Canada is investing in domestic data centres, cloud infrastructure and sovereign computing capacity. That is important progress. But where a server is located is only one part of a much larger question: who ultimately controls Canada's digital infrastructure?
Canada's conversation about digital sovereignty is changing.
For years, digital sovereignty could sound like an abstract policy concept—something discussed primarily by cybersecurity specialists, government departments and technology policy experts. That is no longer the case.
Digital infrastructure now supports virtually every part of Canadian society. Health care, banking, government services, education, transportation, communications, research and critical infrastructure all depend on software, cloud services, networks and data.
The Government of Canada itself now describes digital sovereignty in straightforward terms: Canada remaining in control of its data, technology and essential online services rather than depending excessively on foreign companies, systems or laws.
That is an important recognition.
But it raises another important question.
What does "control" actually mean?
Building infrastructure in Canada is an important step
On September 3, 2026, the federal government announced Canada's Responsible Data Centre Development Principles, establishing a national framework around the development of data-centre capacity.
The government acknowledged something particularly significant: Canada currently relies substantially on infrastructure and services outside the country for compute, cloud and data storage supporting artificial intelligence.
Increasing Canadian capacity, it argues, can provide greater resilience and choice.
The principles also go beyond simply encouraging construction. They address electricity costs, water consumption, environmental effects, transparency, community benefits and the strategic value that data-centre projects should provide to Canada.
These are welcome developments.
Shared Services Canada is moving in a similar direction. Its 2026–27 plans include a dedicated sovereign private-cloud environment within Canadian jurisdiction, Canadian-resident disaster-recovery capabilities, engagement with Canadian cloud providers and efforts to reduce dependence on foreign-hosted services for sensitive communications.
Canada clearly recognizes that digital infrastructure has become strategic infrastructure.
But there is an important distinction we should not lose in this discussion:
Data residency and digital sovereignty are not the same thing.
A server can be Canadian while the dependency remains foreign
Imagine that an application used by a Canadian public institution is hosted entirely in a data centre in Canada.
Its data physically stays in Canada.
That sounds sovereign.
But now consider some additional questions.
Who owns the software running the system? Can the organization inspect it? Can it operate the system independently if its vendor relationship changes? Are its files stored in open formats that another system can understand? Can the workload realistically be moved to another provider? Does the organization control its encryption keys? Is authentication dependent upon an external platform? What happens if licensing terms change dramatically? What happens if a product is discontinued?
And perhaps the simplest question:
Could Canada keep the system running without the vendor?
If the answer is no, then the physical location of the server has solved only part of the sovereignty problem.
A Canadian data centre can protect Canadian data residency while still hosting an ecosystem built around technological dependencies that Canada does not control.
That doesn't make the data centre unimportant.
It means sovereignty has more than one layer.
Sovereignty should include the ability to leave
One of the most useful ways to think about digital sovereignty is not simply to ask:
"Where is our technology?"
Instead, ask:
"How much freedom do we have to make a different technology decision tomorrow?"
That distinction matters.
A healthy digital ecosystem should allow governments, businesses and institutions to change suppliers without rebuilding everything from scratch.
Data should be exportable.
Interfaces should be documented.
Standards should be interoperable.
Systems should not deliberately make migration prohibitively difficult.
Organizations should understand the technology upon which critical operations depend.
And wherever appropriate, software should be capable of running across different infrastructure rather than being permanently tied to one vendor.
In other words, one of the strongest measures of digital sovereignty is choice.
If leaving a provider is technically or financially impossible, sovereignty is limited regardless of the postal code of the data centre.
This is where open source becomes strategically important
Open-source software should not be presented as a requirement that Canada must use in every situation. Proprietary software has a legitimate place in Canadian technology environments, and procurement decisions should consider security, capability, support, cost and operational requirements.
But open source provides characteristics that are particularly valuable when discussing sovereignty.
Source code can be inspected.
Software can often be operated independently.
Knowledge can be transferred between organizations.
Open standards can reduce barriers between systems.
Communities and Canadian businesses can develop expertise around technology without requiring permission from a single vendor.
And when a particular supplier disappears, changes direction or becomes unsuitable, access to the underlying technology does not necessarily disappear with it.
That is not merely a philosophical advantage.
It is a form of strategic resilience.
Interestingly, Canada has already begun acknowledging this connection. In June, the Government of Canada, through the Canadian Digital Service, joined the Digital Public Goods Alliance. Digital public goods include open-source software, open data, open AI models and open standards.
That provides an opportunity to connect Canada's infrastructure strategy with a broader software strategy.
Canadian ownership matters—but so does technological independence
Supporting Canadian technology companies should absolutely be part of Canada's digital strategy.
The launch of Digital Transformation Canada on September 3 included a commitment to use federal purchasing power more strategically to help Canadian digital and AI companies test, scale and commercialize technologies. The government explicitly connected that work to strengthening Canada's digital sovereignty.
That can help develop Canadian expertise, businesses and intellectual property.
But even "Buy Canadian" cannot be the complete definition of digital sovereignty.
A Canadian proprietary platform can still create vendor lock-in.
A foreign-developed open-source technology can sometimes provide Canada with considerably more operational control than a closed Canadian product.
The important questions therefore extend beyond the nationality of a supplier.
They include control, portability, interoperability, transparency, jurisdiction, resilience and choice.
Sovereignty is a stack
It may be helpful to think of digital sovereignty as a stack.
At the bottom is physical infrastructure: data centres, networks, electricity and computing hardware.
Above that is jurisdiction: which laws govern the infrastructure and information.
Then comes data control: where information is stored, who can access it and who controls its encryption.
Above that is software: the operating systems, platforms and applications that make the infrastructure useful.
Then there are standards and interfaces, which determine whether systems can communicate and whether information can move between them.
And finally there are people and skills: whether Canada has professionals capable of building, operating, auditing, repairing and replacing these technologies.
True digital sovereignty requires attention throughout that stack.
Owning the building while depending completely on technology we cannot inspect, replace or operate independently would be an incomplete solution.
Canada has an opportunity to get this right
The encouraging part of the current discussion is that Canada is beginning to treat digital infrastructure with the strategic importance it deserves.
Domestic compute capacity matters.
Canadian data centres matter.
Canadian cloud providers matter.
Canadian technology companies matter.
Protecting sensitive information under Canadian jurisdiction matters.
These investments should continue.
But as Canada builds the next generation of its digital infrastructure, we should also build freedom of choice into its architecture.
That means encouraging open standards.
It means considering open-source alternatives during procurement.
It means requiring meaningful data portability.
It means avoiding unnecessary vendor concentration.
It means developing Canadian technical expertise rather than outsourcing all institutional knowledge.
And it means evaluating sovereignty throughout the entire technology stack—not simply asking where the servers happen to be located.
Canada does not need to disconnect itself from the global technology ecosystem to achieve digital sovereignty. Nor would doing so be desirable.
Digital sovereignty is not digital isolation.
It is the ability to participate in that global ecosystem from a position of resilience, capability and choice.
A Canadian data centre is an important part of that future.
But putting the server in Canada is only the beginning.



Comments (0)