in the cloud.

Furthermore, a person who collects personal information must inform the individual concerned of the object of the file, of the use that will be made of the information, of their rights of access and of the place where their file will be held[20]. The law is not clear, however, as to whether the place is to be interpreted as a physical location, a region or a country, since no court has interpreted these provisions to date[21]. It is also very difficult to know exactly where information kept in the cloud is located, unless that has been provided for by contract beforehand. Under section 8 of the Private Sector Act, a business should therefore be sufficiently informed and know the location of the personal information it has hosted in the cloud, so as to be able to tell the individuals concerned where it is held, what their rights of access are and what security measures are in place.

Best practice

Before turning to services in the cloud, it is therefore necessary to remain cautious and to provide by contract for every arrangement relating to the handling of personal and confidential information, such as the location of the data. Note, however, that it is much harder, if not impossible, to stipulate the terms of a cloud service in the case of the public model. In many cases, the use of the public cloud will be governed by a free contract of adhesion whose terms are set in advance and non-negotiable.

Moreover, and in order to protect the confidentiality of the information, we take the view that using a cloud service operated by a Canadian provider hosting the information in Canada is much less risky than doing so abroad. Where a body must nonetheless use the services of a provider for which it is impossible to know precisely where the data is kept, it will need security measures protecting the sensitive data[22], such as encryption technologies[23]. Recall that where data is not localized, the jurisdiction competent to hear an eventual dispute will also be difficult to determine, if that aspect has not been provided for by contract beforehand.

*This does not constitute legal advice*


[1] OFFICE QUÉBÉCOIS DE LA LANGUE FRANÇAISE, Grand dictionnaire terminologique, online: <https://gdt.oqlf.gouv.qc.ca/ficheOqlf.aspx?Id_Fiche=26501384>. Notes: “In the computing world, the cloud is the image generally used to represent the Internet graphically. Cloud computing is in fact computing seen as a service and outsourced by way of the Internet. It refers to the use of the memory and computing capacity of computers and servers distributed around the world and linked by the Internet. The computing resources pooled and so made available remotely may be, among other things, software, storage space and servers”.

[2] CANADIAN INSTITUTE OF CHARTERED ACCOUNTANTS, « Infonuagique : Les grandes tendances technologiques », 2012, p. 2.

[3] Patrick JOSET, « Cloud Computing, tentative de définition », Abissa Informatique, online: <https://www.abissa.ch/data/fichiers/tec_cloud_computing.pdf>.

[4] “Network as a service”, “Business Process as a service” and “Desktop as a service” are services offered to businesses. Note that other options are also currently possible, such as “Storage as a service”, “Workplace as a service” and “Data as a Service”. Although they may have their own particular features, the way they work overlaps with the three main models explained above.

[5] OPC, “Reaching for the Cloud(s): Privacy Issues related to Cloud Computing”, March 2010, online: <https://www.priv.gc.ca/information/research-recherche/2010/cc_201003_e.asp>.

[6] Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act of 2001, « USA Patriot Act ». As a report from the University of Amsterdam notes, « the U.S. government has ample possibilities to request data from foreign (in this case Dutch) users of the cloud. The most striking example in this regard is the specific provision (50 USC § 1881a) introduced in 2008 for the acquisition of data of non-U.S. persons outside the United States, given the far-reaching powers it grants to retrieve information on a large scale, including access to complete data sets. U.S. authorities also have powers to request information from cloud providers in the context of criminal investigations. Jurisdiction under U.S. law is a necessary precondition, which is effectuated when cloud providers are based in the United States or if they conduct continuous and systematic business in the United States. It is a misconception that U.S. jurisdiction applies only if the data are physically located on U.S. territory ». See Joris Van HOBOKEN, Axel ANRBAK and Nico Van EIJK, « Cloud Computing in Higher Education and Research Institutions and the USA Patriot Act », Institute for Information Law, University of Amsterdam, 27 November 2012.

[7] OPC, “Bank’s notification to customers triggers PATRIOT Act concerns”, PIPEDA Case Summary #2005-313. Note that an organization subject to such an order may not reveal that it has provided information to the FBI. See Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act of 2001.

[8]Id.

[9] OPC, “Bank’s notification to customers triggers PATRIOT Act concerns”, PIPEDA Case Summary #2005-313.

[10] Cynthia CHASSIGNEUX, « Quand la sécurité nationale interpelle la protection des renseignements personnels : l’exemple de la USA PatriotAct », in Service de la formation continue du Barreau du Québec,Vie privée et protection des renseignements personnels (2006), Cowansville, Yvon Blais, 2006.

[11] Id.

[12] See S. SUBASHINI and V. KAVITHA, « A survey on security issues in service delivery models of cloud computing », Journal of Network and Computer Applications, 34 (2011) 1–11, Anna University, Tirunelveli, 2010, India.

[13] Id.

[14] S. 13, Private Sector Act.

[15] S. 20, Private Sector Act.

[16] See OPC, “Introduction to Cloud Computing”, online: https://www.priv.gc.ca/resource/fs-fi/02\_05\_d\_51\_cc\_e.pdf

[17] LCCJTI, R.S.Q., c. C-1.1

[18] S. 26, LCCJTI.

[19] The LCCJTI applies to Québec public and private entities alike.

[20] S. 8, Private Sector Act. Note that, in the federal sector, individuals must also be informed of the place where their information is kept and that it may be subject to a foreign jurisdiction, under the Personal Information Protection and Electronic Documents Act. See Outsourcing of canada.com e-mail services to U.S.-based firm raises questions for subscribers (19 Sept. 2008), PIPEDA Case Summary #2008-394; Canadian-based company shares customer personal information with U.S. parent (19 July 2006), PIPEDA Case Summary #2006-333; and Bank’s notification to customers triggers PATRIOT Act concerns (19 October 2005), PIPEDA Case Summary # 2005-313.

[21] See Éloïse GRATTON, « Dealing with Canadian and Quebec Legal Requirements in the Context of Trans-border Transfers of Personal Information and Cloud Computing Services », Développements récents, Volume 358, 2012.

[22] Sensitive information includes, among other things, tax, banking, medical and personal data.

[23] A body should use an encryption service separate from the one offered by the cloud service provider it has retained, failing which certain risks could persist, in particular if the provider allows a third party to take a copy of the information before encrypting the data. See: Iain THOMSON, « Snowden leak: Microsoft added Outlook.com backdoor for Feds », (2013) The Register: <https://www.theregister.co.uk/2013/07/11/snowden_leak_shows_microsoft_added_outlookencryption_backdoor_for_feds/>.

Send us a message

Only your email is required. Pick a subject, add a note, and send.

Incident in progress? Call the 24/7 line instead of waiting for a reply: +1 450 681-1681, extension 277