Data Residency vs. Data Sovereignty: The Difference That Matters

Your AI vendor promises "Canadian data residency." That sounds like protection. Under a US law called the CLOUD Act, it often isn't, and the gap between those two words is quietly becoming one of the most important questions a Canadian business can ask before signing an AI contract.
This isn't a new problem, but it's a louder one this year. The federal government's Digital Sovereignty Framework, published in late 2025, and Budget 2024's roughly $2 billion Sovereign AI Compute Strategy both exist because Ottawa has concluded that "our data lives in a Canadian data centre" was never the same guarantee as "our data is beyond a foreign government's reach." If your business runs AI tools on infrastructure owned by a foreign company, the same distinction applies to you.
Two different questions, wearing the same name
Data residency and data sovereignty answer different questions, and vendors benefit when you conflate them. Residency is geography: where is the server, physically, that stores your data? Sovereignty is jurisdiction: whose laws govern that data, and which government can force it out of the vendor's hands?
A data centre in Toronto or Montreal, owned by a US corporation, satisfies residency. It does not satisfy sovereignty. The company operating that building answers to US law regardless of the postal code on the front door, because US law reaches its own companies wherever they keep their servers.
Even Canada's own government has said this plainly. A Treasury Board white paper on cloud data sovereignty put it this way: "regardless of where the cloud resources are physically located, when data is stored in a cloud environment, the stored data may be subject to the laws of other countries." That sentence was written years before generative AI became a procurement line item, and it's more relevant now than it was then.
The law that changed the answer: the US CLOUD Act
The Clarifying Lawful Overseas Use of Data Act, known as the CLOUD Act, is why "sovereignty" stopped being an abstract policy term and became something worth checking in a vendor contract. The US signed it into law on March 23, 2018, folded into a larger federal spending bill after starting out on its own as H.R. 4943.
The CLOUD Act allows a US warrant to compel a company to hand over data "regardless of whether such communication, record, or other information is located within or outside the United States." It doesn't matter whether the servers sit in Toronto, Dublin, or Singapore. If the company holding the data answers to a US court, so does the data.
Two points matter most if you're evaluating a vendor. The rule isn't limited to companies headquartered in the US. It covers any provider that operates or has a legal presence there, and a US court can order a US parent company to produce data held by its foreign subsidiary, even if that subsidiary is Canadian. The law also lets the US sign bilateral agreements with allied governments for faster data sharing, skipping the older, slower treaty process entirely. The UK signed one of these in 2019, and British police now use it routinely. Canada has not signed an equivalent agreement, so Canadian investigators (and Canadian businesses relying on Canadian channels) are still stuck with the slower process.
The law exists because of a real dispute over a customer's emails. In 2013, the FBI wanted messages stored on a Microsoft server in Dublin Ireland, and Microsoft refused, arguing a US warrant couldn't reach data kept overseas. The dispute climbed all the way to the Supreme Court as Microsoft Corp. v. United States. It never got decided on the merits. Once the CLOUD Act passed in 2018, the US government simply obtained a fresh warrant under the new law, and the Supreme Court dismissed the original case that April. Congress had already settled, by statute, the question the courts were still arguing over.
The admission that ended the debate
In June 2025, a French Senate inquiry got the clearest answer yet, straight from the vendor's own mouth. Anton Carniaux, Microsoft France's Director of Public and Legal Affairs, testified under oath that Microsoft could not guarantee French customer data would stay beyond the reach of US authorities, including data held in the "sovereign cloud" tier Microsoft built specifically to satisfy European privacy law. Pressed on whether Microsoft could rule out a CLOUD Act disclosure happening without a French court ever knowing, he could not say yes.
Microsoft has spent real marketing budget telling European and Canadian customers that a local or "sovereign" cloud tier solves this problem. Its own legal counsel just confirmed, on the record and in front of a national legislature, that corporate ownership beats server geography every time a US warrant shows up.
Public case names for this kind of disclosure are rare on purpose. Most CLOUD Act warrants arrive as sealed criminal orders, and the companies served are barred from discussing them individually. What surfaces instead is aggregate: Microsoft and Google both acknowledge, in their own transparency reporting, receiving large volumes of US warrants each year that reach accounts held outside the US, without naming a single one. The absence of a public case list naming a Canadian business is not evidence the tool sits unused. It is evidence of how quietly it is designed to operate.
Canada is done pretending residency alone is enough
Canada's own procurement guidance flagged this risk long before AI made it urgent. The same Treasury Board white paper that defines the residency-sovereignty split names the primary threat plainly: US intelligence and law enforcement authority reaching Canadian government data "regardless of the data's location and without notifying Canada." Its recommended fixes from that era still hold up: encrypt data and keep the keys in Canadian hands, and use standard contract clauses that force a vendor to disclose any government access request unless a foreign gag order forbids it.
The 2025 Digital Sovereignty Framework commits the federal government to rewriting procurement contracts around exactly those principles: control over sub-processors, transparency on foreign access, and jurisdiction that doesn't quietly shift the moment data crosses a corporate ownership line rather than a border. Budget 2024's Sovereign AI Compute Strategy backs that policy with money, funding a Canadian-owned supercomputer and co-investment in domestic AI data centre capacity so that "Canadian" eventually means Canadian-controlled, not just Canadian-hosted.
British Columbia took the opposite, older approach for its own public bodies: strict residency, full stop, personal information stored and accessed only from inside Canada under FIPPA. That rule protects against some risks well. It does nothing about a Canadian-hosted server owned by a company that answers to a foreign court, which is precisely the gap Ottawa's newer sovereignty language is trying to close.
What this means for your business
If you supply goods or services to a government agency, check your contract for the word "sovereignty," not just "residency." Some public sector and regulated contracts now spell out a sovereignty requirement explicitly, control over the vendor itself, not just the location of the data centre. If that language isn't in your contract, don't assume it's implied. Ask the contracting authority directly.
For most private businesses, residency is still the standard you're held to today. Neither BC PIPA nor PIPEDA currently requires full data sovereignty from private organizations. Storing personal information in a Canadian data centre generally satisfies what both laws expect right now. The problem isn't that residency stopped being good enough. It's that a lot of businesses assume they have residency when they don't.
That gap usually opens through sub-processors, not through the vendor whose name is on the contract. An AI tool can have a Canadian front end and still call a model hosted in the US behind the scenes, moving personal information across the border with every query. If your business handles personal information, confirm residency holds end to end, including whatever model or API the tool calls in the background. If it doesn't, and often it won't, that fact belongs in your own privacy policy and terms of service. Name your sub-processors, and say plainly where customer data goes. Staying silent on that point is now a more common privacy failure than anything the CLOUD Act does.
A short list of questions worth asking any AI vendor before you sign or renew:
- Who owns the company, and where is it incorporated? A Canadian office doesn't tell you who the parent company answers to.
- Who are the sub-processors, and where do they sit? This is the question that determines whether your residency claim is true.
- What happens if the vendor receives a foreign government request for your data? A contract clause requiring notice (except where the vendor is legally gagged) at least creates friction and a paper trail.
- Can you encrypt with keys you control? Customer-managed encryption, sometimes called BYOK, keeps the decryption key out of the cloud provider's hands entirely. Served with a CLOUD Act warrant, the provider can only hand over unreadable ciphertext, which is a real mitigation against this risk.
- Does the data need to leave the building at all? For your most sensitive material, client trust records, health information, anything covered by solicitor-client privilege, an on-premises or Canadian-owned option may be worth the extra cost, even if it's less convenient than the big-name cloud tool everyone already uses.
Most Canadian businesses will keep using US-based AI vendors, and for routine work that's a manageable risk under current Canadian privacy law. What changes is the standard of care: verify residency instead of assuming it, and tell your own customers, plainly, where their data sits.
This article is general guidance, not legal advice. Consult a qualified professional for decisions specific to your business.
If you don't know which laws govern your customer data once it leaves your building, that's exactly the kind of gap Evolutie's AI Risk X-Ray is built to find, a structured look at the AI tools and vendors you're using, where their infrastructure and sub-processors sit, and what that means for your obligations under PIPEDA and beyond.
Sources: Government of Canada, "White Paper: Data Sovereignty and Public Cloud," Treasury Board Secretariat; the CLOUD Act (Pub. L. 115-141, Div. V); Microsoft Corp. v. United States, U.S. Supreme Court (vacated April 17, 2018); In re Grand Jury Proceedings (Bank of Nova Scotia), 11th Cir., 1984; Ontario Court of Justice production order re: OVHcloud, September 25, 2025; French Senate inquiry testimony of Anton Carniaux, Microsoft France (June 2025); UK-US CLOUD Act Agreement (in force 2022); Government of Canada Digital Sovereignty Framework (2025); Budget 2024 Sovereign AI Compute Strategy.