Home AI Services Impacts Insights About Team Qatalink Contact Us

Jun 23, 2026

When "Our Data Stays in Canada" Isn't Enough


A data sovereignty guide for public sector AI adoption

The problem we keep hearing about

EDOs and municipalities are under real pressure to modernize. AI tools promise to cut reporting time, accelerate grant writing, and help small teams punch above their weight. The interest is genuine, and the tools are ready. The federal government is putting funds behind AI adoption.

But when the proposal reaches the CAO or council, one question stops the conversation cold: where does our data go? Municipal data is sensitive — community economic strategies, business visit notes, investment prospect details, land inventories, internal council deliberations. Councils are right to be cautious about it.

The trouble is that most AI vendors answer this question badly. They point to a Canadian data centre and call it solved. It isn't.


First, know what your own rules require

Before you assess any vendor, know which rules bind you — and in Canada, they are not uniform. Several have also changed recently:

  • Nova Scotia (PIIDPA) is the strictest: public bodies and municipalities generally cannot store or allow access to personal information outside Canada, except in narrow circumstances. (These restrictions transition into a modernized FOIPOP framework effective April 1, 2027.)
  • Quebec (Law 25) requires a privacy impact assessment and "essentially equivalent" protection before personal information leaves the province — and it applies to private-sector partners too. It also imposes automated decision-making obligations, with penalties at the top penal tier reaching C$25 million or 4% of worldwide revenue.
  • British Columbia (FIPPA) dropped its strict "Canada-only" storage rule in 2021. Storage outside Canada is now permitted on a risk-based basis, with an assessment required before sensitive personal information goes offshore.
  • Alberta (Protection of Privacy Act, in force 2025) requires public bodies to complete privacy impact assessments that explicitly weigh foreign-jurisdiction and U.S. legal exposure for SaaS tools.
  • Ontario (FIPPA / MFIPPA) and most other provinces impose no blanket residency mandate but require reasonable security and accountability for data handled on your behalf.
  • Federally, PIPEDA does not mandate localization, but Principle 3 (meaningful consent) and Principle 4 (collecting only what is necessary) constrain how commercial AI platforms handle personal data — and your organization remains accountable for whatever a processor does with it.

The first question, in other words, is internal: what does our governing statute actually require?


Difference between residency and data sovereignty

We have all been hearing a lot about data sovereignty lately. But data residency and sovereignty are not the same thing.

  • Residency is about where your data physically sits.
  • Sovereignty is whose laws can compel access to it.

Under the U.S. CLOUD Act, American authorities can require a U.S.-headquartered company to produce data in its control regardless of where that data is physically stored. A Canadian data centre operated by a U.S. company offers no real protection, because the legal reach follows the corporate entity, not the server location.

This does not mean you should "avoid all U.S.-linked vendors." If it were, no public body could use the major cloud services such as Microsoft Azure at all. The right response is to assess foreign-access exposure honestly and bring it to an acceptable, documented level.


The questions to actually ask a vendor

Two questions cut through the talking points fast:

  • Who controls the corporate entity behind this platform, and what jurisdiction governs legal access to our data?
  • Where is our data stored and processed, who at your company can access it, and do we hold the encryption keys?

And a few more that separate serious vendors from the rest:

  • Do you use our data to train or improve any shared model — and is that off by default, in writing?
  • Will you sign a Data Processing Agreement and name your sub-processors?
  • Can you support the privacy impact assessment our statute requires?
  • What happens to our data when the contract ends, and will you certify deletion?

This is how we answer those questions: Our Partnership with Leading AI

Qatalyst and our technology partner Leading AI built KnowledgeFlow specifically to take data sovereignty off the table as a barrier to AI adoption for public sector organizations. KnowledgeFlow runs entirely within your own Microsoft Azure environment — not a shared cloud, not Leading AI's servers, not Qatalyst's infrastructure. Your environment. Your municipal data never leaves your control, never sits on a third-party server, and never trains a public AI model.

The architecture is built to answer the questions councils and CAOs actually ask:

  • Who can be compelled. There is no U.S. company in the application layer. Leading AI is UK-based, Qatalyst is Canadian, and neither holds your data or is subject to U.S. legal compulsion over it. The platform runs on Microsoft Azure — the same infrastructure most public bodies already rely on — so KnowledgeFlow adds no foreign-access exposure beyond the Azure environment your organization has already assessed and approved.
  • Data residency. KnowledgeFlow deploys to Canadian Azure regions. Your data stays in Canada — and the corporate structure backs that up rather than undercutting it.
  • Access controls. Role-based permissions, Microsoft Entra ID (formerly Azure AD) integration, and document-level access controls mean your staff see only what they should. Every query is logged and auditable.
  • No model training. Your documents, strategies, and community data are used to answer your questions — never fed into a shared model or used to improve anyone else's platform.
  • Compliance alignment. Built with GDPR and SOC 2 alignment, and configured to support your PIPEDA obligations and Law 25 requirements where applicable.

What this looks like in practice

An EDO using KnowledgeFlow can tell its council exactly where the data lives, who has access to it, and what happens if someone requests it. The result: your organization moves forward with AI confidently, with a governance paper trail that satisfies legal counsel, a platform that doesn't require blind trust in a vendor's privacy policy, and tools that actually deliver on the productivity promise.


Qatalyst is a Canadian management consulting firm specializing in AI-enhanced solutions for public sector and economic development organizations. We partner with Leading AI to deliver KnowledgeFlow — a secure, private AI platform deployed within your own cloud environment.

Never Miss an Update!

Sign up for our newsletter to be notified when we post a new article.