My perspective comes from both sides: I founded AssetMetrix, an early SaaS company that became part of the foundation of Microsoft’s management stack, and later worked in the Office of the CDO at Health Canada. From both vantage points, the same lesson keeps resurfacing: data sovereignty is too often treated as a geography problem, when it is really a control problem.

For years, organizations have comforted themselves with a familiar idea: if sensitive data is stored in the right country, under the right regional hosting label, with the right legal language in the contract, then sovereignty has been addressed.

It is an appealing idea. It is also increasingly incomplete.

Data sovereignty is still often discussed as though it were mainly a map problem. Keep the data in Canada. Keep it in Europe. Keep it inside national borders and assume the issue is largely settled. But that framing misses the harder and more important question: who actually holds the power?

Because the truth is simple: a flag on the rack does not change who holds the power.

If a major foreign cloud provider operates the infrastructure, controls key parts of the platform, manages or influences access to encryption workflows, or can be compelled under another jurisdiction’s laws, then the fact that the hardware happens to be sitting in your country may be relevant, but it is not decisive. The data may be local. Control may not be.

That is the gap many organizations are now running into. They have achieved residency, but often speak about it as though they have achieved sovereignty. Those are not the same thing. Residency answers where the data lives. Sovereignty answers who can actually do something with it when the pressure is on.

A Canadian public institution, for example, may place highly sensitive data in a Canadian region run by a large non-Canadian cloud provider. On paper, that can look reassuring. Procurement is satisfied. The compliance language is polished. The architecture diagram has all the right labels. Everyone gets to go home feeling responsible.

But if one provider still has too much visibility, too much administrative reach, or too much capacity to reconstruct the asset under pressure, then what exists is not full sovereignty. It is sovereignty with an asterisk.

And that asterisk matters.

This is why the Chief Data Officer role is becoming more important, and why it needs to evolve. Too often, the CDO is still treated as the executive sponsor for governance meetings, stewardship committees, metadata hygiene, data quality reports, and dashboard diplomacy. All of that has a place. None of it answers the core question of power.

The next generation of CDOs will need to think more seriously about architecture, concentrated trust, and technical control. Not because they must personally design storage systems, but because the strategic question is no longer just whether data is governed. It is whether control over that data has been meaningfully preserved.

That means asking questions that are more uncomfortable than the usual governance checklist allows.

Is encryption still a strong control if the same provider storing the data can also participate in key access? Is resilience really resilience if one outage, one insider compromise, or one legal order can still expose the full asset? Is sovereignty something you write into policy, or something you build into the structure of the system itself?

This is where the conversation gets more interesting. Real sovereignty starts to emerge when trust is not merely declared, but deliberately limited. When storage is separated from key control. When no single provider has enough of the puzzle to reconstruct the whole. When architecture reduces what any one vendor, administrator, or jurisdiction can do unilaterally.

That broader design logic matters more than any one vendor or service. The important shift is not simply “multi-cloud,” because multi-cloud on its own can still mean multiple providers participating in the same old trust model. The more meaningful principle is distributed trust: reducing the amount of power any single provider holds over the whole asset.

That distinction is subtle, but important.

Much of the market still bundles privacy, resilience, backup, and sovereignty into one vague promise and hopes nobody asks too many follow-up questions. But they are not interchangeable. You can have redundancy without sovereignty. You can have encryption without meaningful control. You can have local hosting without true independence. The question is not whether your data is somewhere safe-looking. The question is whether someone else still has too much power over it.

That is the strategic frontier for a modern CDO office.

The CDO should not be absorbed entirely into the tactical management of pipelines and policy artifacts while the actual trust model is set elsewhere by vendor defaults and infrastructure teams. The role should be helping the organization define where control must remain internal, where trust must be fragmented, and where architecture must do the work that contracts and compliance statements cannot.

Because contracts matter, but they do not magically dissolve concentrated power. Regional hosting matters, but it does not override platform control. Policy matters, but it does not compensate for architecture that places too much faith in one provider behaving, surviving, or resisting pressure exactly as hoped.

That is the real shift underway in data sovereignty. It is moving from a legal and geographic framing to an operational and architectural one. Less attention to where the bytes rest. More attention to who can access, reconstruct, compel, or surrender them.

And that shift is only becoming more urgent in an AI era, where data is not just stored but indexed, inferred from, modeled, replicated, and moved across systems faster than most governance frameworks can keep up. In that world, sovereignty cannot mean “we know where it started.” It has to mean “we know who can actually do what with it.”

That is a harder standard. It is also a more honest one.

So yes, data residency still matters. Jurisdiction still matters. National interest still matters. But none of them, on their own, resolve the central issue. A local data centre does not guarantee local control. A flag on the rack does not change who holds the power.

And that is exactly why the future of the CDO role is not clerical. It is strategic. It sits at the intersection of governance, architecture, security, procurement, and risk. It asks not just whether data is managed, but whether power over that data has been intentionally designed to remain where it belongs.

That is the conversation organizations need to be having now.

Not where the server is.

Who holds the power.


Originally published by Ross Norrie, founder of SkyeConnex, on LinkedIn.

Published March 9, 2026 · More from the SkyeConnex blog