At 2:15 PM on a Thursday afternoon in late November, the HR director of a regional manufacturing company in Red Deer sat at her desk reviewing the master services agreement that the CFO had executed six weeks earlier with a cloud-based human resources information system vendor headquartered in Texas. The document ran forty-seven pages, dense with technical specifications, service level commitments, and limitation of liability clauses, but as she worked through Schedule B—the data processing terms—she realized that several provisions she had assumed would be standard were either ambiguous or entirely absent. The platform was designed to consolidate the company's payroll processing, benefits enrolment workflows, and performance review documentation into a single integrated system, replacing three legacy applications that had served the organization for nearly a decade. What the HR director discovered as she moved paragraph by paragraph through the agreement was that the contract contained no binding commitment regarding where employee data would be stored, no explicit acknowledgment of the vendor's obligations under Alberta's Personal Information Protection Act, and no mechanism for ensuring that subprocessors engaged by the vendor would be held to equivalent privacy standards. The migration was scheduled to begin in twenty-three days, and the company's four hundred and twelve employees—including those with documented medical accommodations, disability claims, and workplace injury histories—would have their most sensitive personal information transferred to infrastructure that the contract described only as "secure data centers located in North America."