The Six Regimes the Tennant Tribunal Missed

How a single paragraph of arbitral reasoning created the textbook case for Lex Data, and why ARIHQ has now closed the enforcement loop

Prof. Barry Appleton, FCIArb TechCredFaculty Director, ABA TechCred Program, Co-Director and Distinguished Senior Fellow, New York Law School
This is the third piece in an ongoing series. First publish on TechCred Blog on Substack. Click here to subscribe.
On June 24, 2019, a three-member arbitral tribunal in Tennant Energy LLC v. Government of Canada, dismissed the applicability of European data protection law to its own proceedings in a single paragraph. The reasoning was terse: the European Union was not a party to NAFTA, so the GDPR did not, “presumptively, come within the material scope” of the arbitration.1
That paragraph is now the textbook example of what happens when a tribunal treats data protection law as if it were optional. The arbitration was Toronto-seated. The presiding arbitrator was established in Singapore. One of the co-arbitrators was a United Kingdom-based practitioner who had publicly acknowledged acting as a data controller under the GDPR in his own data privacy notice.2 The Permanent Court of Arbitration secretariat processed case materials through European-based infrastructure.3 California-resident counsel and California-resident expert witnesses participated on the investor side, with their personal data and the personal data of California-resident witnesses moving through the proceeding throughout. The Government of Canada was the respondent. The proceeding processed personal data of witnesses, experts, and counsel located across multiple jurisdictions.
The tribunal addressed all of that with five words: “does not, presumptively, come within.”4 That answer was not merely insufficient. It was wrong. The author was lead counsel for the investor in the proceeding and is now publishing a working paper that walks through, regime by regime, why.5
Seven years later, on April 22, 2026, the Quebec Superior Court annulled an arbitral award in ARIHQ v. Santé Québec6 on grounds that included the arbitrator’s transfer of party data outside Quebec and Canada in violation of Quebec and Canadian data privacy law. Tennant and ARIHQ are now the two ends of the same arc. Tennant shows what happens when a tribunal declines to identify the applicable data protection regimes. ARIHQ shows what happens in court when those obligations are then breached. The intervening seven years have turned the lex data from an unaddressed analytical gap into an enforcement-determinative requirement.
What the Tribunal Actually Missed
The Tennant tribunal did not miss one data protection regime. It missed six. Each one attached to the proceeding through an independent jurisdictional trigger that no tribunal ruling could displace.
The GDPR. Article 3 of the General Data Protection Regulation establishes extraterritorial reach in three ways. It applies whenever personal data is processed in the Union, whenever a controller or processor is established in the Union, and whenever the targeting criteria are met. The UK-based co-arbitrator processed personal data on a personal device located in the United Kingdom (then still subject to the GDPR’s EU-law successor regime), and the European-based PCA secretariat processed case materials in The Hague. Either of those facts, standing alone, was sufficient to engage the Regulation.
The UK GDPR. Following the United Kingdom’s withdrawal from the European Union, the United Kingdom retained the GDPR through the Data Protection Act 2018 and the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019.7 The Tennant tribunal’s UK-based co-arbitrator was personally subject to the UK GDPR, regardless of NAFTA’s identity.
California’s CCPA, as amended by the CPRA. The California Consumer Privacy Act, codified at Cal. Civ. Code § 1798.100 et seq. and amended by the California Privacy Rights Act effective January 1, 2023, applies to businesses that collect or process the personal information of California residents and meet statutory thresholds.8 The investor’s California-resident counsel and California-resident expert witnesses participated in the Tennant proceeding. Their personal data, and the personal data of California-resident witnesses whose information was processed in connection with the case record, fell within the CCPA/CPRA’s scope. The California regime is enforced by the California Privacy Protection Agency, which has rule-making and administrative-fining authority that does not depend on the parties’ choice of arbitral seat.9 The tribunal’s confidentiality order was silent on the regime entirely.
Canada’s PIPEDA. The Personal Information Protection and Electronic Documents Act applies to private-sector processing of personal data in the course of commercial activities anywhere in Canada.10 The investor’s counsel was based in Toronto. The arbitration was seated in Toronto. The investor itself was a private-sector commercial party. PIPEDA applied.
Canada’s Privacy Act. The Privacy Act governs federal government institutions in their handling of personal data. 11 The Government of Canada was the respondent. The respondent’s processing of investor and witness personal data in connection with the proceeding fell squarely within the Privacy Act’s scope.
Singapore’s PDPA. The Personal Data Protection Act 2012 applies to organizations that collect, use, or disclose personal data in Singapore. 12 The presiding arbitrator was established in Singapore and practiced there throughout the proceeding. The presiding arbitrator’s processing of case materials was governed by the PDPA.
A single proceeding. Six mandatory regimes. The tribunal addressed none of them.
Why “Mandatory” Means What It Says
International arbitration has long accommodated mandatory norms. Tribunals have applied mandatory tax laws despite contrary party stipulations, recognized legal privilege as inviolable irrespective of the procedural code, and invalidated agreements tainted by corruption on public policy grounds. The structural logic is settled: certain obligations attach regardless of party choice because the obligations protect interests the parties cannot waive.
Data protection regimes belong on that list. The GDPR, the UK GDPR, the CCPA/CPRA, PIPEDA, the Canadian Privacy Act, and the Singapore PDPA each protect a fundamental right of natural persons whose personal data is processed in the course of arbitration. None of those regimes asks for the parties’ permission. None can be displaced by an arbitration agreement. None turns on whether the European Union, the United Kingdom, the State of California, Canada, or Singapore is a party to the underlying treaty. 13
The lex data is the doctrinal name for this overlay. 14 It is the mandatory, extraterritorial data protection framework that attaches to international arbitral proceedings through five digital connecting factors: the seat, the location of arbitrators, counsel, and institutional secretariats, the location of data subjects, the location of data storage and processing, and the location where the proceeding’s outputs will be used. Each connecting factor is independent. Each can engage a different regime. Where two or more attach simultaneously, the proceeding becomes subject to multiple regimes operating in parallel. This is the transnational simultaneity problem, and it is now a feature of every digitally active international arbitration.
What ARIHQ Now Adds: Data Privacy Breach as an Enforcement Risk
For the seven years after the Tennant ruling, the consequence of ignoring the lex data was, in practice, deferred. Tribunals could decline to perform the analysis without an immediately visible cost. ARIHQ changed that.
In ARIHQ v. Santé Québec, Justice Sheehan of the Quebec Superior Court annulled an arbitral award rendered August 8, 2025, by sole arbitrator Michel Jeanniot. The award was annulled on multiple grounds, four of which addressed the arbitrator’s undisclosed use of generative AI to produce hallucinated legal authorities. A fifth ground, less commented on but equally important for present purposes, addressed data sovereignty directly. The court observed that entering party information into an AI platform likely transferred personal data to servers outside Quebec and Canada, and that such a transfer would violate Quebec’s and Canada’s data privacy laws. 15 In the ARIHQ court’s framing, this is not an abstract compliance problem. It is a jurisdictional problem that affects the validity of the arbitral process itself.
The doctrinal step is significant. The ARIHQ court did not treat data protection law as parallel to the arbitration. It treated compliance with data protection law as part of what makes the arbitral process valid. Breach of data privacy law in connection with the proceeding, in ARIHQ’s analysis, undermines the integrity of the procedure and the validity of any resulting award.
That linkage matters far beyond Quebec. New York Convention Article V(2)(b) permits a recognition court to refuse enforcement of an award where recognition would be contrary to the public policy of the enforcing forum. Schrems II identifies data protection as constitutional public policy in the European Union. 16 Awards rendered in proceedings that disregarded mandatory data protection obligations, or that involved transfers of personal data in violation of the GDPR, the UK GDPR, the CCPA/CPRA, PIPEDA, the Canadian Privacy Act, or the Singapore PDPA, become structurally vulnerable at the recognition stage. The Lex Data working paper develops the analysis for three enforcement jurisdictions and concludes that the risk is no longer hypothetical. 17
Tennant defined the failure mode at the front end of the proceeding: the tribunal declines to identify which data protection regimes apply. ARIHQ defined the failure mode at the back end: the arbitrator breaches a data protection regime in connection with the proceeding, and the resulting award does not survive judicial review. The two cases connect through a single proposition: data protection law is integral to the validity of the arbitral process, and its breach is no longer an off-balance-sheet liability.
What Proactive Lex Data Governance Looks Like
The tribunal that has identified the applicable regimes at the first procedural meeting, allocated controller and processor roles transparently, addressed cross-border transfer mechanisms, conducted a Data Protection Impact Assessment where Article 35 requires it, and documented compliance, has built the record that defeats Article V(2)(b) at the enforcement stage. When California-resident participants are involved, the tribunal has identified and addressed the CCPA/CPRA threshold question. Where AI tools are used in the proceedings, whether by the arbitrators, counsel, or experts, the tribunal has documented the platform’s data-handling characteristics and ensured that personal data is not transferred to servers in a manner that breaches applicable regimes. The cost is an hour at the first session. The benefit is enforceability.
Why the Cybersecurity Protocol Is Necessary But Not Sufficient
The leading institutional instrument for digital governance in international arbitration is the ICCA-NYC Bar-CPR Cybersecurity Protocol for International Arbitration (2020, revised 2022).18 The Protocol normalized information security planning as a component of the arbitral procedure. Its contribution is substantial.
It is also incomplete. The Protocol is a cybersecurity instrument. It addresses the protection of case information against unauthorized access, use, disclosure, modification, and destruction. It does not address the affirmative obligations that data protection law imposes regardless of any security threat: the lawful basis for processing under GDPR Article 6; the controller and processor mapping under Article 26 and Article 28; the Data Protection Impact Assessment under Article 35; the cross-border transfer mechanisms under Articles 44 through 49; the consumer-rights mechanisms under the CCPA/CPRA; and the post-quantum security dimension that NIST FIPS 203, 204, and 205 (published August 2024) now adds to the Article 32 “appropriate to the risk” standard.19
The Lex Data working paper proposes five targeted enhancements to close the gap: a data-role mapping appendix, a DPIA decision tree, a transfer mechanism appendix, a multi-regime coordination matrix, and a post-proceeding data governance protocol that incorporates a documented plan for post-quantum re-encryption of any materials retained over a long time horizon. The enhancements are designed to be adopted by the institutional drafters of the Protocol’s next edition, not to compete with the Protocol.
How Tennant and ARIHQ Define the Arc
Tennant Energy and ARIHQ v. Santé Québec: the front and back covers are of the same volume. Tennant is the case in which a tribunal dismissed a claim under mandatory data protection law on grounds that did not survive analysis. ARIHQ is the case decided seven years later in which a court annulled an arbitral award in part because an arbitrator’s data-handling practices breached Quebec and Canadian data privacy laws and undermined the procedural integrity of the proceeding.
Both decisions belong to the same arc. Both turn on the same insight: the lex arbitri is necessary but no longer sufficient to govern the digital conduct of international arbitration. The lex data governs informational sovereignty. The companion lex AI framework governs the digital tribunal.20 The Digital Security Framework governs the security of the infrastructure. 21 Together with the lex arbitri, they constitute the Digital Procedural Constitution.
The Tennant tribunal could have closed the analytical gap in 2019 with one additional paragraph. The ARIHQ arbitrator could have avoided annulment in 2025 through disclosure and a different platform choice. Neither did. Their successors have run out of room to repeat the omission.
A Final Word
The Tennant tribunal’s single-paragraph ruling is a useful artifact. It marks, with unusual clarity, the moment when the digital governance gap in international arbitration became visible. The proceeding processed multimillion-dollar claims across six mandatory data protection regimes simultaneously. The tribunal addressed none of them. The result was a regulatory vacuum that no party had requested and no law required.
The post-Tennant, post-ARIHQ tribunal has no excuse. The applicable regimes are identifiable. The connecting factors are objective. The procedural responses are now in the institutional literature and will shortly be consolidated into a Digital Governance Protocol designed to be dropped directly into Procedural Order No. 1.
When the next tribunal is asked at its first procedural meeting whether the GDPR, the CCPA/CPRA, or any other applicable regime applies, the answer is no longer one paragraph. It is an analysis. The lex data is the framework for that analysis. Performing it is now the baseline.
References
Appleton, Barry. Lex Data: Reconceptualizing the Law of the Digital Seat in International Arbitration (Working Paper, April 30, 2026), https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6610079.
Appleton, Barry. Lex AI: Mandatory AI Governance and the Digital Tribunal in International Arbitration (Working Paper, April 30, 2026), https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6610019.
Appleton, Barry. Arbitration Hacked: Toward a Unified Cybersecurity and Data Breach Framework for International Arbitral Proceedings (Working Paper, April 21, 2026), https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6625218.
Appleton, Barry. ARIHQ v. Santé Québec: The Case That Changed Arbitrator AI Liability, TechCred Substack (May 4, 2026).
Association des ressources intermédiaires d’hébergement du Québec (ARIHQ) c. Santé Québec — Centre intégré universitaire de santé et de services sociaux du Centre-Sud-de-l’Île-de-Montréal, 2026 QCCS 1360 (Que. Sup. Ct. Apr. 22, 2026) (Sheehan, J.C.S.), https://canlii.ca/t/kkjtm.
California Consumer Privacy Act, Cal. Civ. Code §§ 1798.100–1798.199.100 (West 2024), as amended by the California Privacy Rights Act of 2020.
ICCA, New York City Bar Association & CPR Institute, Cybersecurity Protocol for International Arbitration (2022 ed., first published 2020), https://drs.cpradr.org/rules/protocols-guidelines/icca-nyc-bar-cybersecurities.
ICCA-IBA Joint Task Force on Data Protection in International Arbitration, Roadmap to Data Protection in International Arbitration, ICCA Reports No. 7 (2022), https://www.arbitration-icca.org/icca-reports-no-7-icca-iba-roadmap-data-protection-international-arbitration.
National Institute of Standards and Technology, Federal Information Processing Standards Publications 203, 204, and 205 (August 2024), https://csrc.nist.gov/projects/post-quantum-cryptography.
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation), 2016 O.J. (L 119) 1.
Thanks for reading TechCred! Subscribe for free to receive new posts and stay ahead of the curve.
1 Tennant Energy LLC v. Government of Canada, PCA Case No.2018-54, Tribunal Communication on Confidentiality Order (June 24, 2019), as analyzed in Barry Appleton, Data, Sovereignty, and Arbitral Autonomy: Confronting Extraterritorial Digital Regulations, in Austrian Yearbook on International Arbitration 2026 (Klausegger et al. eds., 2026). Prof. Appleton was counsel for Tennant Energy in that proceeding.
2 The disclosure was a matter of public record at the time of the proceeding and is discussed at length in Barry Appleton, Lex Data: Reconceptualizing the Law of the Digital Seat in International Arbitration (Working Paper, April 21, 2026), Part IV, https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6610079.
3 The PCA secretariat is established in The Hague. Its processing of case materials engaged GDPR establishment-based jurisdiction under Article 3(1).
4 Tennant Energy, Tribunal Communication on Confidentiality Order, supra note 1.
5 All scholarly comment in this post reflects the author’s scholarly capacity and does not reflect on any client or organization. The Tennant arbitration concluded with a final award rendered October 25, 2022. Public information about the proceeding is referenced consistent with what appears in the Lex Data working paper.
6 Association des ressources intermédiaires d’hébergement du Québec (ARIHQ) c. Santé Québec — Centre intégré universitaire de santé et de services sociaux du Centre-Sud-de-l’Île-de-Montréal, 2026 QCCS 1360 (Que. Sup. Ct. Apr. 22, 2026) (Sheehan, J.C.S.), https://canlii.ca/t/kkjtm.
7 Data Protection Act 2018, c. 12 (U.K.); Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019, S.I. 2019 No. 419 (U.K.).
8 California Consumer Privacy Act of 2018, Cal. Civ. Code §§ 1798.100–1798.199.100 (West 2024); California Privacy Rights Act of 2020, codified through amendments to the CCPA, effective January 1, 2023. The “doing business in California” threshold is set out at Cal. Civ. Code § 1798.140(d)(1). For the application of the regime to participants in international arbitration through California-resident data subjects, see Appleton, Lex Data, supra note 2, Part III.A.
9 California Privacy Protection Agency, established by Cal. Civ. Code § 1798.199.10, with rule-making authority under Cal. Civ. Code §§ 1798.185 and 1798.199.40.
10 Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5, ss. 2, 4(1)(a) (Can.).
11 Privacy Act, R.S.C. 1985, c. P-21 (Can.).
12 Personal Data Protection Act 2012, No. 26 of 2012 (Sing.), as amended by Personal Data Protection (Amendment) Act 2020, No. 40 of 2020 (Sing.).
13 The structural argument is elaborated in Appleton, Lex Data, supra note 2, Parts II and III.
14 The term “lex data” was identified in earlier commentary on extraterritorial digital regulation. The Lex Data working paper systematizes it as a doctrinal category and identifies the five connecting factors. See Appleton, Lex Data, supra note 2, Part III.A.
15 ARIHQ, supra note 6, at para. 90 et seq.; see also Barry Appleton, ARIHQ v. Santé Québec: The Case That Changed Arbitrator AI Liability, TechCred Substack (May 4, 2026) (analyzing the data sovereignty holding).
16 [1] Case C-311/18, Data Protection Commissioner v. Facebook Ireland Ltd. (Schrems II), ECLI:EU:C:2020:559 (July 16, 2020); see also Appleton, Lex Data, supra note 2, Part VI.A.
17 Appleton, Lex Data, supra note 2, Part VI (analyzing enforcement risk under Article V(2)(b) of the New York Convention across three jurisdictions).
18 ICCA, New York City Bar Association & CPR Institute, Cybersecurity Protocol for International Arbitration (2022 ed., first published 2020), https://drs.cpradr.org/rules/protocols-guidelines/icca-nyc-bar-cybersecurities.
19 National Institute of Standards and Technology, Federal Information Processing Standards Publications 203, 204, and 205 (August 2024), https://csrc.nist.gov/projects/post-quantum-cryptography.
20 Barry Appleton, Lex AI: Mandatory AI Governance and the Digital Tribunal in International Arbitration (Working Paper, April 30, 2026), https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6610019.
21 Barry Appleton, Arbitration Hacked: Toward a Unified Cybersecurity and Data Breach Framework for International Arbitral Proceedings (Working Paper, April 21, 2026), https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6625218





Comments