Data sovereignty is the principle that data is subject to the laws of the country in which it is physically stored and in which the company controlling it is legally domiciled. For Canadian businesses, this means your hosting choice has direct legal consequences, not just technical ones.
The US CLOUD Act and why it affects Canadian businesses
The Clarifying Lawful Overseas Use of Data Act, passed in 2018, allows US law enforcement agencies to compel US-based companies to produce data stored anywhere in the world. The key phrase is US-based companies. If your hosting provider is incorporated in the United States, or is a subsidiary of a US company, a valid US legal order can require them to produce your data without notifying you and without going through the standard international legal assistance process.
This applies even if the servers are physically in Canada. AWS Canada, Microsoft Azure Canada, and Google Cloud Canada are all operated by US corporations. Data stored in those Canadian regions is legally accessible to US authorities under the CLOUD Act. The physical location of the hardware is less important than the legal domicile of the company operating it. This is not a hypothetical scenario. US authorities have used predecessor statutes for cross-border data access for years, and the CLOUD Act formalized that capability explicitly.
What PIPEDA requires when data crosses borders
PIPEDA does not prohibit transferring personal information outside Canada, but it requires that organizations take reasonable steps to ensure that third parties handling the information provide comparable privacy protection. The question of whether a US cloud provider under CLOUD Act jurisdiction provides protection comparable to PIPEDA is genuinely difficult to answer in the affirmative. The Privacy Commissioner of Canada has noted in guidance documents that organizations transferring data to the US should be aware of the CLOUD Act's implications and should ensure their privacy disclosures inform users of that exposure.
What genuine data sovereignty actually requires
Three things need to be true simultaneously. First, the hardware must be physically located in Canada. Second, the company operating that hardware must be incorporated in Canada and not be a subsidiary of a foreign company subject to foreign compulsion laws. Third, the contractual relationship between you and the hosting provider must be governed by Canadian law. All three conditions. A Canadian data centre operated by a US company satisfies the first condition and fails the other two. That is not data sovereignty in any meaningful sense.
Canadian-owned and operated hosting providers that maintain their own physical infrastructure in Canada are the only clean solution. Gotekky is one of them. Canadian-owned, incorporated in Canada, operating its own hardware in Toronto under Canadian law, and not a subsidiary of any US parent company. For businesses that need to clearly articulate data sovereignty in a compliance document, that distinction matters.
Provincial considerations beyond PIPEDA
Quebec's Law 25 adds requirements beyond PIPEDA for businesses operating in Quebec, including mandatory Privacy Impact Assessments for transfers outside Quebec and specific contractual requirements for third-party data processors. Ontario's PHIPA applies to healthcare information custodians. Alberta's Personal Information Protection Act and British Columbia's Personal Information Protection Act are deemed substantially similar to PIPEDA and apply to provincially regulated activities in those provinces. For businesses operating nationally, PIPEDA is the primary framework but provincial laws may add requirements layered on top.
Regulated industries where this is not optional
Legal professionals have solicitor-client privilege obligations that extend to where client data is stored. Healthcare organizations in Ontario are subject to PHIPA and the guidance of bodies like the College of Physicians and Surgeons regarding data handling. Financial services firms are subject to OSFI guidance on data management and third-party risk. Federal contractors handling government data may be subject to Treasury Board policy requirements regarding data residency. For businesses in any of these sectors, Canadian data sovereignty is a compliance requirement, not a preference. For everyone else, it is a reasonable risk management decision and an increasingly meaningful trust signal with clients who are aware of where their data goes.
Gotekky
Need help deciding what to do next?
Tell us what you are seeing and what outcome you need. We will identify whether a managed service, scoped project or paid technical assessment is the right next step.