Share via

MS Forms Data Residency

Anonymous
2024-10-18T17:13:04+00:00

Hi,

I am trying to understand how to address the issue of MS Forms data residency in the US. Our company is based in Canada, and we plan to use MS Forms to collect personal health information from our service users. However, we are concerned that storing MS Forms data in the US may not comply with Canada’s Personal Health Information and Privacy Act (PHIPA).

Are there any workarounds to ensure that the data is stored on Canadian servers?

For example, if we use MS 365 to export the completed forms to Excel, CSV, or a SharePoint environment and then delete the form and associated responses, will this resolve the data residency issue? Will the data be stored on Canadian servers since Excel is hosted on Canadian servers?

Microsoft 365 and Office | Microsoft Forms | Other

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

2 answers

Sort by: Most helpful
  1. Anonymous
    2024-10-23T22:40:52+00:00

    Hello Justice,

    Addressing the data residency concerns for MS Forms in Canada involves understanding both the data storage policies of Microsoft and the compliance requirements of Canadian privacy laws. According to the information available, Microsoft 365 services, including MS Forms, offer data residency in Canada for customer data. This means that data generated by Canadian users can be stored in Canadian data centers. However, it's important to verify the specific data residency options for MS Forms as they may vary from other Microsoft 365 services.

    Regarding compliance with Canada's PHIPA, while the act does not explicitly require personal health information to be stored within Canada, it mandates stringent protections and controls over personal health data. Exporting MS Forms data to Excel, CSV, or SharePoint and then deleting the original form and responses could be a potential workaround, provided that these services are configured to store data in Canadian servers. It's crucial to ensure that any exported data remains within the scope of Canadian data protection laws and that proper consent, security measures, and contractual agreements are in place when handling personal health information.

    In summary, while there are potential workarounds to address data residency concerns, they require careful planning and verification to ensure compliance with Canadian privacy laws. It is advisable to consult with legal experts familiar with PHIPA and data privacy regulations to develop a comprehensive strategy that aligns with legal requirements and organizational needs. Additionally, staying updated with Microsoft's data residency policies and any changes in privacy legislation is essential for maintaining compliance over time.

    Hope this helps,

    Fathia A

    Hello

    According to this website, Data Residency for Other Microsoft 365 Services - Microsoft 365 Enterprise | Microsoft Learn the data residency of MS Forms "Tenants in EU member Countries/regions maintain data in Macro Region Geography 1 – EMEA. All other tenants have customer data stored in the United States, except Australia. For customers in Australia, Microsoft Forms customer data is stored at rest in Australia for all new tenants using Forms and existing tenants that haven't previously used Forms." and it doesn't state Canada. How can we check where our data residency is for Forms?

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2024-10-19T08:54:41+00:00

    Hello Justice,

    Addressing the data residency concerns for MS Forms in Canada involves understanding both the data storage policies of Microsoft and the compliance requirements of Canadian privacy laws. According to the information available, Microsoft 365 services, including MS Forms, offer data residency in Canada for customer data. This means that data generated by Canadian users can be stored in Canadian data centers. However, it's important to verify the specific data residency options for MS Forms as they may vary from other Microsoft 365 services.

    Regarding compliance with Canada's PHIPA, while the act does not explicitly require personal health information to be stored within Canada, it mandates stringent protections and controls over personal health data. Exporting MS Forms data to Excel, CSV, or SharePoint and then deleting the original form and responses could be a potential workaround, provided that these services are configured to store data in Canadian servers. It's crucial to ensure that any exported data remains within the scope of Canadian data protection laws and that proper consent, security measures, and contractual agreements are in place when handling personal health information.

    In summary, while there are potential workarounds to address data residency concerns, they require careful planning and verification to ensure compliance with Canadian privacy laws. It is advisable to consult with legal experts familiar with PHIPA and data privacy regulations to develop a comprehensive strategy that aligns with legal requirements and organizational needs. Additionally, staying updated with Microsoft's data residency policies and any changes in privacy legislation is essential for maintaining compliance over time.

    Hope this helps,

    Fathia A

    Was this answer helpful?

    0 comments No comments