Skip to main content
Expand Labs
Policy9 min read

Is Canada a "trusted partner" for Europe's sovereign cloud?

Not yet — and Ottawa's own bills are the reason

By Gautam Soni · Founder, Expand Labs Inc.

  • Digital Sovereignty
  • EU Regulation
  • Canadian Policy
  • Cloud Infrastructure
  • Data Residency

On 3 June 2026 the European Commission proposed the Cloud and AI Development Act (CADA). It is Europe's most serious attempt yet to decide who may host its most sensitive public data. The Act sets four "Union assurance levels" for public cloud procurement. At Level 3 and above, a provider may not be controlled from outside the EU. That rule effectively reserves the top tier of the market for European companies.

There is one exception, and Canada should care about it more than any other country. Article 18 lets the Commission recognize "associated third countries" whose cloud providers may still qualify for Level 3. Lawfare's analysis of the proposal sets out the three conditions: the country must hold a GDPR adequacy decision, must not require providers to give governments access to non-personal data protected under Article 32 of the EU Data Act, and must not compel providers to degrade or disrupt service, including through sanctions. The conditions are cumulative. Failing one is failing all three.

The United States holds an adequacy decision for commercial data flows. It still fails the third test, because its sanctions law can force a provider to cut off European users. The EU learned that from the US sanctions on International Criminal Court officials. Commission Executive Vice-President Henna Virkkunen has said the goal is that nobody holds a "so-called kill switch possibility."

Canada is the obvious next candidate. It is a close ally, it has held EU adequacy for a quarter-century, and it opened Digital Trade Agreement negotiations with the EU in June. The Canada–EU partnership story says Canada should pass easily. Tested against the text, it does not, at least not yet. The reasons are mostly within Ottawa's control.

Test one: adequacy — a pass, with an asterisk

Canada has held an adequacy decision since 2001. In January 2024, the Commission's first review of older adequacy decisions concluded that Canada still offers adequate protection. The review also found that Canadian public authorities face appropriate limits and oversight under the Charter and Canadian case law.

The asterisk is scope. Canada is the only country whose adequacy covers only commercial operators under the Personal Information Protection and Electronic Documents Act (PIPEDA). The drafters saw cases like this coming. The proposal's recitals tell the Commission to check two things: whether a country's adequacy covers it as a whole or only certain sectors, and whether it covers the specific processing the cloud service would do.

For a commercial cloud provider, the limit probably does not bite. The real exposure is timing. On 15 June Ottawa tabled Bill C-36, which would replace PIPEDA's privacy provisions with a new Protecting Privacy and Consumer Data Act. An adequacy decision that names PIPEDA will need to be revisited when PIPEDA's privacy rules no longer exist. A stronger law should survive that review. A messy transition, just as Brussels is deciding who is trusted, is a risk Canada is choosing to run.

Test two: compelled access — as the law stands, a fail

The Data Act condition asks whether a country requires providers to hand over non-personal data held in the EU. Canada does.

The clearest example has already appeared in Lawfare's CADA analysis as a warning to Europe. In The King v. OVH, Justice Heather Perkins-McVey of the Ontario Court of Justice upheld a production order against OVHcloud's French parent on 25 September 2025. The court found jurisdiction through the company's "virtual presence" in Canada — a real and substantial connection built from Canadian staff, Canadian data centres and commercial benefit derived from Canadian customers. The data itself sat on servers in France, the UK and Australia. OVH applied for judicial review.

The case has since escalated in a way that makes the point better than any analysis could. On 31 July 2026, OVH confirmed that Canadian authorities had threatened charges against both OVH Groupe S.A. and its Canadian subsidiary — failure to comply with a production order under section 487.0198 of the Criminal Code, and obstruction of justice under section 139(2). OVH says it will contest them fully, and argues the RCMP should have used the mutual legal assistance treaty instead. Whatever the merits, Brussels now has a live example of a European cloud provider facing Canadian criminal exposure for declining to produce data held in Europe.

A Criminal Code production order does not distinguish personal from non-personal data. If a Canadian court can compel a French cloud company to produce data held in France, Brussels will ask what it could compel a Canadian-controlled provider to produce from Frankfurt.

Bill C-22, the Lawful Access Act, moves further in the same direction. It lets courts order foreign entities that provide telecommunications-related services to produce subscriber information and transmission data. Its second part, the Supporting Authorized Access to Information Act, requires designated "core" providers to build interception capability and retain metadata for up to six months. It also lets the Minister issue orders to every electronic service provider, subject to Intelligence Commissioner approval. The House passed the bill at third reading on 19 June 2026, after the government limited committee study and debate as Parliament rose for the summer. The Senate took up its study on 21 September.

In fairness to Canada, these powers are judge-authorized and Charter-constrained, and the Commission itself called Canada's safeguards adequate in 2024. Several EU member states, including Belgium, Denmark, France, Ireland and Spain, can compel production of evidence held abroad. The Computer & Communications Industry Association (CCIA) argues that no major technology-producing nation meets the Article 18 standard, the EU included.

That criticism is fair, but it does not help Canada. As drafted, Article 18 asks whether the power exists, not whether it is well supervised. Canada has the power, is currently exercising it against a European provider, and C-22 would enlarge it.

There is also a US dimension. Canada has been negotiating a CLOUD Act executive agreement with Washington since 2022. Such agreements let the partner country's law enforcement send orders directly to providers, so a signed deal would formalize a US route to data held by Canadian providers. Brussels will read that as bearing directly on whether Canadian control is meaningfully different from American control.

Test three: compelled disruption — narrower than America's, but not zero

Canada has a kill switch too. The question is how far it reaches.

Under the Special Economic Measures Act, cabinet can prohibit the provision of "any other services" to sanctioned persons. That prohibition binds anyone in Canada and any "Canadian" abroad. The Act defines "Canadian" as a citizen or a company incorporated in Canada.

That reach is structurally narrower than the American problem that inspired Article 18. A cloud service run by an EU-incorporated subsidiary, operated from Europe, is not directly bound. A service whose control plane, support staff or parent company operations sit in Canada is bound. For sanctions, a Canadian provider's eligibility will depend on its architecture, not its flag.

In June, Bill C-8 also became law. Under the amended Telecommunications Act, the Minister of Industry may prohibit a telecom provider from serving certain persons or temporarily suspend its services. The power targets Canadian telecom networks, and it is uncertain whether it reaches a cloud service. It is still a statutory service-disruption power, enacted three months before this Act comes before the European Parliament and Council.

The honest reading is that Canada does not clear this test on paper. It comes much closer than the US, and the remaining gap can be closed by how providers are structured and by what the two governments agree.

What the answer actually is

Read strictly, Canada passes one test and fails two. So does nearly everyone else, which means Article 18 as written is close to a dead letter.

The recitals point to a more workable reading. The Commission is to ask whether a country has "specific safeguards" that remove the risk of unauthorized access or disruption, not whether it lacks all such powers. Under that functional reading, Canada is among the strongest candidates of any large non-EU democracy. Canada is probably the country whose application would show Brussels which of the two readings it means.

That makes the next six months unusually important, and most of the work sits in Ottawa:

  1. Amend C-22 in the Senate with an EU carve-out. Orders under the new foreign-production and ministerial-order powers should not reach data held in the EU by EU-established services unless they go through an international agreement. That mirrors the EU Data Act, which already exempts orders based on mutual legal assistance agreements. The change costs Canadian law enforcement little and gives the Commission something concrete to cite. The Senate study that began on 21 September is the last practical opportunity.
  2. Resolve OVH through the treaty channel. Pressing criminal charges against a French cloud provider for protecting data held in France is the single most damaging fact pattern Canada could put in front of the Commission while Article 18 is being negotiated. Using the mutual legal assistance treaty here costs one case and buys the argument.
  3. Use the Digital Trade Agreement to trade assurances. A reciprocal e-evidence channel plus a mutual commitment to consult before sanctions disrupt each other's providers would give both sides what Article 18 is groping for.
  4. Protect adequacy through C-36. Draft the transition with the Commission's review in mind rather than discovering the problem afterward.
  5. Sequence the CLOUD Act deal carefully. Signing with Washington before securing Article 18 status would look, from Brussels, like opening the door Article 18 exists to close.

For Brussels, the ask is simpler. Define Article 18 functionally, in terms of safeguards, reach and oversight, or accept that it is decoration. A partner-country clause that no partner can meet does not keep the market open to partners.

Canada wants to be Europe's most trusted non-European partner, and on most counts it deserves to be. Article 18 is where that claim will be checked line by line. Right now Canada's own legislative agenda is the biggest obstacle.


Disclosure: The author is the founder of Expand Labs Inc., a Canadian software company that builds data-residency and sovereignty-conformance tooling for regulated environments. Expand Labs therefore has a commercial interest in how Article 18 and comparable sovereignty requirements are interpreted. This article reflects the author's own views and not those of any employer or client.

Status of facts: Current as of 22 September 2026. Bill C-22 is before the Senate, the OVH judicial review and the threatened charges against OVH Groupe S.A. remain unresolved, and CADA is a Commission proposal that has not yet been considered by the European Parliament and Council.

Sources