The practical reality is that virtually any company of a size that can provide the kind of security we need over that data will have sufficient connections to the United States such that U.S. laws, such as the CLOUD Act, or U.S. courts using jurisdictional rules will apply. That's the trade-off. If a small Canadian company says it does not have any ties to the U.S. so it can avoid foreign laws, the problem is that it doesn't have the sophistication and capital investment to provide security over our data. Once they get big enough to be able to do that, they have those connections, and the missing piece is sufficiently strong Canadian privacy laws.
