Digital sovereignty: does your data really belong to you?
A company can be the legal owner of its data while depending entirely on another organization to access it. It may have paid for its software, signed its contracts, met its regulatory obligations, and retained all of its rights over the information. Yet if its data resides in a supplier's infrastructure, if its backups depend on that same platform, if its employees use that supplier's identities, and if its operations stop when that service becomes unavailable, the notion of ownership quickly becomes more complex.
The dispute currently pitting OVHcloud against the Canadian authorities offers a particularly interesting illustration of this reality. In April 2024, a Canadian order required OVH France and its Canadian subsidiary to provide certain subscriber and account data associated with IP addresses. The servers in question, however, are located in other countries and are operated by other subsidiaries of the group. OVHcloud argues that the presence of its Canadian subsidiary does not automatically allow the Canadian authorities to obtain data held by other entities and jurisdictions, and that such a request could instead go through the international mutual legal assistance mechanisms provided for that purpose. The Canadian authorities dispute that position and have threatened OVH France and OVH Canada with prosecution for failing to comply with the order and for obstruction of justice.
The litigation will have to run its course, and it would be premature to predict its outcome. For executives, its main interest lies elsewhere: it reveals with remarkable clarity that the physical location of data, the nationality of the company hosting it, the jurisdiction of its parent company, those of its subsidiaries, and the laws that may be invoked to seek access to that information are all different realities.
This distinction compels organizations to move beyond an essentially geographic conception of digital sovereignty. The decisive question is no longer only where the data is located, but who actually has the legal, technical, and operational capacity to act on it and, above all, whether the organization will retain that capacity when its environment changes.
For years, the discussion of digital sovereignty has given considerable weight to the location of data centers. For a Canadian organization, asking whether its data is hosted in Canada remains entirely legitimate and can address important regulatory, contractual, or strategic considerations. Data residency, however, is only one component of a far broader question.
Data can physically sit in Canada while being operated by a foreign company, administered from another jurisdiction, processed by various subcontractors, or subject to legal obligations that extend beyond where the server is located. Conversely, as the OVHcloud dispute allows us to observe, a company can carry on business in one country while certain data sought by its authorities is held by another legal entity of the same group in another territory. Digital sovereignty therefore cannot be reduced to a data center's mailing address.
It is about control first and foremost, and about the ability to retain that control as circumstances change. This distinction takes on particular importance in Canada. In September 2026, the federal government itself acknowledged the country's significant dependence on infrastructure and services located abroad for part of the computing, cloud, and storage capacity required in particular for the development of artificial intelligence. Increasing Canadian capacity is presented in particular as a way to expand resilience and the choices available.
The word "choice" probably explains digital sovereignty better than several far more complex definitions. Being sovereign does not necessarily mean owning, developing, and operating everything yourself. A company can use Canadian, American, European, or other suppliers while maintaining a high level of autonomy. The challenge is to determine whether that relationship leaves it enough real options.
Can the organization retrieve its data in a genuinely usable format and transfer it to another supplier? Can it continue certain essential operations if its main platform becomes temporarily inaccessible? Does it understand which legal entities and which subcontractors can access its information? Does it itself control certain particularly sensitive cryptographic keys? Does it have backups that are sufficiently independent of its primary supplier? Are its systems built in a way that makes a platform change technically and economically realistic? These questions turn digital sovereignty into a genuine matter of corporate governance.
An organization may, for example, run its email, its documents, its backups, its CRM, its ERP, its collaboration tools, certain artificial intelligence functions, and its employee authentication on a handful of external suppliers. Legally, the data still belongs to it. Operationally, a considerable share of its digital existence then depends on infrastructure and decisions it does not directly control.
Over time, various situations can alter that relationship. A significant price increase can change the economics, an acquisition can transform a supplier's strategy, a major outage can interrupt operations, a regulatory or judicial development can change the conditions of access to data, and a commercial or geopolitical conflict can create new restrictions. A decision made thousands of kilometers away can thus have direct consequences on the company's daily activities. Sovereignty therefore begins with a clear-eyed understanding of one's dependencies.
Artificial intelligence now adds a new depth to this issue. An organization may send certain information to a model provider, use cloud infrastructure from a second company, connect the whole thing to data stored with a third, and integrate agents or applications from other suppliers. The actual path taken by the information then becomes far more complex than the experience visible to the user.
This development explains why data sovereignty can no longer be analyzed solely from the standpoint of where the data ultimately sits. You have to understand its flows, the models that use it, the APIs that carry it, the infrastructure that processes it, the identities that can access it, and the jurisdictions the various actors in that chain belong to. Technological dependency gradually becomes an economic dependency and, for some organizations, a question of operational continuity.
This reality takes nothing away from the value of the large international suppliers. Their scale has given companies access to infrastructure, computing capacity, services, and levels of innovation they could hardly have developed on their own. Some platforms can also offer extremely high levels of cybersecurity, availability, and resilience. The real vulnerability appears when the organization no longer knows how to operate any other way.
A supplier-client relationship can then gradually become a structural dependency. A simple question makes it possible to measure its depth: what would happen if the organization had to leave this supplier within six months? When the answer involves several years to retrieve the data, rewrite applications, rebuild identities, replace interfaces, retrain teams, and negotiate new contracts, the company still owns its data, but its freedom to decide is far more limited.
The cost of exit should therefore be part of the initial evaluation of a technology. Organizations already examine acquisition cost, monthly fees, features, performance, cybersecurity, and the supplier's reputation. Assessing reversibility adds another dimension: how much would leaving cost, and how long would it take to recover an equivalent operational capability elsewhere?
This reflection does not mean that the solution that is easiest to replace should automatically be preferred. Some platforms can justify a significant dependency because of their operational value, their performance, or their level of specialization. The challenge is to know that dependency consciously, understand its consequences, and decide whether it remains acceptable for the level of criticality involved.
Sovereignty thus becomes a matter of degree. Not all data and not all systems require the same degree of control. Public information, routine administrative documents, and some applications can benefit from a great deal of flexibility. Trade secrets, sensitive financial information, intellectual property, personal information, research data, business strategies, proprietary models, or government information may justify architectures offering more control, reversibility, and independence.
This approach avoids two pitfalls. The first would be wanting to bring everything back in house in the name of sovereignty, with potentially considerable costs and sometimes a lower level of security if the organization does not have the resources needed to operate that infrastructure properly. The second would be assuming that outsourcing automatically transfers all responsibilities and risks to the supplier.
The guidance published in September 2026 by the Office of the Privacy Commissioner of Canada is a reminder that an organization remains accountable for the personal information under its control when it is collected or processed on its behalf by a third-party supplier. It must in particular assess that supplier's practices, build appropriate requirements into its agreements, and be able to demonstrate its accountability. This principle has broader implications for digital sovereignty: outsourcing certain functions transfers tasks, while the responsibility to protect information, maintain operations, meet obligations, and serve customers remains within the organization.
That responsibility leads directly to resilience. A mature sovereignty strategy must look at what the company can still accomplish when it temporarily loses access to part of its digital ecosystem. Backups hosted in the same cloud environment as the production systems can be perfectly valid from a technical standpoint while leaving a strategic dependency on that same infrastructure in place.
A more resilient architecture will therefore seek to introduce certain separations when the level of risk warrants it: genuinely independent backups, portable formats, the ability to restore elsewhere, cryptographic keys under organizational control, procedures making it possible to rebuild essential functions and, in some cases, diversification of infrastructure. The same reasoning applies to identities. When access to practically every system depends on a single identity provider, that provider becomes one of the organization's most strategic components.
Software presents a similar issue. Years of data locked into a proprietary format that is difficult to use elsewhere create a dependency that must be understood from the moment the technology is selected. Artificial intelligence amplifies this reality further: if the organization's knowledge, processes, agents, and interfaces are progressively structured around a single supplier or a particular proprietary environment, the cost of a future migration can rise considerably without that dependency being immediately visible.
Sovereignty should therefore be considered from the initial architecture onward. Portability, interoperability, documentation, APIs, separation of layers, identity governance, cryptographic control, and the ability to integrate several suppliers are all mechanisms for preserving options. These technical choices in fact become instruments of strategic freedom.
Being sovereign thus amounts to retaining enough control to be able to choose. An organization must be able to choose to stay with a supplier because it continues to offer the best solution, to negotiate when conditions change, to move certain data when its sensitivity increases, to adopt a private or sovereign environment for certain uses of artificial intelligence, to change partners when legal risk evolves, and to keep operating when an external service becomes temporarily unavailable. When those possibilities disappear, sovereignty becomes essentially theoretical.
The OVHcloud dispute adds another essential dimension: the legal structure of suppliers. When an organization chooses a technology platform, it also chooses — sometimes without fully grasping the implications — a corporate structure, jurisdictions, contracts, subcontractors, support mechanisms, and technological dependencies. Depending on the circumstances, different laws can also produce effects beyond the territory where the data is physically hosted.
Whatever the outcome of the current litigation, this dimension should enter procurement decisions alongside cybersecurity, price, performance, and features. It should also be reassessed periodically, since a supplier can be acquired, a legal structure can change, a law can evolve, a subcontractor can be added, an infrastructure can be relocated, or new artificial intelligence services can create data flows that did not exist when the contract was signed.
Digital sovereignty here connects directly with cyber vigilance and, more broadly, with Hypersecurity. A secure architecture must not only protect data against unauthorized access. It must also understand the dependencies liable to affect the organization's availability, integrity, confidentiality, reversibility, and decision-making autonomy. Identities, data, suppliers, cloud infrastructure, artificial intelligence, cryptographic mechanisms, and jurisdictions then become different dimensions of one and the same architecture of trust and resilience.
Quantum Beyond can step in precisely in that zone where technology, governance, cybersecurity, and strategy meet. Work carried out alongside internal teams can make it possible to identify digital dependencies, map data flows, analyze the suppliers and jurisdictions involved, examine identity and encryption mechanisms, and determine which capabilities warrant more direct organizational control.
This approach can also incorporate private and sovereign artificial intelligence, Zero Trust and Continuous Trust, data governance, the Qb Knowledge Standard, cyber resilience, and post-quantum preparation. In every case, the same principle holds: know the environment well enough to prevent a dependency chosen today from becoming a constraint discovered too late. The end goal thus goes well beyond compliance and consists of preserving the organization's ability to decide its own digital future.
The dispute between Canada and OVHcloud does not yet make it possible to determine how far a jurisdiction will be able to impose its demands on a technology group whose infrastructure and data are spread across several subsidiaries and several countries. It is nevertheless a remarkable case study for organizations, because it is a reminder that data never exists solely on a server. It exists simultaneously within technological, legal, contractual, and economic environments.
This reflection becomes particularly relevant in Canada as the country seeks to increase its domestic computing, cloud, and storage capacity in order to expand its resilience and its choices. Companies too must examine their architectures from this angle, particularly as cloud, SaaS services, and artificial intelligence take up a growing place in their operations.
Digital sovereignty does not automatically require repatriating all data to Canada, building your own data centers, or abandoning international platforms. Above all, it requires understanding dependencies and preserving alternatives where they become strategic. Knowing the applicable jurisdictions, understanding the contracts, controlling identities and certain cryptographic keys, preserving portability, maintaining genuinely independent backups, and preventing essential operations from becoming practically impossible to move are all expressions of one and the same capability.
Quantum Beyond can support organizations in this analysis by adding a sovereignty perspective to decisions still often assessed mainly through the lens of cost, features, and cybersecurity. This expertise complements that of internal teams by bringing a cross-cutting view of the technological, legal, operational, and strategic dependencies liable to influence their ability to act over the long term.
Data can thus belong legally to one company while being hosted by another organization, administered from another country, subject to several jurisdictions, and integrated into an architecture that would be extremely difficult to leave. Ownership remains important, but it is no longer enough to define sovereignty. Its true measure appears when circumstances change: does the organization still have enough control, knowledge, and options to decide for itself what it will do next?
