USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Data Flows
Per USMCA Chapter 19: Cross-border transfer of information by electronic means + Location of computing facilities + restrictions on data localization with limited exceptions.
- USMCA evidence for USMCADIGITAL-1
- data flows + source code partial
Government Data
Per USMCA: open government data + cybersecurity cooperation + interoperability + paperless trading.
- USMCA evidence for USMCADIGITAL-4
- data flows + source code partial
Privacy
Per USMCA Article 19.8: personal information protection + Consumer protection in e-commerce + Unsolicited commercial electronic communications.
- USMCA evidence for USMCADIGITAL-2
- data flows + source code partial
Source Code
Per USMCA Article 19.16: source code + algorithm protection + limits on disclosure requirements.
- USMCA evidence for USMCADIGITAL-3
- data flows + source code partial
USMCA Chapter 19: Consumer and Personal Information Protection
Parties must adopt or maintain measures regarding unsolicited commercial electronic communications, including requirements for suppliers to facilitate the ability of recipients to prevent ongoing reception of those communications.
- Unsubscribe and consent management policies
- Records demonstrating opt-in or opt-out aligned with each Party's law
- Sender identification and accurate header information
- Complaint handling procedures for spam complaints
- Single opt-out flow applied without regard to differing jurisdictional rules (e.g., CASL in Canada)
- Sender identification missing from automated transactional messages
- Complaint reports retained without trend analysis
Parties must adopt or maintain laws to proscribe fraudulent and deceptive commercial activities that cause harm to consumers engaged in online commercial activities and must cooperate with other Parties on enforcement.
- Pre-contract disclosure templates for online sales
- Refund, cancellation, and complaint handling procedures
- Records of cooperation with regulators across the Parties
- Trust mark or self-regulation participation records
- Dark patterns in subscription flows hindering cancellation
- Complaint channels lacking multilingual support across the three Parties
- No documented coordination with consumer protection regulators
Parties must adopt or maintain a legal framework that provides for the protection of personal information of users of digital trade and must promote compatibility between their respective regimes.
- Personal information governance policy
- Privacy notices for users in the United States, Mexico, and Canada
- Cross-border data transfer impact assessments
- Records of cooperation with privacy authorities
- Privacy notices addressed to a single jurisdiction without acknowledging others
- Lack of demonstrable accountability for processors in another Party
- No remediation process for affected users following an incident
USMCA Chapter 19: Cooperation and Compliance Practices
Parties must cooperate on digital trade issues, including sharing information and experiences on regulations, policies, enforcement, and compliance regarding digital trade.
- Records of regulator engagement across the three Parties
- Participation in industry working groups on digital trade
- Internal procedures for responding to regulator information requests
- Annual cross-jurisdiction policy review
- Engagement led by external counsel without internal knowledge capture
- No documented process for sharing lessons across teams
- Industry group participation without translation to internal policy
Covered persons should maintain records adequate to demonstrate compliance with Chapter 19 obligations, including cross-border data transfers, source code protection, and unsolicited commercial communications.
- Records management policy referencing Chapter 19 obligations
- Audit logs for cross-border data flows
- Customer consent and unsubscribe records
- Source code disclosure approval logs
- Records dispersed across systems with no consolidated retrieval
- Audit logs incomplete for backend transfers between cloud regions
- Consent records retained only for the active relationship
Covered persons should provide training to relevant staff covering Chapter 19 obligations and the interaction with domestic privacy, cybersecurity, consumer protection, and customs requirements.
- Training curriculum covering Chapter 19 obligations
- Role-based training matrix
- Completion records and knowledge checks
- Annual refresh schedule reflecting regulator developments
- Training conducted by legal team only without operational scenarios
- No training for product and engineering teams handling source code requests
- Refresh cadence exceeds two years
USMCA Chapter 19: Data Flows and Computing Facilities
Parties must not prohibit or restrict the cross-border transfer of information, including personal information, by electronic means when this activity is for the conduct of the business of a covered person, subject to legitimate public policy objectives.
- Data flow inventory documenting transfers across the three Parties
- Legal basis register for personal information transfers
- Documented assessment of legitimate public policy objectives where restrictions exist
- Contractual safeguards with processors and subprocessors
- Data flow inventory missing direct-to-customer endpoints
- Restrictions imposed for convenience and characterized as policy-based
- Processor contracts lacking onward transfer commitments
Parties must not require a covered person to use or locate computing facilities in that Party's territory as a condition for conducting business in that territory.
- Cloud architecture documentation showing facility selection criteria
- Legal review of regulatory requirements for data residency
- Contracts allowing flexibility in facility location
- Records of regulator dialogue where localization is asserted
- Localization assumed mandatory based on outdated or non-binding guidance
- Sector-specific regulators requiring local hosting without Chapter 19 carve-out analysis
- Vendor contracts inflexible in facility selection
USMCA Chapter 19: Digital Products and Electronic Transactions
Parties must not impose customs duties, fees, or other charges on or in connection with the import or export of digital products transmitted electronically between the territories of the USMCA Parties.
- Customs classification and treatment policy distinguishing electronic transmissions
- Tariff schedule maintenance records aligned with Chapter 19
- Invoicing controls that prevent fees on electronic deliveries
- Internal training for customs and finance teams
- Service fees recharacterized as customs charges on electronic deliveries
- Mixed shipments where electronic portion is bundled into dutiable totals
- No internal escalation when finance imposes charges inconsistent with Chapter 19
Parties must accord treatment no less favourable to digital products created, produced, published, contracted for, commissioned, or first made available on commercial terms in the territory of another Party than they accord to like domestic digital products.
- Market access policies covering digital products
- Procurement criteria reviewed for nationality-based preferences
- Pricing policies covering digital subscriptions across the three Parties
- Legal opinions covering exceptions and reservations
- Procurement specifications referencing country of origin without justification
- Tax incentives accessible only to domestic platforms
- Pricing differentials applied by geography without documented basis
Parties must maintain a legal framework governing electronic transactions consistent with the UNCITRAL Model Law on Electronic Commerce 1996 or the United Nations Convention on the Use of Electronic Communications in International Contracts 2005.
- Mapping of contract formation controls to UNCITRAL principles
- Electronic signature and authentication policy
- Records retention covering electronic contracts
- Customer disclosures about electronic contract terms
- Electronic signature processes lacking documented audit trails
- Contract repositories without time-stamped evidence of consent
- Inconsistent treatment of click-through versus negotiated agreements
Parties may not deny the legal validity of an electronic signature solely on the basis that it is in electronic form and must permit parties to electronic transactions to mutually determine appropriate authentication technologies and methods.
- Electronic signature policy and accepted technologies
- Risk-based assignment of signature assurance levels
- User consent and identity verification procedures
- Logs proving signer identity, intent, and integrity
- Required use of a specific national signature technology without alternatives
- No risk-based selection between simple, advanced, and qualified signatures
- Signature evidence not retained for the full statute of limitations
Parties must endeavour to accept trade administration documents submitted electronically as the legal equivalent of paper versions and to make them available to the public electronically.
- Single window participation records
- Electronic filing procedures for customs and trade documents
- Validation that electronic submissions are accepted as legal equivalents
- Public availability of trade administration forms online
- Paper originals still required despite electronic submission
- Single window outages without contingency procedures
- Forms published online but not accepted in electronic format
USMCA Chapter 19: Scope and Exceptions
The Chapter applies to measures adopted or maintained by a Party that affect trade by electronic means and does not apply to government procurement or to information held or processed by or on behalf of a Party, or measures related to such information, including measures related to its collection.
- Legal analysis identifying activities in scope of Chapter 19
- Procurement carve-out documentation
- Records distinguishing private-sector data flows from government-held information
- Trade compliance training reflecting scope distinctions
- Scope confusion between Chapter 19 and Chapter 13 (Government Procurement)
- Application of Chapter 19 obligations to government-held data without basis
- Training omits the financial services carve-out under Article 19.1
Measures that would otherwise be inconsistent with Chapter 19 may be justified if they are necessary to achieve a legitimate public policy objective and are not applied in a manner that constitutes arbitrary or unjustifiable discrimination or a disguised restriction on trade.
- Necessity analysis for any restrictive measures invoked
- Records of less restrictive alternatives considered
- Consultation records with affected stakeholders
- Periodic review confirming continuing necessity
- Restrictive measures retained after the underlying public policy concern has changed
- No documented consideration of less restrictive alternatives
- Stakeholder consultation limited to domestic actors
USMCA Chapter 19: Source Code, Cybersecurity and Open Data
Parties recognize the benefit of consumers being able to access and use services and applications of a consumer's choice, subject to reasonable network management.
- Network management policy and transparency disclosures
- Terms of service describing permitted devices and applications
- Records of regulator engagement on open internet practices
- Customer disclosure of throttling or filtering practices
- Network management practices not disclosed in customer-facing terms
- Application restrictions imposed without documented technical rationale
- No periodic review of policies against Chapter 19 principles
Parties recognize that the threats to cybersecurity undermine confidence in digital trade and must endeavour to build capabilities to identify and mitigate intrusions and to use existing collaboration mechanisms to cooperate.
- Cybersecurity program documentation including governance
- Incident response procedures with cross-jurisdictional notification steps
- Threat intelligence sharing arrangements
- Workforce capability development plan
- Incident response plans omit notification across jurisdictions
- Threat intelligence consumed without internal action procedures
- Capability development limited to security team without business engagement
Parties must not require the transfer of, or access to, source code of software owned by a person of another Party, or to an algorithm expressed in that source code, as a condition for the import, distribution, sale, or use of that software in its territory.
- Source code disclosure policies and approval workflows
- Records of regulator requests and responses regarding source code or algorithms
- Escrow arrangements consistent with Chapter 19 exceptions
- Legal opinions on permitted disclosures (e.g., to a regulatory body or judicial authority)
- Vendor responses to regulator requests without legal review
- Algorithm disclosure conflated with source code disclosure
- No carve-out for critical infrastructure investigations
Parties recognize the importance of the promotion of interactive computer services and must not adopt or maintain measures that treat a supplier or user of an interactive computer service as an information content provider in determining liability for harms related to information stored, processed, transmitted, distributed, or made available by the service.
- Terms of service distinguishing user-generated content
- Notice and takedown procedures with documented timelines
- Records of good faith content moderation decisions
- Audit trail for content moderation policy changes
- Moderation actions undocumented and not subject to appeal
- Notice and takedown queues exceeding service level commitments
- Lack of jurisdictional analysis when removing content
Parties recognize that facilitating public access to and use of government information fosters economic and social development and competitiveness and must endeavour to make government information available in machine-readable and open formats.
- Inventory of government datasets published in machine-readable formats
- Licensing terms for open government data
- Metadata standards aligned with international practice
- User feedback channels for dataset quality
- Datasets published in PDF rather than machine-readable formats
- Licensing terms unclear or inconsistent across departments
- Metadata absent or inconsistent across publishing systems
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement) framework page.