Canadian sovereignty is more important than ever, and sensitive government data compliance is at the heart of it. If we aren’t in control of who can access our data, we don’t truly own it—and that can put our national economy at risk.
To provide better services in today’s digital world, Canada’s public sector is collecting growing amounts of citizen data—often while interacting with other countries. How do we keep this data secure from foreign interference, hackers, and unauthorized access? The Canadian government enforces strict laws to protect sensitive information from outside threats, and for public sector organizations, this means staying compliant with Protected B standards under Canada’s Privacy Act.
A sovereign cloud offers a powerful way to protect and govern sensitive data securely within Canadian borders. However, not all “sovereign clouds” are truly sovereign. Some foreign-owned providers claim compliance with Canadian law but may still be compelled to share data with foreign governments, putting your organization’s regulatory compliance and security at risk.
As CIO Magazine explains: “If data stays in Canada, local privacy laws apply to personal information. But that control may be lost once data slips outside the border.”
What is sensitive government data?
Sensitive government data is information that, if compromised, could lead to serious harm. Think of it as highly confidential details about a person, organization, or government—like contact information, financial records, medical history, or even tax and pension details. It’s the kind of data that needs extra layers of security to keep it safe.
When it comes to sensitive government data, there are two important federal guidelines that must be understood by public service organizations:
- Compliance requirements provide strict guidelines for managing sensitive government information that, if compromised, could result in serious harm to citizens or government. The framework covers confidentiality, integrity, and availability requirements for cloud services and guidelines for protecting sensitive data like personal medical records or financial information.
- The IT Security Risk Management (ITSG-33) standard outlines required security controls for government services handling sensitive information. Public service organizations must follow this guide to ensure that systems are designed to meet federal standards for confidentiality, integrity, and availability of sensitive data.
It’s important to recognize that public sector organizations are liable for cloud security, and while cloud service providers do offer some security measures, the onus is on the department collecting the data to secure it—as stated by the Government of Canada, “GC departments and agencies using cloud services remain accountable for the confidentiality, integrity, and availability of the GC information systems and related information hosted by the cloud service provider.”i
Sovereign cloud: Keeping your data safe and secure on Canadian soil
Why is data sovereignty such a big deal for data security? Think of it this way: a sovereign cloud is like keeping your most sensitive documents locked in a safe on Canadian soil, with no foreign keys floating around. With a true sovereign cloud, all your data—metadata, backups…everything—stays right here in Canada, protected from foreign jurisdiction claims and meeting Canadian data sovereignty laws.
This is more than just a nice-to-have; it means that your data isn’t subject to foreign laws or handled by offshore contractors who could be forced to share it with other governments or third parties. It’s like having a passport that only works within our borders—safe, secure, and fully in line with Canadian data protection requirements.
CIO Magazine points out the difference between data stored in Canada, and data managed only within Canadian borders: “If data stays in Canada, local privacy laws apply to personal information. But that control may be lost once data slips outside the border.”ii
Why data residency isn’t enough: The realities of cloud security
Those large, household-name hyperscale cloud providers are all US owned businesses. They may tell you that your data is safe within Canadian borders, but data residency is not enough to protect your sensitive information. Here are some factors to consider:
- The CLOUD Act can compel any US company, including US-based CSPs to turn over your data to the US government, regardless of where that data is stored.
- Data is nomadic. It moves around a lot, traversing borders from data centre to data centre on its way to its destination. Even if your data is stored in Canada and its ultimate destination is in Canada, it could jump borders on its way, exposing your data to foreign intervention.
- Data supply chains can be complex, and not all CSPs are transparent about who is managing your data, where they are located, and what their authorization level is to access your data.
Data governance: Going beyond data residency for true sovereignty
Storing data in Canada is an important first step in securing data sovereignty, but to meet government privacy and protection standards, public sector organizations need comprehensive data governance frameworks for handling sensitive data. This includes adherence to the ITSG-33 standards and secure management of complex data supply chains.
When data is stored, managed, and accessed only by Canadians, the risk of foreign interference is considerably lessened. To ensure that foreign governments can’t access sensitive Canadian data, you need a sovereign cloud, one that’s owned and operated only by Canadians within Canada.
It’s like locking your front door (storing data in Canada) and then hiring a trusted neighbor (data governance frameworks) to keep watch, making sure no unwanted visitors (foreign governments) can get in!
Ensuring compliance: Key requirements for a Canadian sovereign cloud
Canada’s Digital Privacy Act lays out strict guidelines for data management and defines the requirements for a Canadian sovereign cloud. Public service organizations must critically evaluate sovereign cloud offerings and claims, in order to make sure they’re getting the cloud security and regulatory compliance services they need.
To secure Canadian data, a sovereign cloud solution must be:
- Built on trusted code (instead of vulnerable open source) to meet specific Canadian security requirements.
- Certified to industry-recognized standards for information security management systems.
- Deployed on self-service micro-segmentation and zero trust access to protect data.
- Based on a common security policy framework for consistent security.
- Equipped with the capability to encrypt data at rest and in transit with customer-owned encryption keys.
Sensitive government data and regulatory compliance: At rest, at work, or on the move
Did you know that the Canadian government provides authorization to select cloud service providers who meet their rigorous standards for data governance?
As the only Canadian-owned cloud provider authorized to handle data requiring enhanced protection measures, ThinkOn remains at the forefront of delivering secure, compliant, and innovative solutions for the public sector. We also support workloads from all levels of municipal, federal, and Indigenous government public sector entities across Canada, including healthcare, education, defence, and policing. With our extensive experience and trusted reputation, ThinkOn is the perfect choice for public sector data management.
ThinkOn sovereign cloud: VMware certified and government secure
Concerned about the security of domestic data in the countries they serve, VMware developed a sovereign cloud certification initiative with stringent data management standards, which requires proof of a sovereign data supply chain, ITSG-33 compliance, and increased security and data governance.
ThinkOn was the first Canadian CSP to be selected—one of only a few in-country leaders worldwide—to be part of the VMware Sovereign Cloud initiative—a distinction reserved only for companies that can address data sovereignty requirements encompassing everything from where data resides to how it is stored, serviced, and shared.
As a Canadian VMware Sovereign Cloud partner, ThinkOn delivers cloud infrastructure specifically designed for public sector needs, ensuring security, transparency, and regulatory compliance. This makes it ideal for Canadian government entities looking to safeguard sensitive information.
What steps is your organization taking to ensure the security and compliance of your sensitive data?
Learn more about ThinkOn Sovereign cloud here.
[i] Government of Canada Security Control Profile for Cloud-based GC Services. https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/cloud-services/government-canada-security-control-profile-cloud-based-it-services.html
[ii] CIO. 2022. Emily Jackson. “What every Canadian CIO needs to know about data sovereignty.” https://www.cio.com/article/305461/what-every-canadian-cio-needs-to-know-about-data-sovereignty.html
