Data sovereignty has four dimensions. Your provider may only cover one.
Ask five executives what they mean by data sovereignty. Yet you will get five answers. The first one thinks of a server in Montreal. For the second, it means compliance with Law 25. The third wants a Quebec provider. The fourth thinks of cybersecurity instead. As for the fifth, he hasn’t decided yet.
None of them is wrong. But none of them has the whole answer.
The term has made its way into calls for tenders, cloud brochures and board meetings. Yet no one has given it a common definition. A provider can therefore call itself sovereign because its servers are in Canada. Its parent company, however, may still answer to a foreign law such as the CLOUD Act, which forces it to hand over your data on request.
In my view, data sovereignty is a level of control. More precisely, that control is measured along several axes.
What are the four pillars of data sovereignty?
At recent conferences, I was able to summarize the following four pillars. Each one answers a different question. In fact, the same provider can be strong on one and weak on another.
The four pillars of data sovereignty: location, operational, legal and technical sovereignty.
1. Data location: where is your data, and where can it go?
This is the pillar everyone knows, and the one most poorly assessed. Indeed, the question doesn’t stop at where the data is hosted. It also covers where the data travels and where it gets copied. You also need to know where the backups sit and where support access comes from. For example, a database hosted in Montreal but copied to Virginia for recovery does not stay in Quebec. Likewise, an event log sent to an American monitoring tool leaves Quebec.
2. Operational sovereignty: who runs the environment?
Your data can stay in Canada while teams located elsewhere manage it. Think of the people who run the servers and apply the patches. Also add those who handle support tickets and hold privileged access. All of them are part of the equation. Thus, an administrator access opened from abroad amounts to a transfer, even if not a single byte moves.
3. Legal sovereignty: which laws does your provider obey?
This is the most often ignored pillar, and the most decisive. The American CLOUD Act dates back to 2018. It requires any cloud provider subject to U.S. law to disclose the data in its possession, custody or control. In other words, it doesn’t matter whether that data is in the United States or elsewhere. The hosting location therefore changes nothing to that obligation. What matters is the legal regime that governs the provider and its parent company.
In June 2025, a French Senate commission of inquiry questioned the director of public and legal affairs of Microsoft France under oath. The senators specifically asked him for a specific guarantee. Could Microsoft commit to never sending French citizens’ data to the U.S. government without the consent of French authorities? His answer: “No, I cannot guarantee it, but, again, it has never happened.” (Translated from French.)
In fact, the answer is honest. But it also sums up the whole problem of data sovereignty.
4. Technical sovereignty: how much control do you keep?
The fourth pillar measures your ability to keep technical control over your data and services. It also assesses your ability to reduce your dependence on a provider.
Several questions help assess it:
- Who controls the encryption keys? Do you have real control over the keys that protect your data? Think in particular of their management, rotation and revocation.
- Can you get your data back? Can you export it in documented, common and machine-readable formats? If needed, can you also recover the metadata, configurations and other assets required for service continuity?
- Can you switch providers? Do you have an exit plan? Have you confirmed, through testing, that a migration to another provider is feasible? In fact, the ISO/IEC 19941 standard and ENISA name interoperability, portability and migration barriers as key issues in cloud computing.
Which pillar matters most for your organization?
The four pillars don’t carry the same weight for every organization. For an executive, the useful question is therefore about real exposure. On which pillars would a failure cost you the most?
You hold personal information
In this case, location and the legal pillar come first. Since September 22, 2023, section 17 of the Act respecting the protection of personal information in the private sector applies as amended by Law 25. It requires a privacy impact assessment (PIA) before any communication of personal information outside Quebec. That notably includes a cloud provider. The company may only share this data if the assessment concludes that protection is adequate. Moreover, a written agreement must govern this communication. Administrative monetary penalties can reach $10 million or 2% of worldwide turnover. As for penal fines, they can reach $25 million or 4%.
You protect industrial designs or processes
If you are a manufacturer protecting designs, processes or data entrusted to you by your customers, technical and operational sovereignty take over. For example, in defence, aerospace or energy, your customers may demand to know who accesses this data. They will also want to know from where.
You depend on a platform to operate
Whether it’s your ERP, your CRM or your phone system, the technical pillar becomes a matter of continuity and negotiation. After all, a provider that knows you can’t leave sets the renewal price.
You are adopting generative AI
Here, all four pillars of data sovereignty kick in at the same time. Take an employee who pastes a client contract into an AI assistant hosted abroad. They have just moved a piece of data and handed it to unknown operators. On top of that, they have placed it under a foreign jurisdiction and lost control over how it is processed. This is also what we see when your employees use AI without guardrails. I also explored this angle in a previous article, You’re renting someone else’s AI. In short, sovereignty now plays out at the moment AI processes the data, and no longer only where it is stored.
Classify before you demand
Absolute sovereignty doesn’t exist. Besides, it isn’t necessary for all your data. Your public website doesn’t have the same needs as an employee file or a process formula. The work therefore consists of classifying your data by sensitivity, then demanding the right level on the right pillar.
The benefits of data sovereignty
Treated as a compliance constraint, sovereignty costs money. On the other hand, treated as a decision criterion, it pays off.
- Data sovereignty makes compliance demonstrable. An assessment based on the four pillars holds up before the Commission d’accès à l’information. By contrast, a box checked “hosted in Canada” is not enough.
- It protects your negotiating leverage. Indeed, an organization able to migrate negotiates its renewals. One that can’t simply accepts them.
- It becomes a sales argument. Take a subcontractor or distributor that answers a vendor security questionnaire with precision. As a result, it stands out from those who reply with a brochure.
- It strengthens resilience. A known dependency can be planned for. Conversely, a dependency discovered during a crisis costs far more.
Quebec is also starting to structure the issue. The non-profit Données souveraines Québec, of which Eficio is a member, will publish its roadmap on October 13, 2026, at the Printemps numérique in Montreal. This document notably proposes a tiered sovereignty label. A fact-based audit will serve as the basis for this label, rather than a simple provider statement. All in all, the principle is sound: sovereignty is measured and demonstrated.
Assessing data sovereignty: a more complex decision than it seems
Assessing your sovereignty requires combining skills that rarely sit in the same team. First, the legal pillar falls under law and procurement. Then, the operational pillar requires understanding how a provider organizes its day-to-day support. As for the technical pillar, it calls on architecture and cybersecurity. Finally, location requires mapping data flows that no one has documented.
Then come the trade-offs. For example, a more sovereign Canadian provider sometimes offers fewer services than an American cloud giant, often called a hyperscaler. A hybrid architecture reduces exposure, but it adds operational complexity. Furthermore, large providers write their contracts to protect themselves. Meanwhile, so-called sovereign offerings are multiplying, and their definition varies from one vendor to the next.
These decisions involve senior management, not just the IT team. Indeed, they affect risk, contracts, compliance and the company’s ability to change course.
Our CIOs support executives in these choices, through fractional engagements or as part of a CIO360 assessment. In practice, they map your data and its flows. They also assess each of your providers on the four pillars and read the clauses that matter. Then, they build a roadmap with you. This roadmap places the right level of sovereignty where it protects the value of the business.
our sovereignty will be defined, by you or by your providers
Two options therefore remain. The first: define for yourself, pillar by pillar, the level of data sovereignty your organization needs. The second: let your providers define it for you, in contracts you didn’t write.
Classify before you host. Measure before you sign. Demand before you depend.
Frequently asked questions about data sovereignty
What is data sovereignty?
Data sovereignty is the level of control an organization keeps over its data, no matter where it is hosted. It is measured on four pillars: data location, operational sovereignty, legal sovereignty and technical sovereignty. Thus, a provider can be sovereign on one pillar and exposed on another.
Why doesn’t hosting in Canada guarantee data sovereignty?
Because location is only one of the four pillars. A provider whose parent company falls under U.S. law remains subject to the CLOUD Act. This law requires it to disclose data under its control, regardless of where that data sits. Furthermore, administrator access from abroad and backups copied outside the country create other exposures. A data centre in Montreal therefore solves location, but not the legal or operational pillar.
What is the difference between data location and legal sovereignty?
Location answers the question “where is the data?”. Legal sovereignty, for its part, answers the question “which law can force my provider to hand it over?”. However, the two can diverge completely. For example, data that an American provider hosts in Quebec is located here, but a foreign jurisdiction can access it. A serious assessment therefore treats the two separately.
What does Law 25 require before entrusting personal information to a cloud provider outside Quebec?
Since September 22, 2023, a company must conduct a privacy impact assessment before communicating personal information outside Quebec. This assessment considers, in particular, the sensitivity of the information and its purpose. It also considers the protection measures and the legal framework of the destination. The company may only share the information if protection is adequate. Finally, a written agreement must govern the communication.
How can I tell if my organization has lost its technical sovereignty?
Watch for three signals. First, you don’t hold your own encryption keys. Second, you couldn’t extract your data in a usable format without the provider’s help. Finally, a migration to a competitor would force you to rebuild your processes. Moreover, if your renewals keep rising with no real room to negotiate, the dependency is already in place.
Where should a data sovereignty initiative start?
With classification. Not all data requires the same level of sovereignty. Aiming for the maximum everywhere is costly without adding protection. You first classify data by sensitivity, then map its flows. After that, you assess each provider on the four pillars. Investments then target the data whose exposure threatens compliance, client contracts or business continuity. We would be happy to discuss it with you. Contact us.
Transparency: I wrote this article with the help of AI for research, structure and language editing.
Sources
- 18 U.S.C. § 2713 (CLOUD Act), Legal Information Institute, Cornell Law School
- French Senate, commission of inquiry on public procurement, hearing of June 10, 2025
- Public Safety Canada, briefing material on the CLOUD Act
- McCarthy Tétrault, Law 25 blog series
- ISO/IEC 19941:2017, Cloud computing, interoperability and portability
- DSQ non-profit website
Inscrivez-vous à l’infolettre Eficio et soyez le premier à recevoir notre actualité !