Skip to content

Evidence request lists

USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)

Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Data Flows

USMCADIGITAL-1
Cross-Border Data Flows and Localisation

Per USMCA Chapter 19: Cross-border transfer of information by electronic means + Location of computing facilities + restrictions on data localization with limited exceptions.

Artefacts an auditor will ask for
  • USMCA evidence for USMCADIGITAL-1
Where this commonly fails
  • data flows + source code partial

Government Data

USMCADIGITAL-4
Government Data, Cybersecurity, Interoperability

Per USMCA: open government data + cybersecurity cooperation + interoperability + paperless trading.

Artefacts an auditor will ask for
  • USMCA evidence for USMCADIGITAL-4
Where this commonly fails
  • data flows + source code partial

Privacy

USMCADIGITAL-2
Personal Information Protection and Consumer Protection

Per USMCA Article 19.8: personal information protection + Consumer protection in e-commerce + Unsolicited commercial electronic communications.

Artefacts an auditor will ask for
  • USMCA evidence for USMCADIGITAL-2
Where this commonly fails
  • data flows + source code partial

Source Code

USMCADIGITAL-3
Source Code and Algorithm Protection

Per USMCA Article 19.16: source code + algorithm protection + limits on disclosure requirements.

Artefacts an auditor will ask for
  • USMCA evidence for USMCADIGITAL-3
Where this commonly fails
  • data flows + source code partial

USMCA Chapter 19: Consumer and Personal Information Protection

USMCA-19.13
Unsolicited Commercial Electronic Communications

Parties must adopt or maintain measures regarding unsolicited commercial electronic communications, including requirements for suppliers to facilitate the ability of recipients to prevent ongoing reception of those communications.

Artefacts an auditor will ask for
  • Unsubscribe and consent management policies
  • Records demonstrating opt-in or opt-out aligned with each Party's law
  • Sender identification and accurate header information
  • Complaint handling procedures for spam complaints
Where this commonly fails
  • Single opt-out flow applied without regard to differing jurisdictional rules (e.g., CASL in Canada)
  • Sender identification missing from automated transactional messages
  • Complaint reports retained without trend analysis
USMCA-19.7
Online Consumer Protection

Parties must adopt or maintain laws to proscribe fraudulent and deceptive commercial activities that cause harm to consumers engaged in online commercial activities and must cooperate with other Parties on enforcement.

Artefacts an auditor will ask for
  • Pre-contract disclosure templates for online sales
  • Refund, cancellation, and complaint handling procedures
  • Records of cooperation with regulators across the Parties
  • Trust mark or self-regulation participation records
Where this commonly fails
  • Dark patterns in subscription flows hindering cancellation
  • Complaint channels lacking multilingual support across the three Parties
  • No documented coordination with consumer protection regulators
USMCA-19.8
Personal Information Protection

Parties must adopt or maintain a legal framework that provides for the protection of personal information of users of digital trade and must promote compatibility between their respective regimes.

Artefacts an auditor will ask for
  • Personal information governance policy
  • Privacy notices for users in the United States, Mexico, and Canada
  • Cross-border data transfer impact assessments
  • Records of cooperation with privacy authorities
Where this commonly fails
  • Privacy notices addressed to a single jurisdiction without acknowledging others
  • Lack of demonstrable accountability for processors in another Party
  • No remediation process for affected users following an incident

USMCA Chapter 19: Cooperation and Compliance Practices

USMCA-19.14
Cooperation

Parties must cooperate on digital trade issues, including sharing information and experiences on regulations, policies, enforcement, and compliance regarding digital trade.

Artefacts an auditor will ask for
  • Records of regulator engagement across the three Parties
  • Participation in industry working groups on digital trade
  • Internal procedures for responding to regulator information requests
  • Annual cross-jurisdiction policy review
Where this commonly fails
  • Engagement led by external counsel without internal knowledge capture
  • No documented process for sharing lessons across teams
  • Industry group participation without translation to internal policy
USMCA-19.C
Recordkeeping for Digital Trade Compliance

Covered persons should maintain records adequate to demonstrate compliance with Chapter 19 obligations, including cross-border data transfers, source code protection, and unsolicited commercial communications.

Artefacts an auditor will ask for
  • Records management policy referencing Chapter 19 obligations
  • Audit logs for cross-border data flows
  • Customer consent and unsubscribe records
  • Source code disclosure approval logs
Where this commonly fails
  • Records dispersed across systems with no consolidated retrieval
  • Audit logs incomplete for backend transfers between cloud regions
  • Consent records retained only for the active relationship
USMCA-19.D
Training and Awareness on Digital Trade Obligations

Covered persons should provide training to relevant staff covering Chapter 19 obligations and the interaction with domestic privacy, cybersecurity, consumer protection, and customs requirements.

Artefacts an auditor will ask for
  • Training curriculum covering Chapter 19 obligations
  • Role-based training matrix
  • Completion records and knowledge checks
  • Annual refresh schedule reflecting regulator developments
Where this commonly fails
  • Training conducted by legal team only without operational scenarios
  • No training for product and engineering teams handling source code requests
  • Refresh cadence exceeds two years

USMCA Chapter 19: Data Flows and Computing Facilities

USMCA-19.11
Cross-Border Transfer of Information by Electronic Means

Parties must not prohibit or restrict the cross-border transfer of information, including personal information, by electronic means when this activity is for the conduct of the business of a covered person, subject to legitimate public policy objectives.

Artefacts an auditor will ask for
  • Data flow inventory documenting transfers across the three Parties
  • Legal basis register for personal information transfers
  • Documented assessment of legitimate public policy objectives where restrictions exist
  • Contractual safeguards with processors and subprocessors
Where this commonly fails
  • Data flow inventory missing direct-to-customer endpoints
  • Restrictions imposed for convenience and characterized as policy-based
  • Processor contracts lacking onward transfer commitments
USMCA-19.12
Location of Computing Facilities

Parties must not require a covered person to use or locate computing facilities in that Party's territory as a condition for conducting business in that territory.

Artefacts an auditor will ask for
  • Cloud architecture documentation showing facility selection criteria
  • Legal review of regulatory requirements for data residency
  • Contracts allowing flexibility in facility location
  • Records of regulator dialogue where localization is asserted
Where this commonly fails
  • Localization assumed mandatory based on outdated or non-binding guidance
  • Sector-specific regulators requiring local hosting without Chapter 19 carve-out analysis
  • Vendor contracts inflexible in facility selection

USMCA Chapter 19: Digital Products and Electronic Transactions

USMCA-19.3
Customs Duties on Digital Products

Parties must not impose customs duties, fees, or other charges on or in connection with the import or export of digital products transmitted electronically between the territories of the USMCA Parties.

Artefacts an auditor will ask for
  • Customs classification and treatment policy distinguishing electronic transmissions
  • Tariff schedule maintenance records aligned with Chapter 19
  • Invoicing controls that prevent fees on electronic deliveries
  • Internal training for customs and finance teams
Where this commonly fails
  • Service fees recharacterized as customs charges on electronic deliveries
  • Mixed shipments where electronic portion is bundled into dutiable totals
  • No internal escalation when finance imposes charges inconsistent with Chapter 19
USMCA-19.4
Non-Discriminatory Treatment of Digital Products

Parties must accord treatment no less favourable to digital products created, produced, published, contracted for, commissioned, or first made available on commercial terms in the territory of another Party than they accord to like domestic digital products.

Artefacts an auditor will ask for
  • Market access policies covering digital products
  • Procurement criteria reviewed for nationality-based preferences
  • Pricing policies covering digital subscriptions across the three Parties
  • Legal opinions covering exceptions and reservations
Where this commonly fails
  • Procurement specifications referencing country of origin without justification
  • Tax incentives accessible only to domestic platforms
  • Pricing differentials applied by geography without documented basis
USMCA-19.5
Domestic Electronic Transactions Framework

Parties must maintain a legal framework governing electronic transactions consistent with the UNCITRAL Model Law on Electronic Commerce 1996 or the United Nations Convention on the Use of Electronic Communications in International Contracts 2005.

Artefacts an auditor will ask for
  • Mapping of contract formation controls to UNCITRAL principles
  • Electronic signature and authentication policy
  • Records retention covering electronic contracts
  • Customer disclosures about electronic contract terms
Where this commonly fails
  • Electronic signature processes lacking documented audit trails
  • Contract repositories without time-stamped evidence of consent
  • Inconsistent treatment of click-through versus negotiated agreements
USMCA-19.6
Electronic Authentication and Electronic Signatures

Parties may not deny the legal validity of an electronic signature solely on the basis that it is in electronic form and must permit parties to electronic transactions to mutually determine appropriate authentication technologies and methods.

Artefacts an auditor will ask for
  • Electronic signature policy and accepted technologies
  • Risk-based assignment of signature assurance levels
  • User consent and identity verification procedures
  • Logs proving signer identity, intent, and integrity
Where this commonly fails
  • Required use of a specific national signature technology without alternatives
  • No risk-based selection between simple, advanced, and qualified signatures
  • Signature evidence not retained for the full statute of limitations
USMCA-19.9
Paperless Trade Administration

Parties must endeavour to accept trade administration documents submitted electronically as the legal equivalent of paper versions and to make them available to the public electronically.

Artefacts an auditor will ask for
  • Single window participation records
  • Electronic filing procedures for customs and trade documents
  • Validation that electronic submissions are accepted as legal equivalents
  • Public availability of trade administration forms online
Where this commonly fails
  • Paper originals still required despite electronic submission
  • Single window outages without contingency procedures
  • Forms published online but not accepted in electronic format

USMCA Chapter 19: Scope and Exceptions

USMCA-19.A
Scope and General Provisions

The Chapter applies to measures adopted or maintained by a Party that affect trade by electronic means and does not apply to government procurement or to information held or processed by or on behalf of a Party, or measures related to such information, including measures related to its collection.

Artefacts an auditor will ask for
  • Legal analysis identifying activities in scope of Chapter 19
  • Procurement carve-out documentation
  • Records distinguishing private-sector data flows from government-held information
  • Trade compliance training reflecting scope distinctions
Where this commonly fails
  • Scope confusion between Chapter 19 and Chapter 13 (Government Procurement)
  • Application of Chapter 19 obligations to government-held data without basis
  • Training omits the financial services carve-out under Article 19.1
USMCA-19.B
Exceptions and Public Policy Objectives

Measures that would otherwise be inconsistent with Chapter 19 may be justified if they are necessary to achieve a legitimate public policy objective and are not applied in a manner that constitutes arbitrary or unjustifiable discrimination or a disguised restriction on trade.

Artefacts an auditor will ask for
  • Necessity analysis for any restrictive measures invoked
  • Records of less restrictive alternatives considered
  • Consultation records with affected stakeholders
  • Periodic review confirming continuing necessity
Where this commonly fails
  • Restrictive measures retained after the underlying public policy concern has changed
  • No documented consideration of less restrictive alternatives
  • Stakeholder consultation limited to domestic actors

USMCA Chapter 19: Source Code, Cybersecurity and Open Data

USMCA-19.10
Principles on Access to and Use of the Internet for Digital Trade

Parties recognize the benefit of consumers being able to access and use services and applications of a consumer's choice, subject to reasonable network management.

Artefacts an auditor will ask for
  • Network management policy and transparency disclosures
  • Terms of service describing permitted devices and applications
  • Records of regulator engagement on open internet practices
  • Customer disclosure of throttling or filtering practices
Where this commonly fails
  • Network management practices not disclosed in customer-facing terms
  • Application restrictions imposed without documented technical rationale
  • No periodic review of policies against Chapter 19 principles
USMCA-19.15
Cybersecurity

Parties recognize that the threats to cybersecurity undermine confidence in digital trade and must endeavour to build capabilities to identify and mitigate intrusions and to use existing collaboration mechanisms to cooperate.

Artefacts an auditor will ask for
  • Cybersecurity program documentation including governance
  • Incident response procedures with cross-jurisdictional notification steps
  • Threat intelligence sharing arrangements
  • Workforce capability development plan
Where this commonly fails
  • Incident response plans omit notification across jurisdictions
  • Threat intelligence consumed without internal action procedures
  • Capability development limited to security team without business engagement
USMCA-19.16
Source Code

Parties must not require the transfer of, or access to, source code of software owned by a person of another Party, or to an algorithm expressed in that source code, as a condition for the import, distribution, sale, or use of that software in its territory.

Artefacts an auditor will ask for
  • Source code disclosure policies and approval workflows
  • Records of regulator requests and responses regarding source code or algorithms
  • Escrow arrangements consistent with Chapter 19 exceptions
  • Legal opinions on permitted disclosures (e.g., to a regulatory body or judicial authority)
Where this commonly fails
  • Vendor responses to regulator requests without legal review
  • Algorithm disclosure conflated with source code disclosure
  • No carve-out for critical infrastructure investigations
USMCA-19.17
Interactive Computer Services

Parties recognize the importance of the promotion of interactive computer services and must not adopt or maintain measures that treat a supplier or user of an interactive computer service as an information content provider in determining liability for harms related to information stored, processed, transmitted, distributed, or made available by the service.

Artefacts an auditor will ask for
  • Terms of service distinguishing user-generated content
  • Notice and takedown procedures with documented timelines
  • Records of good faith content moderation decisions
  • Audit trail for content moderation policy changes
Where this commonly fails
  • Moderation actions undocumented and not subject to appeal
  • Notice and takedown queues exceeding service level commitments
  • Lack of jurisdictional analysis when removing content
USMCA-19.18
Open Government Data

Parties recognize that facilitating public access to and use of government information fosters economic and social development and competitiveness and must endeavour to make government information available in machine-readable and open formats.

Artefacts an auditor will ask for
  • Inventory of government datasets published in machine-readable formats
  • Licensing terms for open government data
  • Metadata standards aligned with international practice
  • User feedback channels for dataset quality
Where this commonly fails
  • Datasets published in PDF rather than machine-readable formats
  • Licensing terms unclear or inconsistent across departments
  • Metadata absent or inconsistent across publishing systems
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement) framework page.