Scalix WorldScalix World/ blog
← All posts

Sovereignty Is Now Law, Not Sentiment

20 July 2026 · Kiran Ravi & Akhil · 4 min read
Share on XShare on LinkedIn
Contents
  1. The law moved
  2. The structural problem
  3. ”EU region” is not sovereignty
  4. What we built
  5. The honest version
  6. FAQ

Data sovereignty used to be a preference. Something privacy-conscious teams cared about, something most startups ignored because the defaults worked and the compliance pressure stayed abstract.

That is over. Not gradually — legislatively.

The law moved

The EU Data Act is in force. It does not suggest that cloud customers should be able to switch providers and control their data. It requires it. Contracts must guarantee portability. Vendors must eliminate barriers to switching. International data transfer safeguards are mandatory.

The proposed Cybersecurity Act for Digital Autonomy — CADA — goes further. It introduces assurance levels for cloud services, effectively a certification system that grades providers on data residency, operational control, and immunity from extraterritorial jurisdiction. The highest assurance level demands that processing and storage occur within the EU, operated by EU-headquartered entities, with no legal exposure to third-country government access. This is not a guideline. It is a procurement filter. Public sector and critical infrastructure buyers will be required to meet it.

India’s Digital Personal Data Protection Act gives the government power to restrict cross-border data transfers for specific categories of personal data. The implementing rules are being finalized. When they land, companies processing certain data categories will need infrastructure that keeps data within Indian borders. Provably resident, not “primarily in India with some processing elsewhere.”

Over 40 countries now have some form of data localization requirement on the books. The EU and India matter most to us because that is where we operate and where our early users are.

The structural problem

The dominant cloud platforms are operated by US-headquartered companies. I am not making a political statement. This is a legal fact with specific consequences.

US-headquartered cloud providers are subject to the CLOUD Act, which allows US law enforcement to compel disclosure of data stored abroad. That is exactly the kind of extraterritorial legal exposure CADA’s highest assurance levels are designed to exclude. A Postgres database hosted in Frankfurt by a US company is geographically in the EU but legally accessible from outside it.

For most startups today, this does not matter. They are not in regulated sectors, not selling to public sector buyers, and their data is not sensitive enough for jurisdiction to be a concern. But the direction is clear. The EU is building a procurement framework that will require sovereign infrastructure. India is building a data protection regime that will restrict outbound transfers of specific data categories.

If you are a developer in Bangalore building a health-tech product, or a founder in Berlin targeting public sector procurement, the cloud you choose today determines whether you need a migration tomorrow.

”EU region” is not sovereignty

This distinction gets blurred in marketing constantly, so I will be blunt about it.

Running a workload in a European data centre owned by a US company does not make it sovereign. The data is geographically local but legally exposed to foreign jurisdiction. The operational control — who accesses the systems, who responds to law enforcement requests, which legal entity holds the customer relationship — remains with a US parent company.

Sovereignty means three things and most “EU region” offerings deliver only the first. The data physically stays in the jurisdiction — that is table stakes. The infrastructure is operated by an entity headquartered there, with no obligation to disclose data to foreign governments — that is where most offerings fall short. And the customer can leave, with data exports in standard formats and no lock-in through proprietary APIs that make switching prohibitively expensive. The EU Data Act makes that last part an explicit legal requirement.

What we built

We did not start with sovereignty as positioning. We started with a practical constraint: we needed to operate our own infrastructure without depending on any hyperscaler control plane.

The result is a platform running on dedicated European infrastructure we operate ourselves. Not resold capacity from a US provider. Not a “region” inside someone else’s cloud. Infrastructure we control, operated by our own entities.

Scalix World Pvt Ltd is incorporated in India. Energy FW Ltd is incorporated in the UK. Independent companies — not subsidiaries of a US parent. When we say your data stays in the EU, we mean it stays on infrastructure operated by entities with no US legal exposure.

For developers, this means a modern cloud platform — Postgres-compatible database with scale-to-zero, AI inference, serverless functions, container deployments, object storage, auth — without giving up data residency. You do not have to choose between sovereignty and developer experience.

India is next. When the DPDP implementing rules define restricted data categories, we will have infrastructure in-country, operated by the Indian entity. Not a rushed response to regulation, but a planned expansion of the same architecture.

The honest version

We are not arguing every developer needs a sovereign cloud. Most consumer apps with no regulatory exposure can use whatever works.

But if you are building something that will sell to regulated buyers in the EU, or process restricted data in India within the next two years, choosing sovereign infrastructure now avoids a forced migration later. The developers who need it should not have to sacrifice modern tooling to get it.

We are early. One EU region. No SLA — two founders, on call, building in the open. We publish our uptime at status.scalix.world because transparency is not optional when you are asking people to trust you with their infrastructure. Try the platform free at scalix.world, find us on Discord, or DM me on X if you want to be part of the founding design-partner cohort and help shape how sovereign cloud gets built.

FAQ

Why is data sovereignty now a legal requirement?

The EU Data Act is in force, CADA is coming, and India's DPDP rules are being finalized — data residency has moved from a preference to a procurement filter written into law.

Is an EU region from a US cloud provider sovereign?

No. Geography is not sovereignty: an EU region operated by a US-headquartered provider remains legally exposed to the US CLOUD Act.

What counts as real data sovereignty?

Three things together: data stored in-jurisdiction, an operator headquartered in that jurisdiction, and a legally guaranteed way to leave.

Kiran RaviAkhil
Kiran Ravi & Akhil

Building Scalix World — the AI-native neocloud: database, AI, compute, storage, and auth as one platform, on sovereign European infrastructure. Say hello on X, LinkedIn, or Discord.