Data sovereignty in Canada: where your data sits and whose law reaches it

Data sovereignty is the question of whose law can reach your data. Where the data is stored, called data residency, is a separate question, and a Canadian address does not settle the first one. For a manufacturer or distributor in Canada, the answer depends on where each copy of the data sits, which company holds it, what Canadian law asks of you and what your contracts say. This guide covers each of those with its source, and ends with the questions to ask any provider.

A clean, brightly lit production hall with a polished floor, yellow safety fencing and a two-storey office block

What data sovereignty means

A Government of Canada white paper on data sovereignty and public cloud defines the two terms that most conversations mix up. Data sovereignty, in relation to Canada, is “Canada’s right to control access to and disclosure of its digital information subject only to Canadian laws.” Data residency is “the physical or geographical location of an organization’s digital information.”

The paper also says “Data residency does not mitigate against the application of foreign laws.” Regardless of where the servers are, a cloud provider with foreign operations “could be required to comply with a warrant, court order or subpoena request from a foreign law enforcement agency.” For a business, the answer depends on who holds the data as well as where it is stored.

TermThe question it answersWhat decides the answer
Data residencyWhere is the data stored?The country and data centre where the provider keeps it
Data sovereigntyWhose law can order the data handed over?The countries whose law applies to each company that holds the data
Data localizationMust the data stay inside a border?A law or a contract that says so

AI adds one more question: where the model that reads your data runs. Sovereign AI in Canada covers models, compute and Canada’s AI programs. This guide stays with the stored data.

What Canadian law requires

For a private business, the Canadian rules in this section attach to two kinds of records: tax records and personal information. Personal information is information about an identifiable individual. A plant’s drawings, routings and price lists usually hold little of it, and its employee files and customer contact lists hold more. Your counsel draws the conclusion for your own setup, and this guide is not legal advice.

Tax records

The Canada Revenue Agency’s record-keeping page sets a residency rule for business records: “You must keep records at your place of business or your residence in Canada, unless the Canada Revenue Agency (CRA) gives you written permission to keep them elsewhere.” It adds that “Records kept outside of Canada and accessed electronically from Canada are not considered to be records kept in Canada.” If your accounting system or ERP stores its data on servers outside Canada, take that rule to your accountant.

Personal information under PIPEDA

PIPEDA is the federal privacy law for businesses. The Office of the Privacy Commissioner’s guidelines for processing personal data across borders say “PIPEDA does not prohibit organizations in Canada from transferring personal information to an organization in another jurisdiction for processing.” The organization that transfers the data stays responsible for it. Under clause 4.1.3, an organization “is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing,” and must use “contractual or other means” to give it a comparable level of protection.

The same guidelines set two limits. “No contract can override the criminal, national security or any other laws of the country to which the information has been transferred.” An organization must also tell customers that their information may be sent to another jurisdiction, where “it may be accessed by the courts, law enforcement and national security authorities.”

Two more points matter to a company that sells to other businesses. The Commissioner’s summary of PIPEDA says the law does not cover business contact information, such as an employee’s name, title and work email, when it is used “solely for the purpose of communicating with that person in relation to their employment or profession.” The summary also says Alberta, British Columbia and Quebec have private-sector privacy laws deemed substantially similar to PIPEDA, and that any business handling personal information that crosses provincial or national borders in its commercial activities is subject to PIPEDA.

Quebec: an assessment before personal information leaves the province

Section 17 of Quebec’s Act respecting the protection of personal information in the private sector says: “Before communicating personal information outside Québec, a person carrying on an enterprise must conduct a privacy impact assessment.” The assessment weighs how sensitive the information is, what it will be used for, the protection measures, including contractual ones, and the legal framework where it would go. The information may leave if the assessment finds it would receive adequate protection, and the transfer needs a written agreement. The same applies when a person or body outside Quebec collects, uses, communicates or keeps the information for you.

The rule came with Law 25 and has applied since September 2023, according to the Commission d’accès à l’information (in French). The section says outside Québec, so it applies to a server in Ontario as well as one in Virginia. Section 3.3 adds an assessment for “any project to acquire, develop or overhaul an information system” that involves personal information. Section 1 exempts information about a person’s duties within an enterprise, such as their name, title and work contact details, from the division of the act that contains section 17.

Public bodies and the companies they hire

Some provinces set storage rules for public bodies, and one of them reaches the contractors those bodies hire. Nova Scotia’s Personal Information International Disclosure Protection Act requires a public body, and any service provider it retains to handle personal information, to keep the personal information in their custody “stored only in Canada and accessed only in Canada,” unless an exception applies, such as the person’s consent. In British Columbia, section 33.1 of the public-sector privacy act lets a public body disclose personal information outside Canada “only if the disclosure is in accordance with the regulations, if any, made by the minister responsible for this Act.” If you supply a public body, read the data clauses in that contract.

Controlled goods

If your company is registered in the Controlled Goods Program, the program’s cloud guidance says registrants “should take note of any data residency options to ensure that their controlled goods data is stored on servers located in Canada.” For data stored outside Canada, it says Global Affairs Canada must be consulted about export licensing. It also asks registrants to encrypt controlled goods data in transit and at rest in a cloud service.

The US CLOUD Act and other foreign law

The US Department of Justice says the United States enacted the CLOUD Act in March 2018. It added section 2713 to title 18 of the US Code, which requires a provider of electronic communication or remote computing services to disclose data in its “possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States.”

The white paper calls the US Foreign Intelligence Surveillance Act (FISA) and “the US government’s ability to compel an organization subject to US law to turn over data under its control, regardless of the data’s location and without notifying Canada” the primary risk to data sovereignty. The Justice Department’s CLOUD Act page, last updated October 24, 2023, lists agreements with the United Kingdom and Australia. For Canada, it lists the March 22, 2022 announcement that the two countries had begun negotiating one.

Canada has laws of the same kind. The Government of Canada’s Digital Sovereignty Framework says most countries, including Canada and the United States, have laws that allow their authorities to request access to information held by organizations within their borders. Its Canadian examples include the Criminal Code, the Income Tax Act and the Customs Act. It concludes: “Using a Canadian supplier or storing data in Canada does not guarantee data will be outside the jurisdiction of foreign courts.”

What a Canadian cloud region settles

A cloud region is a group of data centres in one area where a provider lets you store data and run services. AWS lists two regions in Canada, Canada (Central) and Canada West (Calgary). Microsoft Azure lists Canada Central in Toronto and Canada East in Quebec, and Google Cloud lists regions in Montréal and Toronto.

A Canadian region settles residency for the data you store in it. The provider’s owner stays the same, so the white paper’s point about foreign law still applies. A region may also cover storage without covering every processing step. AWS says that when a Bedrock AI request from its Canada (Central) Region uses cross-Region inference, the processing may happen in another Region, while data at rest, including logs and knowledge bases, “remains exclusively within the Canada (Central) Region.” Ask which region stores each kind of data and which region processes it. The ways to set up AI on company data are compared in private AI for business.

Encryption and who holds the keys

One of the white paper’s answers for government data is encryption with keys the customer controls. It directs that protected data in the cloud be encrypted in transit and at rest, and that the government “maintain exclusive control of the encryption keys.” It also names the limit: data that an application processes in the cloud “would need to be decrypted before processing,” so an unencrypted copy exists there for a time. Ask who holds the keys, and where the data is decrypted when software works on it.

Where your data can sit, and whose law reaches it

The table applies the sources above to the four places a company’s data usually sits. The last column is our suggestion.

Where the data sitsWhose law can reach itWhat to check
A server in your own buildingCanadian law. Canadian authorities can request information from organizations under statutes such as the Criminal Code.Who has administrator access, where the backups are written, and whether a vendor can reach the server remotely
A data centre in Canada run by a Canadian providerCanadian law. A provider that also operates in other countries must follow the laws of each one.Where the provider operates, and which subcontractors can reach the data
A Canadian region of a provider subject to US lawCanadian law, and US law through the provider, which can be ordered to produce data under its control wherever it is storedThe region for each service, where processing happens, and who holds the encryption keys
A region outside CanadaThe law of that country, and US law if the provider is subject to it. Your accountability under PIPEDA stays with you.The CRA rule for tax records, and Quebec’s assessment for personal information
Count every copy

A provider can keep the main database in a Canadian region and write backups, logs or support attachments somewhere else. Ask for the location of each copy by name, and ask who can read it.

Map where your data sits today

Tell Derik which systems hold your records and which customers ask where their data goes. He will tell you where each copy sits and whose law reaches it.

Start a conversation

What to ask a provider, and what to put in the contract

A customer contract can set stricter terms than the law, for example a clause that keeps the customer’s drawings in Canada. Read the data clauses in your largest customers’ agreements before you choose where your own systems store data. Then take these questions to every provider, including ThriveAI, and ask for the answers in writing.

QuestionWhat a complete answer names
Where is our data stored at rest?The provider, region and country for each kind of data, including backups and logs
Where is our data processed?The region for each processing step, including any AI model that reads the data
Which other companies can reach our data?Each subprocessor, where it operates and who owns it, with notice before the list changes
Which countries’ laws apply to you and your parent company?The countries, and what you do when a legal demand for our data arrives
Who holds the encryption keys?The party that holds them, and whether the provider can read the data without them
Is our data used to train models?The contract clause that rules it out without your written consent
How do we leave?The export format, the timeline, and written confirmation that the data was destroyed

The white paper asks the government’s own cloud contracts for one more clause: the provider must disclose any unauthorized access to the data, “including access made under court order,” unless the law forbids it. It notes that US law forbids that disclosure in some cases, such as an order of the US Foreign Intelligence Surveillance Court. The account settings to check next are in secure AI at work, and the wider legal picture for AI is in AI governance.

How ThriveAI handles your data

ThriveAI is an AI engineering company in Ottawa that builds private AI systems for manufacturers and distributors in Ontario and Quebec, on their own data. Derik Lawlis, the founder, leads every project and stays close to the build.

The platform ThriveAI builds on is designed to keep each client’s data on its own server in Canada that only that client uses. You choose the AI model that reads it: one that runs on that server, or a hosted model under a written zero data retention agreement, under which the provider keeps nothing after answering. A hosted model may process requests outside Canada, so the contract names the model and its service tier. Every connection only reads data, and nothing is sent or saved in your systems until the person responsible approves it, as described in human in the loop.

You keep your data, and everything the system records exports in full in a documented format. ThriveAI has no audited certification such as SOC 2 or ISO 27001, and each security measure is written down so your IT lead or outside security adviser can review it. To see where your own records stand first, try the AI readiness assessment. For the company and how a project runs, see About ThriveAI.

Questions people ask

What is data sovereignty?
Data sovereignty is the question of whose law can reach your data. A Government of Canada white paper defines it, in relation to Canada, as Canada's right to control access to and disclosure of its digital information subject only to Canadian laws. For a business, the answer depends on which companies hold the data and which countries' laws apply to them.
What is the difference between data sovereignty and data residency?
Data residency is where the data is stored. Data sovereignty is whose law can order it handed over. The same white paper says data residency does not mitigate against the application of foreign laws, because a provider subject to another country's law can be ordered to produce data it stores in Canada.
Does Canadian law require business data to stay in Canada?
For some records it does. The Canada Revenue Agency says a business must keep its records at its place of business or residence in Canada unless the CRA gives written permission to keep them elsewhere. PIPEDA does not prohibit sending personal information outside Canada for processing, and the business stays accountable for it. Quebec requires a privacy impact assessment and a written agreement before personal information leaves the province. Customer contracts can set stricter terms. This is not legal advice.
Does storing data in Canada protect it from the US CLOUD Act?
Not by itself. The CLOUD Act requires a provider to disclose data in its possession, custody, or control regardless of whether the data is located within or outside of the United States. A Canadian region keeps the data in Canada, and US authorities can still order a provider subject to US law to produce it. The Government of Canada's Digital Sovereignty Framework says using a Canadian supplier or storing data in Canada does not guarantee data will be outside the jurisdiction of foreign courts.
What does Quebec's Law 25 require before data leaves Quebec?
Since September 2023, section 17 of Quebec's private-sector privacy act requires a privacy impact assessment before personal information is communicated outside Quebec. The assessment weighs how sensitive the information is, what it will be used for, how it will be protected and the law where it is going. The transfer then needs a written agreement, and the same applies when someone outside Quebec keeps the information for you.
Is data sovereignty the same as sovereign AI?
The two overlap. Data sovereignty is about stored data: where it sits and whose law reaches it. Sovereign AI adds the AI model: where it runs when it reads your data, and who operates it. ThriveAI's guide to sovereign AI covers models, compute and Canada's AI programs.

Contact

Know where your data sits before AI reads it

Tell Derik which records your AI would read and which customer contracts apply to them. He will tell you where each copy would sit and whose law could reach it.

Prefer to talk? Book a meeting.

Your message goes to Derik Lawlis, the founder.