Quick Answer: Colocation is a data centre service where businesses house their own servers and networking equipment inside a professionally managed, third-party facility. The provider supplies the physical space, power, cooling, physical security, and carrier connectivity. The tenant retains full ownership and control of their hardware. For Canadian enterprises, the choice of colocation provider also determines where your data physically sits, who is legally accountable for it, and which jurisdiction governs it.
IT budgets rarely have room for the full capital commitment that building and maintaining a private data centre demands. Power infrastructure, cooling systems, physical security, carrier connectivity, and the operational staff to keep it all running require specialist investment at a scale most organizations can't justify.
At the same time, the public cloud doesn't solve every problem. Egress fees, performance constraints, and growing concerns around data sovereignty have pushed a significant number of Canadian enterprises back toward infrastructure models that offer more direct control.
Colocation sits in the middle of that equation. It provides the physical infrastructure without the facility ownership burden, and more predictable costs without the metered unpredictability of cloud. But the term covers a wide range of deployment options, and the difference between a facility that genuinely meets your requirements and one that doesn't often comes down to specifications most buyers don't know to ask for.
On paper, colocation is simple. You rent the space, the provider runs the building. What gets far less attention is the shared responsibility model, meaning who covers what, and what remains entirely your obligation after the contract is signed.
In a colocation arrangement, the facility operator is responsible for:
These are infrastructure-layer commitments, backed by service-level agreements that define what happens when something in that layer fails.
The tenant is responsible for their own servers, networking gear, cabling within their allocated space, software configuration, and operating system management. A colocation contract does not automatically include 24/7 monitoring of your specific equipment, OS-level patching, or hands-on technical support for your hardware. Those are separate services, typically called managed services or remote hands, and they are priced accordingly.
The practical implication is straightforward.
If the facility loses power, that's the provider's problem to resolve. If a drive fails on your server, that's yours to handle, unless you've separately contracted for on-site technical support or backup and disaster recovery services that account for hardware failure scenarios.
Colocation is often positioned alongside cloud and on-premise infrastructure as a simple three-way choice, but there’s a lot more to think about here than most firms realize.
With on-premise infrastructure, your organization owns the hardware and operates it in your own facility. You carry the full capital cost and operational responsibility for everything from the servers to the building systems.
With public cloud, the provider owns and manages the hardware. You pay for compute on demand and have limited visibility into where your data physically resides.
Colocation facilities keep hardware ownership with the tenant while shifting the facility burden to the provider, which is the biggest advantage of colocation for businesses.
Not all colocation deployments look the same inside a facility. The type of space you select has direct implications for your physical security posture, your ability to satisfy regulatory requirements, and your operational flexibility as your environment grows. Most carriers-neutral colocation facilities offer three primary formats.
Shared cabinet colocation means you rent a defined number of colocation rack units within a cabinet that may also house equipment from other tenants. Access controls operate at the cabinet level, typically a locking door rather than a dedicated perimeter. The same power redundancy, cooling, and carrier connectivity as more exclusive formats apply throughout the facility.
This format is the most cost-effective entry point and works well for smaller deployments, organizations migrating to colocation for the first time, or workloads that do not require physical isolation from other tenants.
For businesses that need enterprise-grade infrastructure but are not yet running compliance-sensitive or high-security workloads, shared cabinet space delivers the core value of colocation at the most accessible price.
A dedicated cage is a floor-to-ceiling, physically enclosed section of the data centre floor reserved exclusively for one tenant. No other customer shares the space. Entry is controlled and access-logged at the cage boundary, separate from other areas of the facility.
This format suits organizations with stricter compliance obligations, including financial services firms, healthcare providers, and legal entities, where physical separation from other tenants is part of meeting regulatory expectations.
Cages can accommodate additional security layers, including biometric authentication, dual-factor access controls, and individual cabinet locks within the enclosure. If your security framework includes documented requirements for physical isolation, a dedicated cage is usually the minimum deployment model that satisfies them.
A private suite is an entirely dedicated room within the data centre. It offers the highest level of physical isolation available in a colocation facility and supports custom infrastructure configurations, including bespoke cooling layouts, dedicated power feeds, and proprietary equipment setups that a shared or caged environment can't accommodate.
Large enterprises, government agencies, and organizations running multi-megawatt deployments that require full environmental control typically deploy in private suites. For workloads carrying the most stringent sensitivity requirements, such as critical government systems, regulated financial data at scale, or protected health information environments, a private suite removes shared-space considerations entirely from the risk calculation.
Once you know which deployment format fits your needs, the next question is whether the facility's infrastructure can support your workloads. This is where spec sheets matter, and where the numbers are frequently misread or skipped altogether during procurement.
Power density refers to how much electrical power a single cabinet or rack can draw, measured in kilowatts per rack (kW/rack). It is one of the most consequential specifications to evaluate before committing to a facility, because it determines whether the infrastructure can physically support your equipment under real operating conditions.
Standard enterprise workloads typically require between 3 and 10 kW per rack. High-density compute environments, including GPU clusters running AI inference or training workloads, can exceed 20 to 30 kW per rack or more. A facility built or last significantly upgraded a decade ago may be spec'd for 2 to 5 kW per rack, making it physically incompatible with modern workloads regardless of what a sales conversation suggests about available space.
Before evaluating any provider, document what your current and projected workloads actually require. Migrating into a facility that can't meet your power density requirements commits you to infrastructure that creates a hard ceiling on your growth, and moving again later is expensive.
Cooling capacity scales directly with power density. The more power a colocation rack draws, the more heat it generates, and the more cooling infrastructure the facility needs to maintain stable operating temperatures. For high-density environments, conventional air cooling architectures may be insufficient. Liquid cooling and direct-to-chip cooling are increasingly deployed in facilities built or modernized for high-density compute.
Uptime Institute Tier certification is the internationally recognized standard for evaluating data centre infrastructure reliability. The four tiers reflect progressively higher levels of redundancy and expected annual uptime:
For mission-critical enterprise workloads, Tier III is the practical minimum. It is also worth understanding the distinction between a facility that is "built to Tier III standards" and one that is formally "Tier III certified."
Certification requires independent review by the Uptime Institute. Self-reported compliance is not the same as independently verified compliance, and the difference becomes visible when audit committees and CISOs start asking for documentation.
Carrier-neutral means the facility has no contractual or financial relationship with any single telecommunications provider. Multiple carriers are physically present and available for tenants to choose independently. This is meaningfully different from a carrier-affiliated facility, where your connectivity options may be limited or priced in ways that reflect the operator's commercial relationships rather than your interests.
For enterprises, carrier-neutral colocation provides two practical advantages: negotiating leverage with carriers, and protection against single-carrier failure events. When your primary carrier experiences an outage, traffic routes automatically to a secondary provider. Facilities with high-availability connectivity architecture, including physically isolated carrier interconnect rooms and diverse fibre entry points, eliminate the shared-entry single points of failure that less rigorously designed facilities carry.
Cross-connect services within carrier-neutral colocation also allow tenants to connect directly with other organizations in the same building, establishing low-latency, private connections without traffic traversing the public internet.
This is relevant for businesses with inter-enterprise data exchange requirements or hybrid cloud architectures that depend on reliable, low-latency paths to cloud on-ramps. Interconnection capabilities vary considerably between facilities and should be part of any systematic procurement evaluation.
Certifications appear on every provider's marketing page. What they represent in terms of auditable assurance varies considerably, and understanding the difference is the foundation of meaningful due diligence.
SOC 2 evaluates controls related to security, availability, processing integrity, confidentiality, and privacy. SOC 2 Type II, distinct from Type I, means those controls were independently audited over a sustained period, typically six to twelve months, rather than assessed at a single point in time. Type II carries substantially more weight with audit committees and compliance teams because it demonstrates sustained performance, not a snapshot.
ISO 27001 is the international standard for information security management systems. It signals that the provider has systematic, auditable processes for managing information security risks across operations. It's a process certification that demonstrates operational rigour, not a point-in-time vulnerability scan. PCI DSS is relevant if your workloads involve payment card data, and HIPAA compliance applies to environments hosting protected health information.
When evaluating providers, ask for the specific certifications held at the physical facility you intend to deploy in. A provider whose head office holds a SOC 2 but whose specific facility has not been independently audited is not the same as a certified facility. Ask for the certification scope documentation and the audit period, not just the certification name.
For Canadian enterprises, choosing a colocation provider is no longer a purely technical decision. It carries direct implications for regulatory obligations and legal exposure under both Canadian and American law, and in some sectors, the infrastructure choice made today will determine the outcome of an audit years from now.
PIPEDA, Canada's federal private sector privacy law, does not explicitly require that personal information be stored within Canada. It does, however, hold organizations accountable for the protection of personal information even when a third party processes it on their behalf.
If you place data with colocation facilities, your organization remains legally responsible for that information under PIPEDA's accountability principle. Contractual safeguards with your provider are not optional. They are how that accountability is operationalized in practice.
In regulated industries, the stakes are higher and more specific. Healthcare organizations in Ontario face PHIPA obligations tied to physical control over data and audit rights. Federally regulated financial institutions must assess and document jurisdictional risk under OSFI's Guideline B-13. Organizations pursuing federal government contracts regularly encounter explicit data residency requirements in RFPs that effectively mandate Canadian-hosted, Canadian-operated infrastructure.
As the Office of the Privacy Commissioner of Canada notes, organizations transferring personal information to third parties must use contractual or other means to provide a comparable level of protection, and that responsibility does not transfer with the data.
This is the compliance dimension that most colocation discussions never reach, and it is where Canadian IT leaders have the most to gain from a clear-eyed assessment.
The Clarifying Lawful Overseas Use of Data Act, known as the U.S. CLOUD Act, was enacted in 2018. It gives American law enforcement the authority to compel any U.S.-incorporated company to produce data under its control, regardless of where that data is physically stored. A U.S.-parented colocation provider operating a Toronto facility is subject to the CLOUD Act. Your data may sit in a Toronto data centre. The legal authority over it may run through Washington.
This is not a theoretical concern.
In June 2025, Microsoft France's director of public and legal affairs testified before the French Senate that Microsoft cannot guarantee data stored in France would not be disclosed to U.S. authorities in response to a valid legal order under the Act.
As Osler, Hoskin & Harcourt notes, a Canadian entity wholly owned and managed in Canada generally falls outside the scope of the CLOUD Act, but a Canadian subsidiary operating under the direct control of a U.S. parent does not.
Data residency and data sovereignty are not the same thing. Data residency describes where your data is physically stored. Data sovereignty describes which legal jurisdiction governs it. For Canadian enterprises running regulated, sensitive, or government-adjacent workloads, the distinction is not a compliance technicality. It determines which courts can compel access to your data without notifying you.
Canadian IT leaders are operating in a market where data centre capacity is genuinely constrained. According to CBRE's North America Data Centre Trends H1 2025 report, 74.3% of all capacity currently under construction in North America is already pre-leased, driven primarily by hyperscale and AI occupiers locking in infrastructure years ahead of delivery.
The enterprises that are securing space now are doing so ahead of a market that leaves latecomers competing for inventory that simply does not exist.
Qu Data Centres operates nine purpose-built, carrier-neutral colocation facilities across Calgary, Edmonton, Ottawa, Toronto, and London, Ontario. It is the only colocation operator with facilities across all five of these markets, offering a breadth of geographic coverage that no competitor in Canada can currently match.
With 17 MW of capacity available today and a full portfolio of infrastructure solutions ranging from shared cabinet to multi-megawatt private suite, Qu supports Canadian enterprises from their first colocation rack to their full infrastructure footprint. Every facility is operated by Canadian employees, under Canadian law, backed by long-term Canadian institutional capital, and with no foreign ownership chain. For CIOs and CISOs navigating sovereignty requirements, that is not a marketing point. It is a structural fact with verifiable legal standing.
Ready to see the benefits of going with colocation for your data centre needs? Book a facility tour and see what purpose-built Canadian colocation looks like in practice.
With colocation, you own the hardware and the provider supplies the physical facility, power, cooling, and connectivity. With managed hosting, the provider owns and manages both the hardware and the software environment on your behalf. Colocation gives you more control over your infrastructure and software stack. Managed hosting reduces operational burden but limits customization. Many enterprises use both in combination: colocation for owned hardware with managed services layered on top.
Check the facility's published power density specification, the maximum kW per rack they can support. Compare that against your equipment's draw under load, not idle. For GPU-heavy environments or modern AI workloads, 20 to 30 kW per rack is not unusual. If the facility caps at 5 to 10 kW, the infrastructure is not compatible with those workloads without significant investment on the provider's side, and that investment takes time.
Colocation supports a PIPEDA-compliant posture but does not satisfy it automatically. Under PIPEDA's accountability principle, your organization remains legally responsible for personal information even when a third party processes it. Your contract with the colocation provider must include provisions ensuring comparable protection. Choosing a Canadian-incorporated provider also reduces your exposure to foreign legal access regimes, which PIPEDA's accountability framework indirectly implicates through its cross-border transfer guidance.
Carrier-neutral means the data centre has no exclusive commercial relationship with any single telecom provider. Multiple carriers are physically present and tenants can choose independently. This provides negotiating leverage and protects against single-carrier outages. In a carrier-affiliated facility, your connectivity options may be limited and colocation data center pricing may reflect the operator's commercial preferences rather than market rates. For enterprises with performance and resilience requirements, carrier neutrality is a baseline expectation.
Tier III certified means the facility has been independently reviewed and approved by the Uptime Institute against its published criteria. Built to Tier III standards means the operator believes the facility meets those criteria, but has not obtained independent verification.
For most organizations, yes, particularly below 10 MW of required capacity. The capital cost of building a purpose-built data centre, covering land, construction, power infrastructure, cooling, physical security, and carrier connectivity, runs into the tens of millions of dollars before a single server is installed. Colocation converts the majority of those capital costs into predictable operating expenses and allows incremental scaling rather than committing to capacity years ahead of actual need.