Sovereignty Is Not a Postal Code - CTV News
CTV ran a piece this week about Canadian companies building data sovereignty. The reporting is solid and the people quoted are right about the problem. Our lives went digital, the data went to the…
CTV ran a piece this week about Canadian companies building data sovereignty. The reporting is solid and the people quoted are right about the problem. Our lives went digital, the data went to the cloud, and the cloud turned out to be in Virginia. Carmi Levy calls data sovereignty maybe the most important technological issue of our time. He may be correct.
I want to add one uncomfortable thing the article leaves out.
Everyone interviewed treats sovereignty as a question of geography. Where does the cloud physically sit. Is the company that owns the building Canadian. Is it on the federal procurement vehicle. ThinkOn's CEO is quoted saying his is the only Canadian company on that vehicle and the rest are American, and that there should be more of them. He is right on both counts. We need more domestic providers. The money should stay here.
But residency and sovereignty are not the same thing. They get used as synonyms and they are not.
Residency is a fact about location. Your data sits on a server inside Canadian borders. Good. Necessary. Insufficient.
Sovereignty is a fact about control. It is the answer to a different question: who can compel access to the plaintext, and can they do it without telling you.
Here is why the distinction matters. A Canadian-owned data centre full of Canadian servers is still running software. That software has an orchestration layer, a key management system, a support rotation, a vendor supply chain. If the encryption keys are held somewhere a foreign legal order can reach, the building's nationality is decoration. If the management plane phones home, the flag on the roof is decoration. The CLOUD Act and FISA Section 702 do not care where the disk is. They care who controls the entity that controls the data. Storing the bytes in Nepean does not change which company can be served a warrant in a Delaware courtroom.
The CTV article itself contains the proof. It cites a Canadian fighting the U.S. Department of Homeland Security to stop it pulling his personal information out of Google. The data was Google's to hand over. Where it physically lived never entered into it.
So when a provider tells you they are sovereign because they are Canadian-owned and Canadian-located, ask the second question. Where are the keys. Who holds them. Can the operator read my data if compelled to. If the honest answer is yes, what you bought is residency. You can have residency and still have no sovereignty at all.
This is not an argument against the companies in the article. Domestic infrastructure is the floor. You cannot have sovereignty without it. I am arguing that we have been celebrating the floor as if it were the building.
The real version is architectural, not geographic. It looks like data that is encrypted before it is ever written, sharded across jurisdictions so no single location holds a recoverable copy, with keys the operator structurally cannot access. Under that model the warrant produces ciphertext. The support technician sees ciphertext. The subpoena to the parent company produces ciphertext. Sovereignty stops being a promise about corporate citizenship and becomes a property of the math. The provider cannot betray you because the provider was never able to.
That is a higher bar than the procurement checklist measures, and most of the market is nowhere near it. That is fine, for now. We are early. But if Canada is going to spend the next decade and a great deal of money building sovereign infrastructure, we should be honest at the start about what we are buying. Otherwise we will pour billions into Canadian-flagged data centres, congratulate ourselves on the postal codes, and discover the first time a foreign court tests it that the data was reachable the whole time.
Get the foundations right before you scale. Residency is the foundation. Do not mistake it for the house.
Data centres: Canadian companies building data sovereignty
Bias declaration: I build a data sovereignty platform, so I have a commercial interest in the distinction I am drawing here. I would rather disclose that than pretend I am a neutral observer. The argument stands or falls on its own merits — judge it on those, not on my motives. Link in comments.
Originally published by Ross Norrie, founder of SkyeConnex, on LinkedIn.
Published May 20, 2026 · More from the SkyeConnex blog
More from the blog
Reassurance Is a Fine Product. It Shouldn't Cost the Same as Proof
Data Sovereignty 2026: Reality, Relevance, and the Bit Where You Find a Budget
BARC just published their second annual Data Sovereignty survey. 320 enterprises across Europe, North America, and the…
Read → Regulation · 2 min readEurope Has the Cards. It Has Always Had the Cards.
There is a Thierry Breton op-ed about European digital sovereignty roughly every eighteen months. The metaphor changes…
Read → Commentary · 4 min readSovereignty is not a configuration option
A new paper in Media, Culture & Society makes a clean argument: Microsoft, AWS, and Google have rebranded…
Read →