Canada's Telecom Sector Has No Disclosure Requirement for US Tech Dependency That Needs to Change
Minister Solomon,
I'm writing as a Saskatoon constituent because you've called digital sovereignty the most pressing policy and democratic issue of our time, and I want to put a concrete case in front of you: Canada's telecom sector, the infrastructure carrying our most sensitive personal and financial data, has no requirement to disclose or limit its dependency on U.S.-controlled technology, and there is currently no regulator with a mandate to change that.
Years ago I discovered SaskTel had moved its email infrastructure onto Microsoft's platform; not because SaskTel told me, but because I called support about an IMAP issue and their own technician seemed surprised IMAP access still worked at all. I ended up finding a new provider for my email specifically to get off that infrastructure. SaskTel's desktop computers also still run Windows. I have no way to confirm whether my personal information and direct-debit banking details sit on Microsoft-linked infrastructure as well and this exactly the problem. Customers should not have to guess, and a company should not be able to make that call for us with zero disclosure.
This isn't a hypothetical risk. In 2025, after the U.S. sanctioned the International Criminal Court's chief prosecutor, Microsoft cut off his official email and cloud access, then did the same to several ICC judges. This past May, Microsoft was accused of handing Dutch regulators' unredacted internal data to the U.S. House of Representatives the regulators whose job is enforcing EU law against U.S. platforms. And this past weekend, after President Trump ordered Lake Ontario renamed "Lake America," Google complied within a day, and the change rippled into Ontario government and Crown corporation websites before anyone in Ontario had agreed to it. Companies that depend on U.S. infrastructure are discovering, again and again, that they don't fully control their own operations.
The CRTC has no mandate to look at this. I'd like to see ISED close that gap:
- Require telecom providers, SaskTel and the national carriers alike, to publicly disclose which parts of their infrastructure (email, billing, customer data storage, desktop software) run on U.S.-controlled platforms, and to notify customers when that changes.
- Issue a policy direction to the CRTC to weigh foreign-jurisdiction dependency as a factor in telecom regulation, the way it already weighs competition and consumer protection.
- Ensure Bill C-8's critical cyber systems framework explicitly covers foreign-vendor dependency risk for telecommunications, not just breach response.
Europe has stopped waiting to find out the hard way: France is migrating 2.5 million civil servants off Microsoft and onto Linux, and Germany funds its own sovereign infrastructure. Canada's telecom sector, the backbone everything else runs on, shouldn't be the last piece left exposed.
I'd appreciate a substantive response, not a form letter, given how quickly this is moving.
Reann Legge
I use the pronouns She/her
reannlegge.ca