When we pioneered cloud computing over 20 years ago, our mission was to make world-class technology and infrastructure accessible to any organization, anywhere. We’ve always believed that for the cloud to realize its full potential it would be essential that customers have control over their data. Giving customers this sovereignty has been a priority for AWS since the very beginning when we were the only major cloud provider to allow customers to control the location and movement of their data. At AWS, this means customers control the location of their data, who can access it, and how it is used, backed by industry-leading security capabilities.

Today, tens of thousands of Canadian organizations trust AWS to run their most important cloud and AI workloads. Startups, public sector institutions, enterprises, small businesses, in every industry and every part of the country trust us to help power the systems, applications and innovations that millions of people rely on every day – ranging from financial transactions and healthcare delivery to essential public services. Here are seven ways AWS provides Canadian customers with the control and choice needed to keep their data protected and secure while enabling ongoing innovation.

1. Built sovereign-by-design
The AWS Cloud is sovereign-by-design, and we offer a comprehensive set of technical measures, operational controls, and legal protections, providing our customers with control over how and where they store their data.

In 2022, we formalized this with the AWS Digital Sovereignty Pledge – our commitment to offering all AWS customers the most advanced set of sovereignty controls and features available in the cloud, without compromising on performance, innovation, security, or scale. In practice, this means customers choose where their data resides, have verifiable control over who can access it, and can encrypt everything everywhere – all on infrastructure with the highest network availability of any cloud provider, designed to sustain operations through disruption or disconnection. For example, services like AWS Control Tower, provide preventative, detective, and proactive controls to help meet data residency requirements, including purpose-built controls aggregated in a digital sovereignty category grouping.

2. Enabling AI sovereignty
Our commitment to customer control and choice extends to AI. With AWS, customers can develop and use AI services on a trusted foundation where their data remains secure and under their control. Customers can evaluate and select the most suitable models for their specific needs, choose where to deploy them, and fine-tune open weight models privately with their own data in Canada with Amazon SageMaker. No customer inputs to or outputs from Amazon Bedrock are used to train Amazon Nova or any third-party models. Learn more about AI sovereignty on AWS.

3. Canadian Regions, built for Canadian organizations
Building on our long-term commitment to Canada, we continue to invest in sovereign-by-design infrastructure that accelerates innovation while delivering the highest levels of security and protection. In 2016, we launched the AWS Canada (Central) Region in Montreal, enabling organizations to run applications and store data in Canada while benefiting from advanced cloud capabilities, low latency, and improved performance. In 2023, we launched the AWS Canada West (Calgary) Region — becoming the first major cloud provider to establish a data centre hub in Western Canada. With two Regions, Canadian organizations have the choice to deploy and process their data within the country, with control over its location. Today, we offer more services from Canadian regions than any other cloud provider.

Our data centre infrastructure represents a long-term commitment to Canada — supporting jobs, investing in communities, and helping organizations across the country build and grow. By 2037, we plan to invest up to $24.8 billion in building and operating our data centre regions, contributing approximately $42.3 billion to Canada's GDP.

4. Verifiable control over data access
Security is foundational to sovereignty, and it has always been our top priority. We have the most proven operational experience of any cloud provider, and our customers benefit from cloud and network architecture built to meet the requirements of the most security-sensitive organizations.

The AWS Nitro System, which powers all our modern Amazon Elastic Compute Cloud (Amazon EC2) instances, provides a strong physical and logical security boundary to enforce access restrictions so that nobody, including AWS employees, can access customer data running in Amazon EC2. The NCC Group, an independent cybersecurity firm, has validated the security design of the AWS Nitro System.

5. Encryption and key control
AWS also gives customers the features and controls to encrypt data, whether in transit, at rest, or in memory. All AWS services already support encryption, with most also supporting encryption with customer managed keys that are inaccessible to AWS. AWS Key Management Service (AWS KMS) is the first highly scalable, cloud-native key management system with FIPS 140-3 Security Level 3 certification – meaning AWS offers encryption that is independently validated and where customers control who gets a key. Customers can manage encryption keys inside or outside the AWS Cloud, giving them full control over access to their data.

6. Compliance that meets Canada's highest standards
To provide greater transparency on how AWS services are designed and operated, we seek third-party attestations, accreditations, and certifications – supporting more than 140 security standards and compliance certifications around the globe. Our Canadian infrastructure is assessed and authorized to host Protected B workloads, the classification level used by the Government of Canada for sensitive information. We hold certifications and attestations including SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, PCI DSS, and FedRAMP, among others. For AI workloads, AWS is the first major cloud provider to achieve ISO/IEC 42001 certification, an international standard for the responsible development and use of AI systems.

We continue to invest in ongoing independent validation so that customers in government, healthcare, financial services, and other regulated industries can build with confidence.

7. Transparency on cross-border legal frameworks
In recent months, we’ve noticed an increase in inquiries about how we manage government requests for data. The U.S. CLOUD Act did not give the U.S. government any new authority to compel data from providers and provides critical legal guardrails to protect content. It clarified that U.S. law enforcement can use existing authorities, such as a court-approved search warrant, to compel data within a provider's control, regardless of where data is stored. But access is far from unfettered or automatic and law enforcement must meet strict legal standards.

Since we began reporting this statistic in 2020, AWS has not disclosed any enterprise or government customer content data stored outside the U.S. to the U.S. government. Furthermore, many of the AWS core systems and services are designed with zero operator access, meaning the services don't have any technical means for AWS operators to access customer data in response to a legal request.

The CLOUD Act applies to all electronic communication service or remote computing service providers that operate or have a legal presence in the U.S., regardless of where their headquarters are located. The CLOUD Act did not introduce a new legal concept regarding the scope of electronic data that must be disclosed as part of legitimate criminal investigations. Many countries require disclosure of customer data wherever it’s stored in response to legal process involving serious crimes. The U.K.'s Crime (Overseas Production Orders) Act, for instance, allows U.K. law enforcement agencies to obtain stored electronic data located outside of the U.K. According to a filing by the U.S. DOJ, the laws of several European Union (EU) member states, including Belgium, Denmark, France, Ireland, and Spain, have similar requirements.

AWS is advocating for reciprocal executive agreements to conclude under the CLOUD Act, including between the U.S. and Canada and the U.S. and the EU. We believe these agreements are important to definitively resolve potential conflicts of law and enable effective investigation of serious crimes to advance public safety, while recognizing the strong substantive and procedural safeguards that already exist under U.S. law. Learn more here.

Building for Canada’s Digital Future
We remain committed to helping our customers drive continuous innovation while meeting their needs and requirements. As cloud and AI evolve, AWS will continue offering the most advanced set of sovereignty features and controls.

Across Canada, organizations trust AWS to help them innovate faster, tackle real-world challenges, and compete on a global scale. From water purification and wildfire prevention to ensuring our aging population receives better care, they are using AI and cloud infrastructure from AWS to solve some of humanity's toughest challenges. Read moreabout Canada’s AI Innovators.

Read more about Canada’s AI Innovators.