Jul 23, 2026 | Blogs, Resources

CLOUD Act in Canada: The Foreign Actors Lurking in Your Cloud Provider’s Supply Chain

John Slater, Chief Security Officer at ThinkOn

TL:DR: The CLOUD Act is the reason a foreign-owned cloud provider can look entirely Canadian and still answer to foreign law. It lets a foreign government compel access to your data regardless of where that data physically sits — no matter how Canadian the storage location looks on paper. Data residency (where data sits) is not the same thing as data sovereignty (whose laws govern it) — 2025’s €530 million TikTok fine, for remote access from staff outside the EU, is a fresh reminder of exactly how that gap gets exploited. Canadian organizations, especially in the public sector, need a provider that’s 100 percent Canadian-owned, with no foreign ownership or hidden subprocessors in its supply chain.

Your cloud provider might look Canadian on paper. The real question is whether the CLOUD Act — or a law like it — gives a foreign government a legal path to your data anyway. Compliance rules move fast, but most organizations’ biggest blind spot isn’t the provider they signed a contract with — it’s who sits behind that provider in the supply chain, and which country’s laws that provider ultimately answers to. Everyone knows to guard against bad actors, foreign and domestic. Far fewer know that the CLOUD Act alone can undo an otherwise airtight Canadian data residency setup.

Three US-based hyperscalers control roughly 85 percent of Canada’s public cloud market, and more than 60 percent of the global market — concentration that makes provider ownership, not just data location, the deciding factor in data sovereignty.

The structural problem is ownership, not geography. Every foreign-owned cloud service provider (CSP) uses offshore resources to store and manage data, and the three largest hyperscalers — Amazon, Microsoft, and Google — still command more than 60 percent of the global cloud computing market between them. In Canada specifically, that concentration runs even higher: three US companies control 85 percent of Canada’s public cloud market. Storing data “in Canada” on a foreign-owned platform doesn’t erase that platform’s home-country legal obligations. Once a provider is subject to a law like the CLOUD Act, that exposure travels with the company, not the data centre.

The fix is ownership-based sovereignty, not just in-country residency. A cloud provider that’s domestically owned, with no foreign parent and no foreign-law obligations, closes the gap that residency alone can’t. That’s the model ThinkOn’s Canadian Sovereign Cloud is built on.

Glossary

  • Data sovereignty — the principle that data is subject only to the laws of the country where it is collected, stored, and processed.
  • Data residency — the physical location where data is stored, independent of which country’s laws govern it.
  • CLOUD Act — a US law that lets US law enforcement compel US-based or US-owned providers to disclose data in their possession, custody, or control, regardless of where that data is physically stored.
  • GDPR (General Data Protection Regulation) — the European Union’s data protection law, with fines of up to €20 million or 4 percent of global annual revenue for violations.
  • Bill C-36 (Protecting Privacy and Consumer Data Act) — federal legislation introduced June 15, 2026, to replace PIPEDA as Canada’s private-sector privacy law. Still at first reading, so not yet in force; PIPEDA remains the law of record for now.
  • Shared Services Canada (SSC) — the federal department that manages IT infrastructure procurement for the Government of Canada, including approval frameworks for secure cloud workloads.
  • Hyperscaler — a large-scale cloud provider (e.g., AWS, Microsoft Azure, Google Cloud) offering globally distributed infrastructure.
  • Sovereign cloud — a cloud environment operated by a domestically owned provider, built to comply with local privacy and data protection laws without foreign ownership or foreign legal exposure.

That distinction matters because compliance obligations follow legal jurisdiction, not server location. A cloud provider can store your data inside Canadian borders and still be legally required to disclose it to a foreign government, if that provider itself is foreign-owned. True data sovereignty requires both the data and the company managing it to sit outside foreign legal reach.

Can foreign governments access data stored in Canadian cloud data centres?

Yes, if the provider is foreign-owned: laws like the US CLOUD Act let foreign governments compel access to data regardless of where it physically sits.

This isn’t a hypothetical, and it isn’t only a US problem. In May 2025, Ireland’s Data Protection Commission fined TikTok €530 million after finding that personnel outside the EU could remotely access European user data, and that some of that data had, in fact, ended up stored on servers in China — despite the company’s own policies and evidence saying otherwise. Storage location and stated policy are not the same thing as enforceable protection.

What is the difference between data residency and data sovereignty?

Data residency means data is stored in a specific country; data sovereignty means that country’s laws — and only that country’s laws — govern it.

Data residency requirements in Canada are usually the easiest box for organizations to check — and, increasingly, the least sufficient one on its own. A foreign-owned provider can offer data residency (a Canadian data centre) without offering data sovereignty (freedom from foreign legal obligations). Public-sector buyers, in particular, need to evaluate both criteria separately, because RFPs that only specify “data must stay in Canada” can still be satisfied by a provider that remains legally exposed to a foreign government.

ThinkOn CEO Craig McLellan put it directly when ThinkOn was selected to power Canada’s national sovereign AI platform in 2026: “Data residency and data sovereignty are not the same thing. Too many Canadian organizations confuse the two, assuming that because their data is housed in a Canadian facility, it is under Canadian control. That is not the case unless the infrastructure itself is Canadian-owned, Canadian-operated, and accountable under Canadian law.”

Does the CLOUD Act apply to Canadian cloud data?

It can: if a cloud provider is US-based or US-owned, the CLOUD Act lets US law enforcement compel data disclosure regardless of storage location.

The CLOUD Act in Canada is one of the most misunderstood parts of this picture, and it comes up in nearly every public-sector procurement conversation we have. According to the US Department of Justice, the CLOUD Act “amends U.S. law to make clear that law enforcement may compel U.S.-based service providers to disclose data that is in their possession, custody, or control” — regardless of where that data is located. Microsoft’s own transparency reporting shows how often this happens in practice: in the second half of 2025 alone, it received 5,587 legal demands for consumer data from US law enforcement, and 115 of those warrants sought content stored outside the United States. ThinkOn is not subject to any foreign data access or privacy regulations outside of Canada. Only Canadian laws apply to the data we host within Canadian borders. This ensures complete sovereignty and protection for your information.

That’s the general mechanic. For the fullest breakdown of how it applies to Canadian organizations specifically — and why a Canadian data centre alone doesn’t close the gap — see ThinkOn’s Data Residency ≠ Data Sovereignty deep dive. This post’s focus is narrower: even once your primary provider’s ownership is settled, who else sits behind them in the supply chain?

How does virtual private cloud help with compliance and data sovereignty?

A sovereign virtual private cloud lets organizations keep regulated or sensitive data on sovereign infrastructure while using public cloud for less sensitive workloads, balancing compliance and flexibility.

That’s how a sovereign VPC helps with compliance and data sovereignty for partners managing mixed environments: it limits channel risk, since sensitive client workloads stay on infrastructure the partner can vouch for, while less sensitive workloads keep the flexibility and cost efficiency of public cloud. That combination, rather than an all-or-nothing migration, is usually the realistic compliance path for both public- and private-sector clients — and it’s exactly how virtual private cloud solutions help with compliance and data sovereignty in practice: not a single migration decision, but an ongoing split between what has to stay sovereign and what doesn’t.

What certifications should Canadian organizations look for in a sovereign cloud provider?

Look for Canadian ownership, Shared Services Canada approval, VMware sovereign cloud accreditation, and documented no-foreign-access guarantees backed by contractual commitments.

Where to assess cloud provider security posture and data sovereignty starts with ownership, not marketing copy. Ask directly: who owns the company, is it approved under the Shared Services Canada framework agreement for secure workloads, and can the provider name every partner in its supply chain with access to your data?

ThinkOn’s Canadian Sovereign Cloud is the only cloud service provider approved under the Shared Services Canada framework agreement for secure workload, adheres to VMware Sovereign Cloud Initiative specifications, and is 100 percent Canadian-owned and Canadian-staffed. Broadcom named ThinkOn its 2025 VCSP Sovereign Cloud Partner of the Year for the Americas, the VMware ecosystem’s own recognition of that ownership and compliance model.

See what ownership-based sovereignty delivers in practice — 40+ federal departments, four government data centres, Secret-cleared Canadian staff, CLOUD Act exempt.


  • 2025 VCSP Sovereign Cloud Partner of the Year, Americas — award granted to ThinkOn by Broadcom (VMware’s parent company), recognizing its sovereign cloud compliance model.
  • 85 percent — share of Canada’s public cloud market controlled by three US companies (ThinkOn analysis, June 2026).
  • More than 60 percent — combined share of the global cloud computing market held by Amazon, Microsoft, and Google.
  • €530 million — fine issued to TikTok by Ireland’s Data Protection Commission in May 2025, for EU user data being remotely accessed from, and in some cases stored in, China.
  • 5,587 — legal demands for consumer data Microsoft received from US law enforcement in the second half of 2025; 115 sought content stored outside the United States.
  • 32 percent — share of those US legal demands that arrived with a secrecy order attached, meaning the customer was never notified.
  • More than €600 million — GDPR fines issued across the EU in the first half of 2026 alone, on top of €1.2 billion issued in 2025.
  • Up to $25 million CAD or 5 percent of global revenue — proposed maximum penalty under Canada’s Bill C-36, tabled June 2026 to replace PIPEDA. Not yet law; still at first reading.

Irish Data Protection Commission, “Irish Data Protection Commission fines TikTok €530 million…”, May 2, 2025

Statista, “Big Three Dominate the Global Cloud Market”

US Department of Justice, “The Purpose and Impact of the CLOUD Act”

Microsoft, Government Requests for Customer Data Report

CMS Law, GDPR Enforcement Tracker Report 2025/2026

Innovation, Science and Economic Development Canada, “Government of Canada introduces legislation to protect Canadians’ privacy in the digital age”, June 2026

ThinkOn, “ThinkOn Selected to Power Canada’s Sovereign AI Platform”, 2026

Broadcom, “Broadcom 2025 VMware Cloud Service Provider Partner Awards”

Connect on Social