The US CLOUD Act Explained for Canadian Lawyers
If you use any American software to handle client files — ChatGPT, Google Workspace, Microsoft 365, Dropbox, DocuSign — there's a US law you should understand. It's called the CLOUD Act, and it has direct implications for solicitor-client privilege and your confidentiality obligations in Canada.
Here's the plain-English version.
What the CLOUD Act Is
The CLOUD Act — Clarifying Lawful Overseas Use of Data Act — was passed in the United States in 2018. It clarified and expanded the US government's power to compel American technology companies to hand over data.
The key provision: a US-based provider can be compelled by US legal process to produce data in its "possession, custody, or control" — regardless of where in the world that data is physically stored.
That last part is what matters for Canadian lawyers.
Why It Matters for Solicitor-Client Privilege
When your client's confidential information sits with a US-controlled provider, it can, in principle, be accessed through US legal process:
- Without your client's knowledge or consent
- Without a Canadian court's involvement
- Without the protections that solicitor-client privilege is supposed to guarantee
LSO Rules 3.3-1 and 3.1-2 are directly in play: Rule 3.3-1 requires you to hold client information in strict confidence, and Rule 3.1-2 requires you to understand and manage the risks of the technology you use. A tool that exposes client data to compelled disclosure by a foreign government sits in obvious tension with both.
You don't have to imagine a dramatic scenario. The point is structural: once confidential information is under the control of a company subject to US jurisdiction, you no longer fully control who can access it or under what law.
The "Data Centre in Canada" Myth
Here's the trap that catches a lot of well-meaning firms.
Many US providers now offer to store your data in a Canadian region — AWS Canada (Montreal), Azure Canada (Toronto), Google's Montréal region, and so on. It's natural to assume that Canadian data storage solves the problem.
It doesn't, on its own. The CLOUD Act reaches data based on the provider's control, not the data's location. If the company holding your data is subject to US jurisdiction, storing the bytes in a Montreal data centre does not put them beyond the reach of a US order.
In other words: data residency is not the same as data sovereignty. Where the data sits matters far less than who controls it and which laws they answer to.
What Actually Protects Client Data
To meaningfully protect confidential client information from foreign-government access, a provider needs to either:
- Not be subject to US jurisdiction, or
- Store and operate the data exclusively under Canadian law, with contractual and architectural protections — a Data Processing Agreement, no repurposing of your data, isolation of your files, and an audit trail of access
A DPA matters because it's your documented evidence, under Rule 3.1-2, that you took reasonable measures and understood where your client's data lives.
What to Do About It
A practical audit for your own practice:
- List the tools that touch client data — AI assistants, email, document storage, e-signature, practice management.
- For each, ask: is this provider subject to US jurisdiction? ChatGPT (OpenAI), Google, Microsoft consumer products, Dropbox, and DocuSign generally are.
- For the ones that are, decide whether to stop putting client-identifiable information through them, or move to a provider operated under Canadian law with a DPA available on request.
- Document your reasoning, so you can demonstrate compliance if you're ever asked.
None of this means abandoning technology — it means being deliberate about which tools hold your clients' confidential information.
The Bottom Line
The CLOUD Act means "stored in Canada" is not enough. What protects solicitor-client privilege is a provider that operates under Canadian law and can't be compelled to hand your clients' data to a foreign government.
Surface is built on that principle — client data on Canadian servers, a Data Processing Agreement available on request, no AI training on your files, and audit logs of every access. See how Surface approaches compliance.
Related posts
LSO Rules 3.1-2 and 3.3-1: What Ontario Lawyers Need to Know About AI
A plain-English breakdown of the two LSO rules that govern how Ontario lawyers can use AI tools for client work — and what happens if you get it wrong.
Read →Is ChatGPT Legal to Use for Client Documents in Ontario?
Ontario lawyers are using ChatGPT to summarize contracts and draft letters. But does this violate LSO confidentiality rules? Here's what you need to know.
Read →