Compliance by design. Verifiable. Auditable.
tonia is the gated, audited, redacting router for every AI request.
Sensitive data stays in Canada.
tonia applies your rules before anything is sent to a model provider.
How tonia meets each obligation.
Canada's Bill 25 (formerly Bill 64) modernised the private-sector Act respecting the protection of personal information. The obligations applicable to tonia are:
| Obligation | Article | tonia posture |
|---|---|---|
| Privacy Officer designated | art. 3.1 | Yes — contact published in the privacy policy |
| Incident register | art. 3.8 | Maintained since incorporation, CAI-ready format |
| PIA before any cross-border transfer | art. 17 | PIA template provided; sensitive categories blocked before any cross-border send |
| Granular consent | art. 12 | Granular in the portal and in the cookie banner |
| Right to data portability | art. 27 | Structured JSON / CSV export from the portal |
| Automated right to be forgotten | art. 28.1 | Automatic cessation of processing once the stated purpose expires |
Sanctions
For an organisation that contravenes Bill 25:
- Penal sanctions (art. 90.12): up to 25 M CAD or 4 % of worldwide turnover, whichever is greater.
- Administrative sanctions (art. 90.1): from 10 M CAD or 2 % of worldwide turnover.
- Civil sanctions: statutory damages of at least 1,000 CAD per affected person, without proof of harm (art. 93.1).
Why Canadian residency isn't enough.
The US Clarifying Lawful Overseas Use of Data Act (2018) — the CLOUD Act — compels any company subject to US law to produce data — regardless of where that data is physically stored.
"Azure OpenAI Canada Central" — the illusion
Microsoft servers in Toronto store your data in Canada. Microsoft Corp. (Washington) remains subject to the CLOUD Act. A US subpoena served on Microsoft Corp. compels disclosure of the data — including the bytes physically in Toronto. If the subpoena carries a gag order, Microsoft cannot even tell you.
Vendors subject to the CLOUD Act:
- OpenAI (Delaware)
- Anthropic (Delaware)
- Google / Gemini (Delaware)
- Microsoft / Azure / Copilot (Washington) — including the Canada Central region
- AWS / Bedrock (Delaware)
US compliance — HIPAA, GLBA, and state law, applied
The United States has no single federal personal-information law. Three separate regimes apply depending on your sector : HIPAA for health, GLBA for finance, and state laws for the rest. Here is what each requires, and exactly how tonia answers it.
HIPAA — health data
| Obligation | Citation | tonia's answer |
|---|---|---|
| A signed BAA before any access to protected health information (PHI) | HIPAA Security Rule, 45 CFR § 164.308(a)(8) | Direct contract with each provider — never a reseller — that documents exactly who receives what |
| The provider must not train a model on PHI | same rule | "No training" contract clause by default, on every provider |
| Breach notification within a defined timeframe | Federal breach rule | Signed audit log that identifies an incident's exact scope in minutes, not weeks |
GLBA — financial data
The Gramm-Leach-Bliley Act's Safeguards Rule protects a financial institution's customers' nonpublic personal information (NPI).
| Obligation | Citation | tonia's answer |
|---|---|---|
| Vendor security assessment before onboarding | GLBA Safeguards Rule, 16 CFR Part 314 | Direct contract, never an intermediary — the same diligence chain built for Bill 25 |
| Contract limiting use to the service performed, no secondary use | same rule | "No training" clause by default |
| Ongoing monitoring, audit rights, deletion certification at termination | same rule | Signed audit log, exportable at any time |
State privacy laws — 20 states and counting
Twenty US states now have a comprehensive consumer privacy law. Most require explicit consent before processing a sensitive-data category (ethnicity, health, orientation, precise geolocation, biometric data). That is the same logic as Bill 25 : a defined sensitive-category list, a consent gate, and liability for a vendor that processes those categories without authorization.
tonia's answer: policy and detection block a sensitive category from leaving your business by default, before it's sent — no extra configuration. It's the same architecture that already answers Bill 25 art. 17; it didn't need adapting for the 20 state laws.
European GDPR — for Canadian businesses exporting to Europe
GDPR (EU 2016/679) applies to any organization outside the EU that processes personal information of people located in the EU. That includes Quebec businesses with European clients, employees, or partners. The obligations most relevant to an AI deployment : lawful basis for processing (art. 6), extended rights (access, rectification, erasure “right to be forgotten” art. 17, portability, objection, automated decision-making art. 22), a DPO where required (art. 37), 72-hour breach notification (art. 33), and restricted transfers outside the EU (chapter V).
Where tonia excels at GDPR compliance
- Article 17 (right to erasure) in trained models. Most AI vendors cannot remove a fact from an already-trained model. tonia can, through a cascading revocation that strips the record from the audit log, the replay buffer, and the next adapter.
- Article 22 (automated decision-making): no tonia decision is treated as an automated decision with legal effect. Every response is presented to a human who decides.
- Article 25 (data protection by design): on-site tonia is privacy-by-design by architecture.
- Article 32 (security of processing): envelope encryption, cryptographic audit, signature-based access control.
- Chapter V (transfers outside the EU): with no cloud routing, there is no transfer outside the EU. When enabled, routing to a frontier model provider is governed by contract and deterministic redaction.
The 2026 backdrop: the transatlantic framework is fragile
The EU-U.S. Data Privacy Framework (DPF) is the transfer mechanism most US providers rely on. It is being challenged in court since a US Supreme Court decision weakened the independence of its enforcement body. The DPF remains legally in force today, but no serious law firm treats it as its only transfer mechanism. The European Commission has separately proposed a “Level 2” tier for sensitive data (health, finance). That tier requires independence from any third-country jurisdiction, regardless of where the bytes are stored. That is, almost word for word, the architecture tonia already has: a direct contract with each provider, never a reseller, plus an on-prem capability for categories that can never leave.
What tonia doesn't do (as of today)
- tonia is not certified under the EU-U.S. Data Privacy Framework. It doesn't need to be, because it doesn't process European data — on-site tonia processes it at your premises.
- tonia routes to a frontier model provider whose Data Privacy Framework posture is publicly documented by that provider; we track that posture.
- tonia has no EU legal entity and no GDPR Art. 27 representative. Any compliance claim for a European subsidiary must be validated by a European lawyer before becoming a customer promise — the same discipline as for the United States.
The EU AI Act adds obligations specific to risk-tiered AI systems for AI providers. Our ISO 42001 effort (Certifications section below) directly answers this part of European AI compliance.
SOC 2 and ISO 42001.
Status as of 2026:
- SOC 2 Type I: in progress, report target Q4 2026.
- SOC 2 Type II: 6-month observation starts once Type I is obtained (Security, Availability, Confidentiality).
- ISO 42001: in progress, audit scheduled Q4 2026.
- Bill 25 compliance: by design (see section 1).