Barry Lachapelle
Barry Lachapelle

For a long time, most of us didn’t really choose where our work lived. We chose tools that were easy. Tools that were fast. Tools that everyone else was already using. Google Docs is a good product. It works well. It’s collaborative. It’s deeply embedded into how modern writing and knowledge work gets done. And for years, that was enough.

But convenience has a way of hiding trade-offs until they stop being abstract. Jurisdiction, data residency, and legal exposure all sound theoretical right up until the moment they’re not. We normalized the idea that our most important writing could live anywhere, under any legal system, without ever being asked if that was acceptable.

Lately, that assumption feels harder to justify.

Why data sovereignty suddenly matters

Data sovereignty is one of those terms that sounds heavier than it needs to be. In plain language, it just means this: your data is governed by the laws of the country where it physically lives. Those laws determine who can access it, under what circumstances, and what protections or recourse you actually have if something goes wrong.

For a long time, this felt like a non-issue. Platforms promised security, uptime, and trust. Most people didn’t feel the need to look beyond that. But the world has shifted. Political pressure has increased. Surveillance programs are no longer hypothetical. AI systems ingest enormous amounts of content by default. And suddenly, the idea that your unpublished work might be subject to foreign laws, corporate incentives, or opaque processes doesn’t feel so distant anymore.

That line of thinking pushed me down a deeper rabbit hole around what I started calling “small tech”. Tools that are built to serve the people using them rather than extract value from them. I wrote more about that shift here, but the short version is this: not every piece of software needs to scale endlessly, optimize engagement, or quietly monetize everything that passes through it. Sometimes a tool just needs to do one job well and then get out of the way.

It was always important. We just chose not to think about it.

In hindsight, data sovereignty should have been part of the conversation from the beginning. We just collectively decided it was too inconvenient to care. “The cloud” became this magical abstraction that removed geography from the equation. Files floated somewhere. Servers were someone else’s problem. The trade-off was invisible, so we stopped thinking about it.

The problem is that laws don’t disappear just because software feels borderless. They still apply. They always did. We just didn’t notice because nothing forced us to.

What’s changed is that the stakes are clearer now. Writers, journalists, researchers, and organizations are realizing that unpublished work has value long before it’s public. Drafts matter. Notes matter. Context matters. And once that material passes through systems that are designed to extract value from data, control quietly slips away.

Whose laws actually govern your work

This is where the details start to matter. A service can be “hosted in Canada” and still be operated by a foreign company, subject to foreign business practices, foreign intelligence laws, and foreign legal obligations. Google Docs is a good example. Even when data is stored in Canadian regions, it’s still operated by a U.S.-based company and governed by U.S. corporate structures and legal frameworks. The same is true for infrastructure providers like AWS. Physical location is only part of the picture. Ownership and jurisdiction matter just as much.

When your documents live on infrastructure owned and operated by a company headquartered elsewhere, your relationship isn’t just technical. It’s legal. It’s political. It’s shaped by rules you didn’t vote for and courts you can’t realistically engage with. That’s not a conspiracy. It’s just how international law and corporate governance work.

That doesn’t automatically make those platforms bad. Google Docs works incredibly well, and AWS powers a huge portion of the modern internet. But it does mean the trade-off should be explicit, not buried in fine print or waved away with marketing language. If your work matters, you should at least be able to understand which laws actually apply to it.

Choosing where your work lives

Data sovereignty isn’t about nationalism or fear. It’s about agency. It’s about being able to answer a simple question honestly: where does my work live, and who ultimately controls it?

For some people, the answer will still be “I don’t care, I just need it to work.” That’s valid. But for others, especially people doing long-form writing, investigative work, or anything that requires time, trust, and discretion, the answer matters.

Choosing a platform governed by the same legal system you live under isn’t extreme. It’s basic due diligence. It’s the same instinct that drives people to choose local banks, local hosting, or local service providers when stakes are high.

Data sovereignty doesn’t mean rejecting modern tools. It means asking better questions about them.

And maybe, finally, being given the chance to answer those questions before the trade-offs are decided for you.


What is cDox?

cDox is a document platform built around the idea of data sovereignty. Documents are hosted in Canada, governed by Canadian and Quebec law, and not used for AI training or secondary purposes. It was built for people who care about where their work lives and who controls it, whether they’re writers, researchers, organizations, or anyone working with material that deserves time and discretion before it’s public. If this way of thinking resonates, you can learn more or try it at cdox.ca, or reach out if you have questions.

Made with cDox