An IT quote for your business · Across Quebec Request a quoteFrançais

Guide

Digital sovereignty: what Quebec SMBs need to know

Short answer

For an SMB, digital sovereignty means keeping control of its data: where it is stored, which laws apply to it and who can access it. Hosting in Canada settles data residency, not the whole question. A provider subject to a foreign law, such as the US CLOUD Act, may have to disclose data it controls, even outside the United States.

This guide is for information only and is not legal advice. Consult your person in charge of the protection of personal information before communicating personal information outside Quebec.

Your email, files and business software are more and more often hosted by a cloud provider. For your IT, the question is no longer only where your data is, but also which laws apply to it and who can demand access to it. This guide explains the difference between data residency and data sovereignty, what the US CLOUD Act provides, what Quebec's Law 25 requires before personal information is communicated outside Quebec, and the questions to ask your provider.

What does digital sovereignty mean for an SMB?

On its digital sovereignty page (in French), the Gouvernement du Québec defines digital sovereignty as a government's ability to control and protect its digital infrastructure, technologies and data, particularly against the application of foreign laws. It also states what digital sovereignty is not: it is not national sovereignty, and it concerns only the control and protection of technologies, computer systems and data.

The definition is written for the State, but the idea applies to a business. For an SMB, keeping control of its data means being able to answer three questions:

  • Where? In which country, and in which province, your data and its backups are stored.
  • Under which laws? Which laws apply to your provider, in addition to those of the hosting location.
  • Who? Who can access the data, including the provider's technical support and the authorities that can send it a request.

Data residency or data sovereignty: what is the difference?

The Treasury Board of Canada Secretariat's white paper on data sovereignty and public cloud (2018) separates the two concepts. Data residency is "the physical or geographical location of an organization's digital information." In relation to Canada, data sovereignty is "Canada's right to control access to and disclosure of its digital information subject only to Canadian laws."

Data residencyData sovereignty
Question askedWhere is the data?Which laws apply, and who can demand access?
What determines itThe hosting region chosen, including the region for backupsThe laws the provider is subject to, the contract and control of the encryption keys
Its limitAccording to the white paper, "data residency does not mitigate against the application of foreign laws"According to the white paper, the issue is complex and continuously evolving as foreign laws are being tested in foreign courts

Choosing a Canadian region with your cloud provider therefore settles residency. Sovereignty also depends on the provider itself.

Is data hosted in Canada beyond the reach of foreign laws?

Not necessarily. The US CLOUD Act, enacted on March 23, 2018, added section 2713 to Title 18 of the United States Code. That section provides that a provider of electronic communication service or remote computing service must preserve, back up or disclose the contents and records pertaining to a customer that are within its "possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States."

The text targets the provider, not the place where the data is hosted. The federal white paper makes the same point: a cloud service provider with foreign operations could be required to comply with a warrant, court order or subpoena request from a foreign law enforcement agency. A provider subject to US law may therefore remain subject to the CLOUD Act even if your data is hosted in Canada.

The Government of Canada's digital sovereignty framework adds three nuances. It addresses the operations of the federal government, but its findings help put the risk in perspective:

  • These laws are not unique to the United States. According to the framework, "most countries, including Canada and the United States, have laws that allow their authorities to request access to information held by organizations within their borders."
  • Requests are framed. They can require specific steps, such as obtaining judicial authorization based on reasonable grounds related to a specific criminal investigation, and service providers may have recourse to challenge or clarify the order.
  • No documented cases involving Canadian businesses. The framework states: "The GC could find no documented cases of foreign governments seeking access to the data of Canadian enterprises held by suppliers."

The same framework notes that "using a Canadian supplier or storing data in Canada does not guarantee data will be outside the jurisdiction of foreign courts." The risk is therefore neither zero nor automatic: it depends on the provider, the sensitivity of your data and the measures set out in the contract.

What does Law 25 say about data kept outside Quebec?

For personal information, the Act respecting the protection of personal information in the private sector, as amended by Law 25, governs communication outside Quebec. Section 17 provides:

"Before communicating personal information outside Québec, a person carrying on an enterprise must conduct a privacy impact assessment. The person must, in particular, take into account (1) the sensitivity of the information; (2) the purposes for which it is to be used; (3) the protection measures, including those that are contractual, that would apply to it; and (4) the legal framework applicable in the State in which the information would be communicated, including the personal information protection principles applicable in that State."

The information may be communicated if the assessment establishes that it would receive adequate protection. The second paragraph adds: "The communication of the information must be the subject of a written agreement that takes into account, in particular, the results of the assessment and, if applicable, the terms agreed on to mitigate the risks identified in the assessment." The third paragraph adds: "The same applies where the person carrying on an enterprise entrusts a person or body outside Québec with the task of collecting, using, communicating or keeping such information on his behalf."

Three points for an SMB:

  • The text refers to outside Quebec, not only outside Canada. Hosting in another province is also covered.
  • The fourth factor, the legal framework of the State concerned, is exactly where a law such as the CLOUD Act comes into play.
  • Section 8 also requires informing the person concerned, if applicable, of the possibility that the information could be communicated outside Quebec.

The assessment and vendor contracts are explained in detail in our guide Law 25 for SMBs. For support, see the Law 25 compliance assessment.

What is the Quebec government doing about digital sovereignty?

In February 2026, the Ministère de la Cybersécurité et du Numérique published its digital sovereignty and IT procurement policy statement, the Énoncé de politique de souveraineté numérique et d'approvisionnement en technologie de l'information (in French). It is built around eight orientations based on two objectives: increasing Quebec's digital sovereignty and increasing the economic benefits of the State's IT investments. The orientations include sovereign hosting of data in the Nuage gouvernemental du Québec (NGQ, the government cloud) and in government data processing centres (CTI), and control of data through data centres under Quebec jurisdiction.

The statement of orientations on cloud computing and hosting, the Énoncé d'orientations en infonuagique et en hébergement (ministerial order 2026-02, in French), sets out how this applies to the public administration. Among other things, it provides that information assets containing highly sensitive data are hosted on sovereign infrastructure: the NGQ, a data processing centre owned by the Quebec or Canadian government, or a public cloud infrastructure designated by the Minister. These orientations cover the assets a public body holds on May 20, 2026 and those it will hold after that date.

Both documents concern the State's actions and public bodies, not SMBs. For a private business, communicating personal information outside Quebec remains governed by the private sector privacy act. If your business provides services to a public body, ask that body about the requirements that apply to your contract.

What questions should you ask a cloud provider?

The Canadian Centre for Cyber Security recommends that organizations "evaluate legal jurisdiction where outsourced providers store and use sensitive information." It adds: "For non-GC organizations, we recommend that you ensure all sensitive data, including account and security information, is stored within Canada." It also advises first identifying "the value and the level of sensitivity of your information."

Before signing, ask your provider these questions and keep the answers in writing:

  • Data region. In which region is your production data stored, and can that region be fixed in the contract?
  • Backup region. Do backups, disaster recovery copies and logs stay in the same region? See also the backup good practices.
  • Technical support. From where can technical support and administrators access your data?
  • Jurisdiction. In which country are the provider and its parent company incorporated, and which laws are they subject to?
  • Subcontractors. Which subcontractors process your data, and in which countries?
  • Encryption keys. Is your data encrypted in transit and at rest, and who holds the keys: the provider or your business?
  • Lawful access requests. Does the provider commit to notifying you of a request for access to your data, unless the law prohibits it?
  • Exit. In which format do you get your data back at the end of the contract, and how is its deletion confirmed?

These questions apply to a cloud server or a Microsoft 365 migration as much as to an artificial intelligence tool: see the AI vendor assessment. To plan a complete project, read the guide Cloud migration: the steps for an SMB.

How do you state a data residency requirement in your quote request?

Start by classifying your data by sensitivity, as the Cyber Centre recommends. Sensitive personal information or confidential business data does not call for the same measures as a public website. Then state in your request:

  • the residency requirement you want (Quebec, Canada or no requirement) and the data it covers;
  • whether it also applies to backups and technical support;
  • your other requirements: encryption, notice of lawful access requests, exit format.

You can require that your data stay in Quebec or in Canada. The Courtier TI team first contacts you to understand your project and takes this requirement into account to find the best IT services firm to carry it out. That firm presents its quote to you: check that it states the hosting region, the backup region and the related contractual commitments. For a cloud services or cybersecurity project, these details make the quote easier to assess.

Frequently asked questions

Does the CLOUD Act apply to a Quebec SMB?

Section 2713, added by the CLOUD Act, targets providers of electronic communication service and remote computing service, not their customers directly. It can still affect a Quebec SMB's data if its provider is subject to it: section 2713 of Title 18 of the United States Code applies to data within the provider's possession, custody or control, whether it is located within or outside the United States.

Does a Canadian provider guarantee data sovereignty?

Not on its own. According to the Government of Canada's digital sovereignty framework, using a Canadian supplier or storing data in Canada does not guarantee data will be outside the jurisdiction of foreign courts. The framework also notes that many Canadian suppliers rely on components, platforms or infrastructure subject to foreign jurisdictions. Check the jurisdiction of the provider, its parent company and its subcontractors.

Should you stop using US cloud services?

Not necessarily. Quebec's private sector privacy act does not prohibit communicating personal information outside Quebec: section 17 allows it if the privacy impact assessment establishes adequate protection, and the communication must be the subject of a written agreement. The Canadian Centre for Cyber Security recommends classifying your data by sensitivity and ensuring that sensitive data is stored in Canada. The decision is therefore made data set by data set.

Does encryption solve the issue?

It reduces the risk without fully solving it. According to the federal white paper, data encrypted with a strong cryptographic algorithm is protected from anyone who does not have the decryption key, which is why controlling the keys matters. The white paper also notes that data processed by an application in the cloud must first be decrypted, which leaves an unencrypted copy with the provider temporarily.

Can we require our data to stay in Quebec?

Yes. State it in your request, including whether the requirement also covers backups and technical support: the Courtier TI team takes it into account to find the IT services firm. Then check the hosting region in the quote and in the contract. Location settles data residency, but not all of sovereignty.

Sources

  1. LégisQuébec, Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1), sections 8 and 17 (up to date as of August 12, 2026)
  2. U.S. Department of Justice, Full text of the CLOUD Act (Consolidated Appropriations Act, 2018, Pub. L. 115-141, Division V), PDF
  3. U.S. Government Publishing Office, 18 U.S.C. § 2713, Required preservation and disclosure of communications and records (added by Pub. L. 115-141, div. V, § 103(a)(1), March 23, 2018)
  4. U.S. Department of Justice, CLOUD Act Resources (updated October 24, 2023)
  5. Gouvernement du Québec, Souveraineté numérique (updated February 13, 2026, in French)
  6. Ministère de la Cybersécurité et du Numérique, Énoncé de politique de souveraineté numérique et d'approvisionnement en technologie de l'information (PDF, February 2026, in French)
  7. Gouvernement du Québec, Énoncé d'orientations en infonuagique et en hébergement (updated June 18, 2026, in French)
  8. Treasury Board of Canada Secretariat, Government of Canada White Paper: Data Sovereignty and Public Cloud (2018)
  9. Government of Canada, Digital Sovereignty: A Framework to improve digital readiness of the Government of Canada
  10. Canadian Centre for Cyber Security, Secure cloud and outsourced IT services (modified September 6, 2019)
  11. Canadian Centre for Cyber Security, Benefits and risks of adopting cloud-based services in your organization (ITSE.50.060, modified March 5, 2020)

Have an IT project in mind?

Describe your project in a few lines: the Courtier TI team first contacts you to understand it, then finds the best IT services firm to carry it out. That firm presents its quote to you.

Request a quote