of EU–Canada trade in goods and services
2025European Commission, EU–Canada tradeCountry file
Canada
Canada maintains a substantial services relationship with the Union. CETA, data adequacy and cyber assurance must nonetheless remain three distinct readings.
Relationship with the European Union
CETA applied provisionally
CETA notably facilitates trade in services. It does not constitute a general recognition of a supplier's cyber controls.
Sources reviewed on 14 August 2026
of goods and services trade since 2016
2016–2025European Commission, EU–Canada tradeof EU–Canada services trade
2025European Commission, EU–Canada tradeEconomy and sectors
of finance and insurance firms report having been affected by an incident
2023Survey of Canadian businesses
Statistics Canada, incidents by sectorin information and cultural industries
2023Same investigation and same definition
Statistics Canada, incidents by sectorin professional, scientific and technical services
2023Same investigation and same definition
Statistics Canada, incidents by sectorIncidents, fraud and impersonation
of Canadian businesses report having been affected by a cyber incident
2023Business survey; declining since 2019
Statistics Canada, business cybercrimeof affected companies cite scams and fraud among the methods encountered
2023Base: affected organisations
Statistics Canada, business cybercrimeof fraud losses reported to the Anti-Fraud Centre
2025Over 112,000 reports; under-reporting possible
Canadian Anti-Fraud Centre, 2025 reportPoints to check within your organisation
Data adequacy
Verify that the organisation and processing fall within the covered commercial scope; adequacy does not validate any cyber control.
Financial and technology clients
For sectors more exposed in the survey, prepare more detailed evidence on access, incidents, continuity and critical suppliers.
Fraud and impersonation
Separate systems security from validation of sensitive requests: sender identity, bank details, new payees and access.
Developments to be aware of
The topics that may change your answers
CETA and trade in services
The agreement facilitates the business relationship without creating equivalence of controls.
Adequacy decision
Coverage applies to certain business organisations and must be verified for the actual flow.
Sector-specific cyber threats
The gaps between finance, information and other sectors help prioritise evidence without scoring the company.
Reported fraud
Reported losses measure the reports received, not the full extent of fraud suffered.
The adequacy decision can simplify certain flows but does not replace either the security file or the contractual commitments. Sector data is used to prioritise the review, particularly for financial and technology clients.
Official sources
Confidential exchange
