Skip to main content
← Back to Insights
Indigenous PerspectivesGovernance

Your Community's Data Belongs to Your Community

A practical framework for First Nations communities to take real, enforceable control of their information. No IT background required.

CISM, CISA, CRISC, CISSP, PMP
April 2026·10 min read·Updated: Apr 15, 2026
AI Summary

Knowing your community has the right to its data and knowing how to exercise that right are two different things. This framework provides concrete, prescribed actions organized around three pillars - Self-Determination, Stewardship, and Responsibility - that any community member or administrator can act on today. It bridges the gap between sovereignty as principle and sovereignty as practice.

Indigenous Data Sovereignty  ·  Gasgusi

A practical framework for First Nations communities to take real, enforceable control of their information. No IT background required.


There is no shortage of principles in the world of Indigenous data governance. Important frameworks - built by Indigenous scholars and organizations - tell us what communities should value when it comes to their information. Ownership. Authority. Control. Possession. Collective benefit. Access.

These values matter. They are the foundation of a generation of advocacy and hard-won recognition.

But values alone do not lock a file cabinet. They do not encrypt a membership database. They do not stop a government agency from sharing your community's health records without permission. At some point, someone in your community needs to do something, and most frameworks stop well short of telling you what that something is.

This framework is built for that gap. It is grounded in three pillars - Self-Determination, Stewardship, and Responsibility - each of which comes with concrete, prescribed actions that any community member, administrator, or council can begin taking today, regardless of their technical background. Communities that need help turning these principles into an implementation roadmap can start with our [Indigenous data sovereignty services](/indigenous-services/).

The legal foundation for this work continues to grow. The United Nations Declaration on the Rights of Indigenous Peoples (UNDRIP) - particularly Article 31, which affirms Indigenous Peoples' rights to maintain, control, protect, and develop their cultural heritage and traditional knowledge, and Article 3, which affirms the right to self-determination - establishes data sovereignty as a matter of international human rights. Canada's *UNDRIP Act* (Bill C-15), which received Royal Assent in June 2021 and is now in force, requires the federal government to take action consistent with these rights. That legal context matters when you are negotiating contracts, asserting ownership in funding agreements, or making the case internally for investment in data governance. The rights are already yours. This framework helps you exercise them.

Knowing you have the right to your data and knowing how to exercise that right are two very different things. This framework is about the second one.

Pillar 1

Self-Determination

Self-Determination means your community decides - not a province, not a federal agency, not a software vendor - who holds your data, who can see it, and what it can be used for. This is not a political statement. It is a governance decision that has to be made actively, in writing, before anyone else makes it for you.

In practice, this looks like establishing a Data Governance Policy that reflects your community's laws, customs, and values. It means identifying - by name or by role - who in your community is the authority over specific types of information. It means making those decisions before signing contracts with service providers, not after.

Prescribed actions

  • Designate a Data Stewardship Lead - a person (not just a role) in your community who is responsible for data governance decisions. This does not need to be someone with an IT background.
  • Write a one-page Data Sovereignty Statement - in plain language, stating who your data belongs to, who can access it, and under what conditions it may be shared. Have Council ratify it.
  • Review every active contract with external service providers and ask a single question: who owns the data if the relationship ends? If the answer is unclear, that contract needs to be renegotiated.
  • Require a data sovereignty clause in all funding agreements, grant applications, and research partnerships that involve the collection or use of community data. Any research conducted on or with your community should include community ownership of resulting data, a right to review findings before publication, and a right to withdraw data if the relationship ends.
  • Establish a Community Data Ethics Review process - even an informal one - so that external requests to access or study your community's information are assessed against community values before approval is granted. This does not need to be a formal committee. It needs a named person, a defined process, and a written record.

Pillar 2

Stewardship

Stewardship is the ongoing, active care of your community's information over time. It means treating data the way your community treats land or traditional knowledge - not as a static asset that was sorted once and can be forgotten, but as a living responsibility that requires tending.

Good stewardship means knowing what data you have, where it lives, and who is responsible for keeping it accurate, safe, and accessible to the right people. It also means honouring the cultural weight that some information carries - recognizing that not all data is equal, and that some knowledge is sacred, not administrative.

Prescribed actions

  • Create a data inventory - a simple list of every type of information your community holds (membership records, health data, land use records, ceremonial knowledge, financial records). You cannot protect what you have not named.
  • Classify your data by sensitivity and cultural significance. At minimum: general (public-facing), administrative (internal), personal (private, restricted), and sacred (governed by community protocol, never shared externally without explicit consent).
  • Establish a retention and review cycle - decide how long each category of data is kept, who reviews it annually, and how it is properly retired when it is no longer needed.
  • Identify the custodians of your community's sacred and traditional knowledge - Elders, knowledge keepers, or designated title-holders recognized by your Nation's governance. Document, in whatever form is appropriate to your community, who may access records of that knowledge, who may authorize sharing it, and under what conditions. This protocol sits above any IT or privacy policy and should be treated as such.
  • Develop staff data handling agreements for any employees or contractors who access personal, administrative, or sacred community data. These do not need to be lengthy legal documents. They need to make expectations explicit, document that the person understands them, and be on file.

Pillar 3

Responsibility

Responsibility is the execution layer. It is where sovereignty and stewardship become real - because sovereignty that is not enforced is just aspiration, and stewardship without implementation is just good intentions. This pillar is the one that other frameworks most consistently leave out.

Responsibility means implementing the technical and procedural controls that make your policies enforceable. It means encrypting your data so it cannot be read by unauthorized parties. It means mapping your data flows so you know exactly where information moves - within your systems, between departments, and out to external parties. And it means ensuring that the keys to your encrypted data stay where they belong: in your community's hands, governed by your nation's own protocols and values.

Prescribed actions

  • Map your data flows. Trace where information enters your systems, who touches it, where it is stored, and where it leaves. This does not require technical expertise - it can start as a simple diagram drawn with a pen. The goal is visibility: no data should be moving through your community's systems in ways that no one is aware of.
  • Implement encryption on all stored data that contains personal or sacred information. Ask your current technology provider a direct question: "Is our data encrypted at rest and in transit?" If they cannot answer clearly, that is a problem that needs to be solved before the next breach, not after.
  • Protect your community's encryption keys in a way that aligns with your nation's governance and values. Who holds a key is a sovereignty decision, not just a technical one. Your community - not a vendor, not a cloud provider - should control the ability to access, lock, or revoke access to your own data.
  • Require multi-factor authentication (MFA) on all community accounts and systems that hold personal, administrative, or sacred data. Enabling MFA is one of the most effective single controls against unauthorized access and costs nothing to implement on most modern platforms. It is a governance decision, not a technical project.
  • Establish a written Incident Response Protocol: a short document that answers three questions - if community data is accessed, stolen, or lost without authorization, who is notified first; who is responsible for stopping further damage; and how are affected community members informed. Having this decided before an incident occurs is the difference between a managed response and a crisis.
  • Review your community's cyber insurance position. Many First Nations carry no coverage - or inadequate coverage - for data breaches, ransomware, or unauthorized disclosure of member records. This is a risk management gap that can be identified and addressed with a single conversation with an insurance broker who understands public sector and Indigenous governance contexts.

These three pillars do not require a lawyer on retainer or an IT department. They require a community that is willing to make decisions and follow through on them - which is exactly what First Nations have been doing, on their own terms, for thousands of years.

What this framework provides is a structured way to apply that decision-making capacity to the digital world - where the stakes are just as high as they have always been, and where inaction is never neutral.

If your Nation is working through these questions in real time, our [First Nations IT governance and cybersecurity services](/indigenous-services/) are built to translate data sovereignty principles into scoped assessments, governance controls, and implementation plans.

Related Reading

Follow Our Insights

New articles on cybersecurity strategy, Indigenous digital sovereignty, and governance, delivered when we publish.

Subscribe via RSS to get new articles in your feed reader.

Terms and Legal Notice

By reading this article, you agree to our terms and legal conditions in theLegal and Privacy page.

The views shared in this article are the author's own and do not reflect the views of any other organization or employer.

Dustyn Martin-Ross, Principal Consultant and founder of Nitap Technologies

Dustyn Martin-Ross

CISM, CISA, CRISC, CISSP, PMP, MBA (IT Management)

Principal Consultant and founder of Nitap Technologies. 4+ years at Deloitte leading cybersecurity assessments and governance consulting. Expertise in ITSG-33, PBMM compliance, risk management, and Indigenous data sovereignty.