Foreign Processing Disclosure
Tell people where their data goes, the way Canadian privacy law expects.
When a client asks “where is our information actually processed?”, most organisations cannot answer clearly, and Canadian privacy law expects them to. Lavawall® writes a plain-language Foreign Processing Disclosure for you, built from the vendors and data flows already captured in your Business Impact Assessment, complete with the outside-Canada notice Alberta PIPA and Quebec Law 25 lead you to give.
It uses data you already have, and it is written in plain language your clients, staff, and their lawyers can read. No blank page, no legal drafting from scratch.
Start with the GRC Wizard See the full GRC platform
Auto-filled from your BIA · outside-Canada notice · plain language · uncommon on US-focused platforms
The disclosure most Canadian organisations are missing
Your data is almost certainly processed somewhere you have not written down, a hosting region in another country, a support desk in another time zone, an AI feature that sends text to a model abroad. Canadian privacy law expects you to be open about that. Most compliance platforms are built around US frameworks and never produce this notice. Lavawall does.
Two themes run through the whole disclosure
First, it uses data you already have. Lavawall reads the vendors and data flows in your Business Impact Assessment and fills in who processes what, and where, so you are confirming reality instead of guessing. Second, it is written in plain language, so the people whose information you hold can actually understand where it goes and who touches it.
Auto-filled from your BIA vendors and data flows
Every vendor you captured in the Business Impact Assessment, and every data flow between your systems, becomes a line in the disclosure: what personal information is involved, which service handles it, and in which country it is processed. You review and adjust rather than type it out.
A proper outside-Canada notice
Where a service provider outside Canada may handle personal information, Lavawall drafts the notice in the style Alberta PIPA expects: what will be handled outside the country, how an individual can ask about your policies and practices for using service providers outside Canada, and who to contact with questions.
Plain language, not legalese
The disclosure reads like something a client can follow, not a contract clause. That is deliberate. Openness only works if the people it is written for can understand it.
Why the outside-Canada notice is the differentiator
Canadian privacy law treats sending personal information out of the province or country as something people deserve to know about. Here is what the main regimes expect, and why a US-centric platform rarely covers it.
Alberta PIPA
When an organisation uses a service provider outside Canada to collect, use, or disclose personal information, PIPA expects it to notify individuals: what will be handled outside Canada, how to access information about its policies and practices for service providers outside Canada, and the name or position of someone who can answer questions. Lavawall drafts that notice for you.
Quebec Law 25
Before personal information is communicated outside Quebec, Law 25 expects the organisation to assess the privacy implications of the transfer, including whether the information would receive adequate protection. Your BIA data flows give Lavawall the raw material to help you document that assessment.
PIPEDA accountability
Under PIPEDA, when you transfer personal information to a third party for processing, your organisation stays accountable for it and is expected to be open about the practice. The disclosure makes that transparency concrete.
Most compliance platforms are US-focused and do not generate a Canadian outside-Canada disclosure at all. This one does, from the records you already keep. The notices above are drafted to be accurate and measured, not absolute promises of compliance, so your legal counsel can review and finalise them.
What it costs you to not have one
A question you cannot answer in a deal
Enterprise buyers and public-sector clients ask where their data is processed. “We are not sure” stalls the sale. A clear disclosure answers it on your terms and keeps the deal moving.
A gap a regulator or client can point to
If someone complains that they were never told their information is handled abroad, an organisation with no disclosure has nothing to show. One generated from your real vendors demonstrates that you took the obligation seriously.
A blind spot that grows with every new tool
Every SaaS app and AI feature you adopt can quietly move data across a border. Because the disclosure is built from your BIA, it grows with your vendor list instead of going stale in a drawer.
What the generated disclosure includes
Who processes your data
Each vendor and subprocessor from your BIA, described in plain language rather than by brand name in public copy.
What information is involved
The categories of personal information tied to each data flow, so people know what is actually at stake.
Where it is processed
The country or region each service handles data in, with anything outside Canada clearly flagged.
The outside-Canada notice
The Alberta-style notice and a contact point for questions, plus room to record your Law 25 transfer assessment.
Before you rely on it
This disclosure is a starting draft generated from your records. It is designed to save you the blank page and to reflect what Canadian privacy law expects, but it is not legal advice. Have your legal counsel or privacy advisor review and finalise it before you rely on it or publish it to clients.
Part of the wider GRC platform
Business Impact Assessment
The vendors and data flows that fill your disclosure, captured once in plain language.
Learn more →Data Flow Documentation
The internal register of data flows and subprocessors behind every public disclosure.
Learn more →Privacy Policy addendum
The public addendum that ties subprocessors, international processing, and AI use together.
Learn more →Common questions
- What is a Foreign Processing Disclosure?
- A plain-language statement that tells your clients and staff where their personal information is processed and by whom, including handling outside their province or outside Canada. Lavawall builds yours automatically from the vendors and data flows in your Business Impact Assessment, then adds an outside-Canada notice in the style Canadian privacy law expects.
- Why does the outside-Canada notice matter in Canada?
- Canadian privacy law expects organisations to be open about handling personal information outside the individual's province or country. Alberta's PIPA expects you to notify individuals when a service provider outside Canada may handle their personal information, including how to reach someone about your policies. Quebec's Law 25 expects a privacy assessment before information is communicated outside Quebec. PIPEDA keeps you accountable for information transferred to a third party for processing.
- Do I have to fill it in from scratch?
- No. It is auto-filled from data you already have. Lavawall reads the vendors and data flows in your Business Impact Assessment and drafts the who, what, and where for you, so you confirm rather than start from a blank page.
- Is this common on other compliance platforms?
- It is uncommon among US-focused platforms, which centre on US frameworks and do not generate a Canadian outside-Canada disclosure. Lavawall generates it from records you already hold. Treat it as a starting draft and have your legal counsel or privacy advisor review it before you publish it.