What “Canadian hosted” actually means when you’re buying an LMS
Most people who search for a Canadian-hosted LMS aren’t doing it out of preference. Someone handed them a requirement. It might be a line in a procurement template, a clause in a privacy impact assessment, or a policy written by a predecessor. Either way the question lands on your desk and you have to turn it into a vendor decision.
The frustrating part is that vendors answer it badly. Ask ten LMS providers whether they’re Canadian hosted and you’ll get ten yeses, because almost everyone can construct a version of that sentence that’s technically defensible. Sorting the real answers from the constructed ones is the actual work.
Start by finding out what your policy requires
A common assumption is that Canadian privacy law requires personal information to stay inside Canada. Federally, under PIPEDA, that’s generally not the case. Organizations can transfer personal information across borders, provided they use contractual or other means to give it a comparable level of protection while it’s being processed elsewhere. What the law asks for is accountability and transparency, not geography.
Provincial public-sector rules are a different story, and they vary. BC’s FIPPA has historically placed tighter conditions on public bodies storing personal information outside Canada, and other provinces have their own provisions. If you’re a public body, a regulator, or a broader-public-sector organization, your obligations may be considerably stricter than a private company’s, and they may have changed more recently than the internal policy you inherited.
This is worth confirming with your own privacy office before you write the requirement into an RFP. Some organizations discover their residency clause is stricter than the law demands and is quietly eliminating capable vendors. Others discover the opposite. Both are useful to know before you shortlist.
The three places data actually lives
Once you know what you need, “is it hosted in Canada” turns out to be three separate questions.
The first is where the production data sits. This is the one everyone answers. Ask for the city, not the country. A vendor who can name the facility is describing something real. A vendor who says “our Canadian region” is often describing a configuration option inside a global cloud platform, which may still be genuinely compliant, but it’s a different fact and you should record it as a different fact.
The second is where backups and disaster recovery sit. This gets missed constantly. Primary hosting in Canada with backups replicated to a US region is a common architecture, and depending on your requirements it can undo the whole arrangement.
The third is who can access the data, from where. Support staff, contractors, and subprocessors all touch systems in the course of normal operations. A platform hosted entirely in Canada and supported by a team elsewhere involves cross-border access even though no data was “stored” abroad. Ask for the list of subprocessors and where each operates. A vendor who has that list ready has thought about this before you asked.
The integration question nobody asks until it’s too late
An LMS is rarely alone. Proctoring, video hosting, analytics, AI features, content libraries, single sign-on — each of these may be a separate service with its own hosting arrangements.
This is where residency claims most often break. The LMS is Canadian hosted and the proctoring tool is American, or the AI assistant runs on infrastructure somewhere else entirely. Nobody misrepresented anything. The question just wasn’t asked at the right level of detail.
So ask it at that level. For every component you plan to use, where does it run, and who operates it. If a vendor’s answer is “coming soon” for one of them, that’s fine, but you want to know now rather than during implementation.
Where Udutu sits
We host in Richmond, British Columbia as our primary facility, with a second facility in Toronto, through Canadian Web Hosting. Both are in Canada, and we can name them because they’re ours to name.
Some specifics worth stating plainly, since they’re the kind of thing that surfaces in a privacy review anyway. Proctoring isn’t something we provide ourselves. It’s a third-party service and it’s US-based, so if invigilated assessment is part of your requirement, that’s a component to assess separately. Our AI assistant, AskU, can run on our own infrastructure, and a Canadian-hosted option is on the way but isn’t available yet.
We’d rather tell you that now than have it come up after you’ve built a business case around us.
What to ask us, and everyone else
Where is production data stored, by city. Where are backups replicated. Who can access the environment and from what country. Which subprocessors are involved and where do they operate. Which integrated components fall outside the main platform, and what are their arrangements.
Any vendor worth shortlisting will answer all five without hedging. If you’d like ours in writing for your procurement file, ask and we’ll send it.
