Rows of servers in a data centre, representing where Google Workspace stores a Canadian therapist's client email by default

Google Workspace data residency for therapists

Gabriel Borges17 min read

Updated

A question lands in Canadian therapist forums almost every week, in some version of this: “PHIPA says client data has to stay in Canada, right? So is my Gmail breaking the law because Google stores it in the States?”

It’s a fair worry. The premise is also wrong, on both counts.

PHIPA does not require your client email to be stored in Canada. There is no Canadian data residency rule in the statute. And the place Google Workspace keeps your email, which by default is the United States, is a matter of configuration and contract, not a law your Gmail is breaking.

That difference is the whole point of this piece. The panicked reading, that Gmail is illegal and you should migrate everything this weekend, leads to worse decisions than the accurate one. Here’s the honest version: where Workspace actually stores your client email, what PHIPA does and doesn’t say about location, and the moves that genuinely lower your risk. It belongs to the Google Workspace setup series, so if you want the full configuration walkthrough first, start with the Google Workspace PHIPA setup guide for Canadian therapists.

Key takeaways

  • PHIPA imposes no Canadian data residency requirement. The statute does not say client email must be stored in Canada, and no health privacy law in Ontario, Alberta, or BC requires Canadian email storage for a therapist in private practice.
  • PHIPA permits personal health information to be transferred and stored outside Canada. What it requires instead is reasonable safeguards under PHIPA s.12(1), and consent to the disclosure under s.50(1)(a), which s.18(3)(a) makes express where the recipient isn’t a health information custodian.
  • By default, Google Workspace stores covered data, including Gmail, in the United States. Its native Data regions control can move covered data at rest to the United States or Europe only. Canada is not a selectable option.
  • The Data regions control is not available on Business Starter, and it does not cover logs, cached content, or data in transit.
  • The real limitation is configuration and contract, not a residency law your Gmail violates. You lower risk through encryption that travels with the message and proper consent, not by chasing a Canadian server for Gmail.
  • Curio hosts its compliance infrastructure, including the audit trail and encrypted portal messages, on Canadian servers in Montreal. That Canadian hosting covers Curio’s own layer, not the email content Gmail routes through Google.

Does PHIPA require your client email to stay in Canada?

No. PHIPA imposes no Canadian data residency requirement. Nothing in the Personal Health Information Protection Act, 2004 obliges an Ontario health information custodian to store client email, or any personal health information, on servers physically located in Canada.

Data residency is the requirement that data be kept within a particular country’s borders. A data residency mandate in a health privacy law would force a custodian to hold personal health information on domestic servers. PHIPA contains no such mandate.

What PHIPA compliance asks of you is different, and honestly more demanding than a postal code. Under PHIPA s.12(1), a custodian must take reasonable steps to protect personal health information against theft, loss, and unauthorized use or disclosure. Where a server sits is one input into that judgment. It is not a rule that stands on its own.

The law also leaves room for handling information outside the country. A transfer of personal health information across the border, to a service provider that stores or processes it, is permitted, and the transfer on its own does not require a privacy impact assessment. Where the arrangement amounts to a disclosure of PHI outside Ontario, s.50(1)(a) requires the client’s consent, and s.18(3)(a) makes it express rather than implied where the recipient isn’t a health information custodian. PHIPA doesn’t require that consent in writing, but you should be able to show you asked. The posture is permission with conditions, not a ban.

So the accurate sentence is narrow: no Canadian residency requirement, real obligations around safeguards and consent. Hold onto that, because the rest of this piece follows from it.

Where the “it has to stay in Canada” idea comes from

The belief is common, and it has three honest sources.

The first is US spillover. Most compliance writing online is about HIPAA, and US vendors sell “data residency” hard. Read enough of it and Canadian residency starts to feel like settled law. It isn’t.

The second is a genuine mix-up between public sector and private sector rules. In BC, the public sector law FIPPA has long restricted where public bodies may store personal information, and Ontario has its own public sector regime. Therapists in private practice are not public bodies. A counsellor in Vancouver is governed by British Columbia’s Personal Information Protection Act (PIPA), whose s.34 requires reasonable security arrangements, not Canadian storage. FIPPA’s storage rule is not a PIPA rule, and importing it is one of the most common mistakes in this area.

The third is vendor marketing, including, to be fair, the way encrypted email products talk about Canadian hosting. When “Canadian data residency” is sold as the headline feature, it’s tempting to assume the law must require it. A feature can be worth having without the law mandating it. Those are two different claims, and this piece keeps them apart.

No Canadian health privacy law requires therapists in private practice to store client email in Canada. PHIPA in Ontario, PIPA in Alberta, and PIPA in British Columbia each require reasonable safeguards for personal health information. None imposes a data residency mandate.

Where does Google Workspace actually store your client email?

By default, in the United States. Google runs a global network of data centres, and unless an administrator sets a location policy, covered data for your Workspace account, including Gmail, lives in Google’s United States infrastructure.

Google does offer a location control. It’s called Data regions, and it pays to know exactly what it can and can’t do before you count on it.

Where does Google Workspace actually store your client email?
QuestionWhat Google Workspace offers
Default storage locationGoogle’s global infrastructure, commonly United States data centres, for covered data including Gmail
Native location controlThe Data regions setting, in the Admin console under Menu, Data, Compliance, Data regions
Selectable regionsNo preference, United States, or Europe. Canada is not an option.
What it coversCovered data at rest, including backups, for core services such as Gmail, Calendar, Drive, Docs, Chat, Meet, and Vault
What it does not coverLogs, cached content, data in transit, and data types Google does not list
Editions requiredBusiness Standard or higher. Business Starter does not include data regions.

A couple of those rows deserve more than a cell.

What the Data regions control reaches, and what it misses

Set a data region, and Google applies it to covered data at rest for the core services: Gmail, Calendar, Drive, Docs, Chat, Meet, Vault, and several others. According to Google’s documentation on data covered by data regions, the control does not extend to logs, cached content, or data in transit, and it can’t be applied to data types Google doesn’t list.

Read that twice if you’re relying on the feature. Even with a region set, some traces of your Workspace activity sit outside it. The setting narrows where the bulk of your data rests. It does not wrap your whole account in a single border.

Why Canada is not one of the options

Here’s the part that ends the residency fantasy cleanly.

Google Workspace’s Data regions control offers three values: No preference, the United States, or Europe. There is no Canadian data region. A Canadian therapist cannot pin Gmail content to Canadian servers through Google’s native setting, on any edition.

Per Google’s guidance on choosing a geographic location for your data, the choices are the United States or Europe, meaning the European Economic Area, or no preference. Canada isn’t on the menu. And on Business Starter, the entry tier many solo practices pick to save money, the Data regions feature isn’t available at all; you need Business Standard or higher.

So even a therapist who wants to keep Workspace email in Canada has no native way to do it. That isn’t Google flouting Canadian law. It’s the boundary of the product.

How to check where Google Workspace stores your client email

You can see your current setting in a few minutes. This walkthrough was checked against Google’s admin documentation in June 2026. Google moves menus around, so treat the labels as a guide and search the console if a path has shifted.

  1. Confirm your Workspace edition. Open the billing or subscriptions page in the Admin console. The Data regions control exists only on Business Standard, Business Plus, the Enterprise editions, and a handful of others. If you’re on Business Starter, the control isn’t there to set.
  2. Sign in to the Google Admin console. Go to admin.google.com with an administrator account, not your everyday Gmail login. Data location settings are admin-level, so a standard user account won’t show them.
  3. Open the Data regions setting. From the Admin console, open Menu, then Data, then Compliance, then Data regions. If the path has moved, type “data regions” into the console search bar.
  4. Read the current value. The policy reads No preference, United States, or Europe. There is no Canada option. No preference or United States both mean your covered data, including Gmail, sits in Google’s United States infrastructure.
  5. Check what the setting leaves out. A region applies to covered data at rest. Logs, cached content, and data in transit fall outside it. So even a region set to Europe doesn’t put every trace of your Workspace activity in one place.
  6. Decide your safeguards. Since Canada isn’t selectable and you can’t pin every data type to one country, location is the wrong lever to pull hardest. Encryption and consent are where your effort pays off, and the next two sections are about exactly that.

So is your Gmail breaking PHIPA by storing email in the United States?

No. Storing Google Workspace email on United States servers does not, by itself, breach PHIPA. PHIPA has no Canadian data residency requirement, so there is no residency rule for Gmail to break. The obligations that do apply are reasonable safeguards under PHIPA s.12(1) and, for a cross-border disclosure of personal health information, the client’s consent under s.50(1)(a), which s.18(3)(a) makes express where the recipient isn’t a custodian.

Sit with that, because it reframes the worry into something you can act on. The honest question was never “which country holds the server.” It’s two other questions: could the wrong person read this message, and did your client agree to how their information is handled?

Location feeds the first question a little and the second one barely. A US server holding strongly encrypted email protects a client better than a Canadian server holding plain-text email that anyone could read off a misdirected message. The address on the data centre is not the safeguard. The encryption and the consent are.

Whether a particular Gmail configuration actually meets your obligations is its own question, and we work through it in is Gmail PHIPA compliant for Canadian therapists. The Workspace data processing terms, the BAA, get pulled into residency arguments a lot, usually as if signing one parks your data in Canada. It doesn’t. For what that contract does and doesn’t do, see what the Google Workspace BAA covers and what it does not.

Two obligations carry most of the weight here.

Safeguards come from PHIPA s.12(1): reasonable steps to protect personal health information. For email, the safeguard that does the most work is encryption that travels with the message, so a note sent to the wrong “Sarah” is unreadable to the stranger who receives it. That one control changes the risk profile of the most common breach in a solo practice.

Consent is the second. Where your setup involves disclosing personal health information across the border, s.50(1)(a) requires the client’s consent and s.18(3)(a) makes it express rather than implied, which means telling them plainly how their information is handled and getting their agreement. If you see clients in more than one province, the consent rules and college expectations can differ, and the PHIPA vs HIA vs BC PIPA therapist guide maps those differences.

What can you do about it?

Three honest options, from most practical to most limited.

Option one: accept US storage and get the safeguards right

For most solo practices, this is the sound choice. Since PHIPA sets no residency rule, email stored on US servers is lawful as long as you meet the safeguard and consent obligations. Encrypt outbound email so a misdirected or intercepted message isn’t readable, document informed consent, and you’ve addressed what the law actually weighs. You haven’t ignored the residency question. You’ve answered it correctly.

Option two: set your data region to Europe, if your edition supports it

If you’re on Business Standard or higher and you want covered data at rest outside the US, you can set the region to Europe. Be clear about what that buys you. It doesn’t get you Canada. It doesn’t cover logs, cached content, or data in transit. And Europe is not inherently safer for an Ontario therapist than the US, because neither location is required in the first place. This is a narrow lever for specific reasons, not a compliance fix.

Option three: keep the records that can be Canadian in Canada

Your Gmail content routes through Google, on US servers by default, and you’ve seen that you can’t change that to Canada. Your compliance records are a different matter. The audit trail that proves a safeguard was in place doesn’t have to live in Google’s infrastructure. It can be Canadian hosted.

Where Curio fits

This is the gap Curio is built for, and it pays to be precise about what is and isn’t Canadian.

Curio encrypts every outbound email automatically and logs every send in a Canadian audit trail, working with your existing Gmail. Curio’s compliance infrastructure, including that audit trail and your encrypted portal messages, runs on Canadian servers in Montreal.

Now the honest boundary. The email content Gmail routes still lives in Google’s infrastructure, on US servers by default. Curio doesn’t move your Gmail to Canada, and won’t claim to. What’s Canadian hosted is Curio’s own layer: the audit trail a regulator would ask to see, and the encrypted messages your clients open through the portal. The encryption protects the Gmail-routed message when it lands on the wrong desk. The Canadian audit trail is the record that the safeguard was running.

If you want to see where your current Workspace setup leaves client email exposed, join the Curio waitlist.

What this guide doesn’t cover

A few honest limits.

This is informational content, not legal advice. The consent mechanics for cross-border handling get fact-specific fast, and a close call deserves a conversation with a privacy lawyer or a knowledgeable compliance professional. One consultation costs less than mishandling a disclosure.

It’s also centred on Ontario. The residency answer holds across the country, since no province requires Canadian email storage for private practice, but the consent rules and college expectations differ in Alberta and BC. If you practise across provincial lines, treat the cross-provincial guide as your starting point and get advice for your situation.

And it’s a snapshot. Google changes its settings, its edition line-up, and its coverage details on its own schedule. The data region paths and edition limits here were checked against Google’s admin documentation in June 2026. Before you make a decision based on a setting, open the console and confirm it still reads the way this describes.

Frequently asked questions

Does PHIPA require Canadian data residency?

No. PHIPA contains no data residency requirement. It does not say personal health information or client email must be stored in Canada. What it requires under s.12(1) is reasonable safeguards, and under s.50(1)(a) the individual’s consent to a disclosure outside Ontario, which s.18(3)(a) makes express rather than implied where the recipient isn’t a custodian.

Can you store Google Workspace data in Canada?

Not through Google’s native control. The Data regions setting offers only No preference, the United States, or Europe. Canada is not an option on any edition, so you cannot pin Gmail content to Canadian servers using Workspace settings alone.

Where does Google Workspace store Gmail by default?

In Google’s global infrastructure, commonly its United States data centres, for covered data including Gmail. Unless an administrator sets a data region, your Workspace email is stored in the US by default. Logs and cached content can sit elsewhere regardless of the setting.

Does storing client email in the United States break PHIPA?

Not by itself. Because PHIPA sets no residency rule, US storage is lawful when you meet the obligations that do apply: reasonable safeguards under s.12(1), such as encryption, and the client’s consent to any cross-border disclosure of personal health information under s.50(1)(a), express rather than implied where the recipient isn’t a custodian (s.18(3)(a)).

Should I switch from Gmail to a Canadian email provider?

Not for residency reasons alone. No law requires it, and changing email providers is disruptive. What matters is whether your email is encrypted and your consent is documented, and you can address both without leaving Gmail. Switch if another tool serves you better, not because you think PHIPA demands Canadian storage.

Is European storage more PHIPA compliant than US storage?

No. PHIPA does not rank the United States below Europe, because neither location is required. Setting your data region to Europe moves some covered data at rest off US servers, but it does not make your practice more compliant, and it still leaves out logs, cached content, and data in transit.

Does the Google Workspace BAA give you Canadian data residency?

No. The Workspace data processing terms are a contract about how Google handles your data, not a guarantee of where it sits. Signing it does not move your email to Canada. For what it does cover, see our guide on what the Google Workspace BAA covers.

What does Curio store in Canada?

Curio’s compliance infrastructure: the audit trail and your encrypted portal messages, hosted on Canadian servers in Montreal. The email content Gmail routes still lives in Google’s infrastructure, on US servers by default. Curio’s Canadian hosting covers its own layer, not Gmail.


This content is for informational purposes only and does not constitute legal advice. Privacy regulations vary by province and are subject to change. Verify current requirements with the Information and Privacy Commissioner of Ontario and consult a qualified privacy professional for your specific situation.

Curio is designed to encrypt outbound email and maintain a Canadian audit trail. It is not a substitute for professional legal or compliance advice.

Sources

Coming soon

Gmail encryption, built for Canadian therapists.

Join the waitlist →

Share this article

Related posts

Community

Join the community

Connect with Canadian therapists navigating Google Workspace compliance.

Join on Facebook