News & Knowledge


Posted on: Nov 24, 2025

Author: Tara Sarvnaz Raissi, Beneva

Introduction

Amid the wide-ranging shifts in Canada-US relations, data sovereignty - the legal right to assert authority over data - and its connection to data security has become a pressing concern for Canadians. The advent of artificial intelligence ("AI") underscores the importance of data sovereignty. Data used to train and deploy AI systems hosted on cloud infrastructure may be subject to foreign access and jurisdictional oversight. The cross-border flow of this data can influence how AI systems are developed, governed and regulated. 

Cloud providers supply the infrastructure that gives users access to storage, applications and computing resources online, eliminating the need for physical servers or local software. AI systems deployed in the cloud rely on this infrastructure to store data, train models, and deliver services over the internet. In a global cloud environment, laws from various countries may simultaneously apply to data.[1] While major US providers offer scalable, reliable and cost-effective cloud services, data stored in a cloud environment can be subject to foreign law, even if it stays in Canada.[2] For example, the US's Clarifying Lawful Overseas Use of Data Act (CLOUD Act), enacted in 2018, codified the principle that US law enforcement agencies can compel US-based cloud providers to produce data in their control - regardless of where that data is stored.

In response to emerging challenges to data security, the Federal government announced investments in Canadian controlled cloud and AI infrastructure to strengthen Canada’s digital protection and sovereignty.[3] While these solutions are in development and where options such as using Canadian owned providers to store data or maintaining data ‘on premise’ are not feasible, incorporating contractual provisions[4] that promote transparency in the handling of data requests, implementing data localization requirements, encryption and data access management can mitigate risk to Canadians’ data in the cloud.

Data Residency vs. Data Sovereignty

Cloud providers have the ability to move data across borders and clients have the option to isolate their data to “reside” in a specific geographic region. While this can help keep data under the laws of a particular jurisdiction, data residency does not guarantee data sovereignty.[5] The physical location of data is relevant in determining who governs it. However, ownership and control are equally important considerations. A provider with foreign operations may be legally required to comply with a warrant, court order or subpoena request from a foreign law enforcement agency. For example, pursuant to the CLOUD Act, if a provider is subject to US law, there is a possibility that Canadian data stored in data centres located in Canada could be accessed by US authorities under certain legal mechanisms. 

The CLOUD Act and Extraterritorial Reach

The CLOUD Act was enacted to modernize laws around access to digital data. Its passage settled a legal dispute about the extraterritorial reach of US law enforcement agencies. In July 2016, a US federal court ruled that law enforcement did not have the authority to compel Microsoft to release emails stored on a server in Ireland as part of a narcotics investigation.[6] In a direct response to this finding, the Act codified the principle that cloud service providers under US jurisdiction are required to comply with lawful warrants for information stored outside the US if the information is within the custody, control or possession of the provider. 

The CLOUD Act did not create new law enforcement powers. Instead, it extended established rules of evidence to digital data in cloud environments. Its authority is not absolute, nor does it grant unfettered access to data. The Act includes common law comity protections, which allow service providers to challenge US law enforcement data requests under the Act if compliance violates another country’s laws. Further, data requests pursuant to the Act require valid warrants that specify the type of data sought and establish probable cause of a criminal act within the jurisdiction of the US. As it stands, there is very little evidence that this Act has been used to compel the production of data stored in Canada by a US based cloud provider. 

The Act also permits the US to enter into reciprocal executive agreements with trusted foreign partners to facilitate obtaining data stored outside of the US during cross-border investigations of serious crimes.[7] While Canada has not yet finalized an agreement under this Act, if one is reached, it can provide additional safeguards for Canadians’ data.

Contractual and technical safeguards can mitigate (but will not eliminate) risk

When negotiating with cloud providers subject to foreign laws, robust contractual clauses are essential to maintain control over client data that impacts the performance, security and regulatory framework of AI systems. These measures include, but are not limited to, requirements that providers notify clients about foreign legal demands within specific timelines that are agreed upon by the parties. Providers must commit to challenge overly broad disclosures to protect client data to the extent possible. Warranties about data localization ensure data residency in keeping with a client’s preferred geographic location. Provisions of this nature clarify the parties’ responsibilities and promote transparency about how data requests are handled.

Technical safeguards such as encryption of sensitive data are important. If data is to be handed over, it cannot be decrypted without the keys that are typically managed by an organization or a neutral third party. While encryption provides a layer of security, certain legal requests may compel the organization to provide the keys. Deploying identity and data access management systems that control and audit access is also effective. 

Transparency, procedural clarity, and proactive oversight using contractual and technical controls can play an important role in supporting data security, particularly in environments where AI and cloud-based services process large volumes of data and navigate complex cross-border jurisdictional and compliance issues.

 

[1] Rojszczak, M. “CLOUD Act Agreements from an EU Perspective.” Computer Law & Security Review, vol. 38, 2020,

[2] Government of Canada. White Paper: Data Sovereignty and Public Cloud. Treasury Board of Canada Secretariat, 2018. Canada.ca, https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/cloud-services/gc-white-paper-data-sovereignty-public-cloud.html?utm_source=chatgpt.com.

[3] Thompson, Chris. “Canada Advances AI Policy with Focus on Digital Sovereignty and Quantum Computing: Government Outlines Sovereign Compute Plan and AI Adoption Strategy to Secure Data and Scale Innovation.” Economic Insights, 27 Sept. 2025, Analyst Articles, Security, Technology.

[4] Contractual provisions are generally subject to the laws of the local jurisdiction.

[5] Kimball, Bob. “Data Sovereignty vs Data Residency: Key Differences to Note.Aegis Cloud Services, 17 Mar. 2025, https://www.aegis.com.my/data-sovereignty-residency/

[6] Microsoft Corp. v United States, 829 F.3d 197 (2nd Cir. 2016).

[7] Kimball, Bob. “Five Facts About How the CLOUD Act Actually Works.” AWS Security Blog, Amazon Web Services, 22 July 2025, https://aws.amazon.com/blogs/security/five-facts-about-how-the-cloud-act-actually-works/

OUR MEMBERS SAY...

  • Engaging speakers who were knowledgeable about the topic from an educational and practical perspective.
  • Comment on TLA Educational Program
  • Thank you so much for your detailed and prompt assistance. I haven't had the opportunity to review all the attachments yet, but from a first quick review, they look very helpful. Thanks again!
  • Comment on TLA Legal Research Services
  • Hi all, the absolute privilege research your provided me stopped the matter in its tracks. We are now arguing about how much cost he will pay my client! Well done Toronto Library! Shawn M. Philbert B.A. (Hons.) JD, Lawyer
  • Comment on TLA Legal Research Services
  • Thank you kindly for your previous research a few weeks back. That assisted greatly with my pleadings. Robert McNeillie - B.A., LL.B., LL.M. Barrister & Solicitor, McNeillie Law Office
  • Comment on TLA Legal Research Services
  • Directly because of your excellent work and diligence in finding those cases, I was able to solve our issue and close the transaction. I am immensely grateful to you and appreciate your support more than I can possibly express.
  • Comment on TLA Legal Research Services
  • Engaging speakers who were knowledgeable about the topic from an educational and practical perspective.
  • Comment on TLA Educational Program
>
  • TLA Summer Hours
    (Jul - Aug)
  • Monday to Thursday:
    9:00 a.m. – 5:00 p.m.
    Friday:
    9:00 a.m. – 4:00 p.m.

  •