Odaseva for Data Sovereignty

Control where your data lives, who can access it, and where it flows

55%

According to a joint OECD-WTO business survey, combined storage and flow restrictions can increase data management costs by up to 55%.
Canada introduced Bill C-36 in June 2026 to enact the Protecting Privacy and Consumer Data Act (PPCDA), replacing PIPEDA and promoting Canada's data sovereignty. This reflects a broader global trend: data sovereignty has become a defining regulatory challenge of the digital era, accelerated by geopolitical tensions, extraterritorial reach threats, and the rapid expansion of cloud infrastructure across borders.

Data sovereignty encompasses the ability to control where your data is stored (data residency), who can access it (data access), and where it can flow (data transfers). Every country is moving toward tighter constraints, but at different speeds and with different tools. The costs to regulated businesses are real: according to a joint OECD-WTO survey, storage and flow restrictions can increase data management costs by up to 55%.

Odaseva gives enterprises the tools to meet these sovereignty requirements, wherever they operate. By combining flexible data residency, granular access controls, and secure and auditable data transfers, Odaseva lets enterprises adapt to each jurisdiction's and industry’s rules without compromising the global view of their Salesforce data or necessary operational flexibility.

Different Countries’ Approaches to Data Sovereignty

Canada

No federal residency mandate, but strict provincial rules on storage, access, and transfers

Canada's federal privacy law, PIPEDA, never mandated that personal data stay in Canada. It governed how data was protected, not where it lived. The incoming PPCDA changes this framework by requiring formal privacy impact assessments before data crosses the border. It also creates a new regulator with binding enforcement powers and fines up to $25M or 5% of global revenue. The deeper sovereignty gap remains the US CLOUD Act: a Canadian organization's contracts with a US cloud provider cannot override a valid US government access order.

Switzerland

No blanket residency mandate, but sector-specific rules impose strict storage and access controls

Switzerland's revised Federal Act on Data Protection (revFADP), in force since September 2023, mirrors GDPR closely enough that the EU confirmed Swiss adequacy in January 2024. There is no blanket data residency mandate. Transfers to adequate countries flow freely, and standard contractual clauses cover the rest. Banking and healthcare sectors go furthest, with FINMA and medical secrecy laws effectively requiring data to remain in Switzerland under Swiss-controlled encryption keys.

China

Strict residency requirements, government-controlled access, and heavily restricted transfers

China operates one of the world's strictest data sovereignty environments, built across three overlapping laws: the Cybersecurity Law (CSL), the Data Security Law (DSL), and the Personal Information Protection Law (PIPL). Critical information infrastructure operators and large-scale data processors must store data on servers physically located in China. Transfers abroad require either a government security assessment, a standard contract filed with regulators, or a certification, depending on data volume and sensitivity. "Important data," a broad category covering national security and economic interests, may be blocked from leaving entirely. PIPL also applies extraterritorially to any processing that affects persons in China, regardless of where the processor is based.

Control where your data is stored

Store a secure, owned copy of Salesforce data

Odaseva stores a copy of production and historical Salesforce data at the location of choice, across more than 10+ regions worldwide, with the ability to open new locations based on specific residency requirements. Enterprises retain a complete, accurate, and auditable copy of their data that they truly own and control.

Segregate your most sensitive CRM data in a localized storage vault

For enterprises that must keep their single-Org Salesforce architecture intact, Odaseva Data Encryption enables storing the most regulated data in the location of choice, segregated from the rest of Salesforce data, while keeping it fully accessible through the CRM interface.

Control who accesses your data and reach true data sovereignty

Limit exposure of clear-text data to only those who should see it

Odaseva ensures sensitive data does not appear in clear text to unauthorized users, whether through masking PII or PCI at scale across all types of sandboxes for internal developers or contractors, or by adding an extra layer of access rights for the most sensitive data available on Salesforce. Where data must remain accessible, infrastructure-level immutability ensures it stays protected and tamper-proof.

Eliminate exposure to external parties

Odaseva eliminates vendor risk by ensuring customer data can never be accessed in clear text by anyone but the customer. The patented no-view provider architecture means Odaseva itself can never see customer data in clear text. For enterprises seeking the highest level of protection against extraterritorial reach, options include storing encryption keys outside the jurisdiction of any foreign government via BYOK, or leveraging the Data Encryption Vault to store the most sensitive data in the location of choice. Either approach makes the enterprise the sole sovereign over its CRM data.

Control where your data flows

Safely share information within your group

We allow different group entities that are subject to different regulations to automatically block cross-border transfers of sensitive PII, while still giving global teams compliant, anonymized access to the data they need for business intelligence.

Prevent unauthorized third-party access to data in-transit

By default, Salesforce data exiting the platform is transmitted in clear text, leaving organizations dependent on each integration partner to safeguard it correctly as it flows downstream. Zero Trust Connect closes that gap with end-to-end encryption between sender and recipient, making sure data is encrypted before it leaves Salesforce. The encryption key is held by the customer, on the system of their choice.

Resources

Data Security

Data Recoverability

Why Odaseva

FAQs

Can the concept of data sovereignty be treated more broadly?
Yes. This page focuses on the traditional definition of data sovereignty, centered on residency, access, and transfer. But sovereignty can extend further.

Operational sovereignty is about maintaining control over strategic IT decisions and minimizing dependency on any single provider, which Odaseva supports through robust backup and restore capabilities that let enterprises recover their data independently, on their own terms.

Technology sovereignty is about retaining the flexibility to choose and change underlying tech stack without being locked in, which Odaseva enables through Data Edge.

These are nuances we regularly help customers tackle as part of a complete data sovereignty strategy.
Can Odaseva guarantee that data is not only stored and accessible according to sovereignty requirements, but also fully traceable?

Yes. Beyond controlling where data lives and who can access it, Odaseva tracks and logs activity at every level, at any time. Org Portability tracks all data flow activities as data moves between entities or systems, Data Trail captures detailed activity occurring within Salesforce itself, and platform audit trail capabilities log all actions taken within Odaseva. Together, they give enterprises a complete, auditable record of who did what, where, and when, across both the source system and the platform managing their data.

My company just acquired a foreign entity. How can Odaseva help me navigate data sovereignty challenges?

M&A often surfaces sovereignty challenges, especially when an acquired entity sits in a jurisdiction with strict residency or transfer rules, like a Chinese entity whose PII can never legally cross its border. Odaseva supports enterprises through every stage of the transition, from cleaning and protecting data before it moves, to migrating it compliantly, to connecting it securely across the newly combined business organization.

Can Odaseva operate in China?

Yes. Odaseva is the leading Enterprise Data Platform for Salesforce on Alibaba Cloud, operated locally in partnership with Digital China Cloud. This local presence lets enterprises maintain compliant, resilient Salesforce operations in China under strict data sovereignty regulations, while still preserving a unified global view of their customer data.