Back to the blog

DATA SOVEREIGNTY

Your drawings hosted in Canada: what privacy law changes for your shop

In brief

The drawings your customers entrust to you and the quality history you build up over the years are sensitive assets — every bit as much as your machines. Two different protections apply, and you shouldn't confuse them. Privacy law — Quebec's Law 25 and, across the rest of Canada, the federal PIPEDA — governs the personal information your system holds: names of inspectors, of machinists, contact details of the people you deal with. Your drawings and designs, by contrast, are industrial intellectual property — protected by your non-disclosure agreements and by trade-secret practice, not by privacy law. Both live in the same place: in your shop's files. This isn't one more piece of red tape. It's a question of control and ownership.

Hosting your data in Canada means deciding where it sleeps and staying able to prove it. I'd add a conviction of my own: when software hands part of the work to AI, that AI should be processed in the same jurisdiction as everything else — not shipped elsewhere without anyone knowing. ISO 9001 clause 7.5, on documented information, asks for nothing less.


A dimensioned drawing is not a file like any other

When a customer sends you a drawing, they're entrusting you with far more than a PDF. They're handing over their geometry, their tolerances, sometimes their entire product know-how. In some sectors — hydro, medical, defence — that drawing sits under strict confidentiality clauses. Losing it, letting it leak, or simply being unable to say where it is can cost you the contract.

For a long time these documents were treated as paperwork: a network folder, a USB stick, an email inbox. As long as the file opened, nobody asked questions. But the real question was never "can I open it." It's "where has it ended up, and who else can open it."

I spent fourteen years in quality in the industry before I started building software. I've seen shops that were extraordinarily rigorous about the traceability of a part — every dimension measured, every instrument identified — and completely vague about the traceability of their own files. We knew everything about the journey of a piece of steel, and nothing about the journey of the drawing that defined it.

We knew everything about the journey of a piece of steel, and nothing about the journey of the drawing that defined it.

Privacy law, in shop language

Quebec's Law 25 — the province's modernization of its private-sector privacy rules — changed the game for every small and mid-sized business, not just banks and hospitals. Across the rest of the country, the federal PIPEDA plays the same role for the private sector. In substance, both ask you to know what personal information you hold, where it's hosted, who has access to it, and to be able to answer if someone asks.

One common misunderstanding I want to clear up right away: privacy law does not protect your drawings as such. A dimensioned drawing is not personal information; its confidentiality rests on your agreements with the customer and on trade-secret practice, not on privacy legislation. But your quality system is riddled with information that Law 25 and PIPEDA target directly: the name of the inspector who signed a report, the machinist who made the part, the contact details of your people at the customer's shop. The drawing and the identity of whoever handled it travel together, in the same files.

The practical consequence is simple, and it holds for both issues at once. The moment your inspection reports, your nonconformities and your instrument inventory leave the filing cabinet to live inside software, you have to be able to say where that software keeps your data. Not "somewhere in the cloud." The country. The region. It's a question an auditor, a customer or a prime can legitimately put to you — and "I don't know" is no longer an acceptable answer.

Sovereignty = control and ownership, not suspicion

Let's clear up a misunderstanding straight away. Choosing to host your data in Canada isn't about being suspicious of anyone. It's a decision about control and ownership, exactly like choosing which supplier you buy your steel from or which bank you trust with your account.

With a sensitive asset, you want to know where it is. You want to be able to tell a client: "your drawings are hosted in Canada, processed in Canada, and here's how I can demonstrate it." That's not an argument against anyone; it's an argument for you. It makes you master of your own chain, able to answer without hesitation, able to reassure a customer who is themselves becoming more demanding about their own requirements.

And it's an advantage that turns to your commercial benefit. More and more, a customer who has to prove their own compliance prefers a subcontractor who hosts their documents properly. Data sovereignty, presented plainly, becomes a point of credibility — not a defensive posture.

With a sensitive asset, you want to know where it is. The rest is control, not suspicion.

The region: an irreversible choice you never see

Here's the part few people realize, and I'll be honest because I learned it the hard way. When you set up the infrastructure for a piece of cloud software, you choose a hosting region. On most platforms that choice is made by default — and the default is almost never Canada. Worse: once the database is created, the region is often irreversible.

On one of our earliest building blocks, that default trapped us. The database had been created in a region outside Canada without our noticing. Fixing it meant recreating a second database in the right place and migrating the existing data — two days of work and real production risk, to repair an invisible click made weeks earlier.

The lesson holds for any owner evaluating software: the question "where is my data hosted" isn't one you ask once the contract is signed and the files are already inside. You ask it before. Because afterward, moving data from one region to another isn't ticking a box — it's a project. Software that made this choice for you, from the design stage, hosted in Canada by principle rather than by option, spares you a problem you'd never see coming.

The AI has to be processed here too

This is where a nuance many people forget comes into play. Modern inspection or quality software no longer just stores your data: it hands part of it to AI. In our case, the AI reads the dimensions on a drawing so you don't have to retype everything. Elsewhere it classifies, summarizes, suggests. In every case, a fragment of your sensitive data goes off to be processed somewhere.

And "somewhere," by default, is not Canada. Most consumer AI services process data wherever the provider installed its servers — often a very long way from you. You can have carefully hosted your database in Canada, and let it leak out the back door every time the AI comes into play. Sovereignty on one side, a sieve on the other.

The position I stand by is clear: if the data lives in Canada, the AI that processes it must be processed in Canada too. It's doable — AI processing can be carried out in a Canadian region, in the same jurisdiction as everything else. It isn't the simplest path for a software designer; it's often the most constraining. But it's the only one consistent with the promise made to the client.

Let's be honest about the cost of that consistency. Genuinely high-performing AI engines hosted one hundred percent in Canada remain rarer, and sometimes more expensive, than the ones you find by default elsewhere. It's a real technical challenge, not a footnote: the easy path always pushes you offshore. That's precisely what makes the choice meaningful. When you decide to process the AI here despite the constraint, it isn't a free slogan — it's a deliberate trade-off, paid for in engineering effort, for the client's benefit.

Don't send everything: the principle of minimization

There's a second reflex, just as important as the hosting region: give the AI only the strict minimum. The best way to protect a piece of data is still not to send it.

In concrete terms, well-designed software doesn't throw a client's entire drawing at an AI engine. It isolates what it actually needs — a group of dimensions, a zone of the drawing — without the client's name, without the part number, without the CAD file's metadata. The AI sees numbers and tolerances to read, not the identity of the customer or the nature of the product. It does its work on an anonymous fragment, and you keep the context on your side.

This principle has a name in data protection: minimization. You collect, transmit and keep only what's necessary. Serious trade-specific software applies it by design, not as an option you switch on. It's the difference between a tool that thought about your confidentiality before you did, and a tool that leaves you to discover the problem yourself.

What clause 7.5 already asks of you

If your shop is ISO 9001 certified — or aiming to be — you may know clause 7.5 on documented information. It's often read as a paperwork requirement: keep your procedures, your records, hold them up to date. But it says more than that.

Clause 7.5 requires that documented information be controlled: available where and when it's needed, protected from loss of confidentiality and from alteration, and retained under clear rules of duration and access. Put plainly, the quality standard already asks you to know where your reports live, who can change them, and for how long you keep them.

In other words, privacy law and ISO 9001 pull in the same direction. One for reasons of protecting personal information, the other for reasons of documentary control. Software that hosts your data properly in Canada, that traces who did what, and that prevents the silent alteration of a record, answers both in a single move. You aren't ticking two separate boxes: you're adopting one good practice that satisfies both worlds.

The questionWhat good trade-specific software answers
Where is my data hosted?In a Canadian region, chosen by design — not by default, not changeable by accident.
Where does the AI process my drawings?In the same jurisdiction as everything else; never shipped elsewhere without my knowledge.
Is the whole drawing sent to the AI?No: only an anonymized zone, without client name or part number.
Can I prove it to an auditor or a customer?Yes: documented hosting, access traceability, clear retention rules (clause 7.5).

In conclusion: whose data is it, really?

Ask yourself the question plainly. If one of your best customers called tomorrow to ask where their drawings are hosted and how they're processed, would you know how to answer without hesitating? Could you prove it? And the AI that saves you time on your reports — do you even know which country it reads your drawings in?

Data sovereignty isn't a slogan, and above all it isn't a fear. It's a quiet discipline: deciding where your sensitive assets live, sharing only what's necessary, and staying able to demonstrate it. For the personal information in your system, Law 25 and PIPEDA require it of you. For the drawings themselves, it's your non-disclosure agreements that demand it. And ISO 9001, through clause 7.5, was already asking you to control all of it in one move. The rest — choosing a tool that made these decisions for you, from the design stage — is simply industrial common sense.

One open question remains, and I don't have a ready-made answer: as AI works its way into every corner of our trade-specific software, how many shops will discover too late that they'd carefully locked the front door while leaving the back one wide open?

The principles described in this article are the ones that guided the development of Asterion Solutions, a suite of trade-specific software built for small and mid-sized manufacturers who want to structure their quality without piling on administrative work.

Free resource

Checklist: passing your ISO 9001 audit as an SME

Clause by clause, what an auditor will actually ask — plus the 3 questions they almost always ask.