ITSG-33 compliance and Canadian data residency are necessary starting points for protecting Indigenous data - but they are not enough on their own. This article explains the gap between technical security controls and genuine Indigenous data sovereignty, and outlines five practical steps communities and administrators can take to establish real governance: from residency requirements in contracts, to community-specific access controls, to building capacity for Indigenous-controlled infrastructure.
Data Sovereignty and Digital Self-Determination: Why Indigenous Communities Need Control Over Their Data
When Indigenous communities work with government agencies, healthcare providers, or technology vendors, they're often told their data will be "secure" and "compliant." But secure for whom? And compliant with whose standards? At Nitap Technologies, we believe these are the wrong questions. The real question is: Who has the right to control, access, and determine the future of Indigenous data?
Data sovereignty - the principle that data is subject to the laws and governance structures of the Nation where it is collected - is not just a technical consideration. For Indigenous communities, it's a matter of self-determination, cultural preservation, and the protection of future generations. When communities need to turn that principle into a practical roadmap, our Indigenous cybersecurity and data sovereignty services are built for that transition.
The Gap in Current Security Frameworks
Frameworks like ITSG-33 provide comprehensive guidance on protecting sensitive information for federal systems in Canada. They address confidentiality, integrity, and availability. They establish baseline security controls. For systems handling Protected B data at Medium Integrity and Medium Availability (PBMM) - which includes most sensitive government data like health records, financial information, and treaty negotiation documents - ITSG-33 effectively requires Canadian data residency. The Treasury Board Directive on Security Management mandates that Protected information be stored in Canada, and moving it to foreign jurisdictions requires explicit authorization, Privacy Impact Assessments, and Security Assessments.
This is important: if you're working with federal systems or data classified as Protected B, Canadian data residency is already required. Organizations navigating these requirements can benefit from dedicated governance and compliance support to ensure controls are not only technically sound but structurally aligned with their obligations. But here's what ITSG-33 doesn't adequately address: who ultimately has authority over that data beyond the technical custodian, and how Indigenous governance principles are incorporated into that control.
ITSG-33 focuses on security controls: encryption, access management, incident response. These are critical, but they operate within an assumption that the current custodian of the data (typically a federal department or approved service provider) has legitimate authority over it. For Indigenous communities, this assumption is problematic. Even when data is stored in Canada and meets PBMM requirements, questions remain: Can the community determine retention periods? Can they revoke access? Can they establish cultural protocols for who sees what? Do they have the right to take their data and migrate it to a different system?
What Is Data Sovereignty and Why It Matters
Data sovereignty is the principle that data is subject to the laws, regulations, and governance of the jurisdiction where the data subjects reside. For Indigenous communities, this extends further: Indigenous data sovereignty means that Indigenous Peoples have the right to control the collection, ownership, application, and governance of their own data.
In practice, Indigenous data sovereignty rests on four core principles: that a community owns information collectively in the same way an individual owns their personal information; that the Nation controls how that data is collected, used, and shared; that community members have the right to access information about themselves or their community; and that the community should maintain physical possession of data, even when a third party holds it. For a practical breakdown of how to put these principles into action, see our Indigenous Data Sovereignty Framework. In Canada, these principles have become foundational to ethical and rights-based data governance in First Nations research and program delivery contexts, translating the concept of sovereignty into practical governance requirements that service providers - and increasingly, government partners - are expected to meet.
Consider a First Nation that operates a health clinic using electronic health records provided by a provincial health authority. Under ITSG-33 requirements for Protected B data, these records should be stored in Canada. But even when that requirement is met, governance questions remain: Who decides retention periods? Can the community access aggregated health trends for their own planning? Can they migrate to a different system without losing their historical data? Can Elders establish protocols for sensitive health information? These are sovereignty questions that compliance alone doesn't answer.
Or consider a community working with a federal department on a treaty claim. The documents are classified as Protected B and properly stored in Canada, meeting ITSG-33 requirements. But the community has no assurance about how long this information is retained, who within the department can access it, whether it could be used in future disputes, or if they can demand its return when the negotiation concludes. Technical compliance has been achieved, but sovereignty has not.
Data Residency as a Technical Baseline
Data residency refers to the physical or geographic location where data is stored and processed. For organizations working with federal systems at Protected B levels, ITSG-33 compliance effectively requires Canadian data residency. This is a good start, but it's not enough.
Canadian data residency provides several important protections: data is subject to Canadian law including privacy protections under PIPEDA and provincial legislation; foreign data access laws (such as the U.S. CLOUD Act) are more difficult to enforce against Canadian-located data; and physical location makes it clearer which legal regime governs the data and where to seek remedies for breaches.
However, meeting ITSG-33's data residency requirement is necessary but not sufficient for Indigenous data sovereignty. It establishes a technical baseline, but it doesn't establish Indigenous governance or control. It doesn't prevent Canadian government agencies from accessing data through lawful means. It doesn't address issues of consent, cultural protocols, or appropriate use. And critically, it doesn't answer the question: "Who ultimately decides what happens to this data?"
Indigenous data sovereignty goes beyond ITSG-33 compliance. It requires not just Canadian location, but Indigenous governance and control over that data. The technical requirement creates the foundation, and Indigenous governance provides the structure.
Integrating Sovereignty into Security Controls
How do we bridge the gap between technical security frameworks like ITSG-33 and the broader governance needs of Indigenous data sovereignty? Here's a practical approach:
-
Establish Data Residency Requirements: If working with Protected B data or federal systems, Canadian data residency is already required under ITSG-33 PBMM standards - ensure this is explicitly stated in all contracts. For other systems, specify Canadian data residency in all RFPs and contracts. Verify that cloud providers maintain data centers in Canada and are listed on the Government of Canada Cloud Services List where applicable. Ensure backup and disaster recovery systems also comply with residency requirements.
-
Define Ownership and Stewardship in Agreements: Clearly distinguish between data custody (who physically holds it) and data ownership (who has ultimate authority over it). Draft data governance agreements that explicitly state Indigenous ownership and specify that service providers are custodians, not owners.
-
Implement Community-Specific Access Controls: Define access roles that align with community governance. Implement consent mechanisms that reflect cultural protocols. Establish audit trails that track not just who accessed data, but why and for what purpose.
-
Require Transparent Data Processing Agreements: Demand transparency reports from service providers detailing all data processing activities. Prohibit secondary use, analytics, or AI training on community data without explicit consent. Establish clear data retention periods that align with community needs.
-
Build Capacity for Indigenous-Controlled Infrastructure: Support regional initiatives for Indigenous data centers or cooperative cloud infrastructure. Train community members in IT infrastructure management and cybersecurity. Advocate for federal funding to support Indigenous digital infrastructure.
Practical Steps Forward
If you're an Indigenous leader, IT professional, or community administrator wondering where to start, our Indigenous IT security services are designed for exactly this context. Here are concrete actions:
- Audit your current data landscape: Where is your data stored? Who has access? What are the terms of service?
- Prioritize data residency: Make Canadian data residency a mandatory requirement in all new technology procurements
- Develop a community data governance policy: Even a simple one-page policy clarifying ownership, consent, and appropriate use is better than nothing
- Engage legal support: Work with lawyers who understand both IT contracts and Indigenous rights
- Strengthen your data governance capacity by connecting with regional First Nations bodies. These organizations offer tailored resources, training, and peer networks to support community-led data sovereignty.
- Invest in capacity building: Train community members in data governance, cybersecurity, and IT management
Sovereignty as Stewardship
Data sovereignty isn't just about keeping servers in Canada or adding clauses to contracts. It's about ensuring that Indigenous communities have the power to make meaningful decisions about their digital future - decisions that reflect their values, protect their cultures, and serve their people.
At Nitap Technologies, we approach this work as modern stewardship. Just as environmental stewardship asks "How will this decision affect the land for generations?", digital stewardship asks "How will this data infrastructure affect our community's autonomy, culture, and self-determination for generations to come?"
Data residency, combined with explicit governance frameworks, provides a technical and legal foundation for self-determination. It's not the end goal. It's the starting point. The real work is building systems, agreements, and infrastructure that put Indigenous communities firmly in control of their data, their stories, and their futures.
If your community is navigating any of these questions - reviewing existing vendor agreements, building a data governance policy, understanding what PBMM compliance means for your situation, or making the case to leadership for investment in data sovereignty - Nitap Technologies can help. Our work is grounded in both technical security expertise and a genuine commitment to Indigenous self-determination.
Related Reading
Five Eyes Says AI Is Changing Cyber Risk
Why First Nations Organizations Are Higher-Value Targets Than They Think
What AI Adoption Actually Does to Your Attack Surface
Follow Our Insights
New articles on cybersecurity strategy, Indigenous digital sovereignty, and governance, delivered when we publish.
Subscribe via RSS to get new articles in your feed reader.
Terms and Legal Notice
By reading this article, you agree to our terms and legal conditions in theLegal and Privacy page.
The views shared in this article are the author's own and do not reflect the views of any other organization or employer.

Dustyn Martin-Ross
CISM, CISA, CRISC, CISSP, PMP, MBA (IT Management)
Principal Consultant and founder of Nitap Technologies. 4+ years at Deloitte leading cybersecurity assessments and governance consulting. Expertise in ITSG-33, PBMM compliance, risk management, and Indigenous data sovereignty.