Colocation or cloud: how to choose
Both put your workload in a professional datacenter. They differ in who owns the hardware, who carries the risk, and how you pay for it.
Sovereign S3 is a market term, not a certificate. See which layers matter, which S3 settings keep control with you, and which Luxembourg rules apply.
Sovereign S3 is a market term, not a standard. No EU certificate defines it. In practice, it describes S3-compatible object storage where EU law applies, EU-based teams run the service, and the customer keeps control of the encryption keys, the copies and the exit. Each of these points can be checked in the contract and in the settings.
No. S3 is an API. It defines how applications write, read and manage objects. It says nothing about who owns the provider, where the metadata sits or who can decrypt the data.
The closest official reference is the European Commission's Cloud Sovereignty Framework. It turns sovereignty into scored criteria for public procurement, and the Commission applied it to its own cloud tender in April 2026. It is an assessment method, not a label: a provider cannot hold a "sovereign" certificate under it. The Commission does encourage private organisations to use the framework, which makes it a useful reference for any buyer.
Some countries run their own qualification schemes for cloud services, such as SecNumCloud in France. These are national, cover a whole cloud service and are not specific to S3.
So when a provider writes "sovereign S3", the useful next step is to ask which layers the claim actually covers.
| Layer | What it covers | Common gap |
| Jurisdiction | Legal entity, full ownership chain, law governing the contract | Local company inside a non-EU group |
| Keys | Who creates, stores and can use the encryption keys | Provider-managed keys by default |
| Control plane | Console, identity, API endpoints, metadata, access logs | Objects in the EU, management plane elsewhere |
| Operations | Admin and support staff, subcontractors, vendor remote access | Support with admin rights from outside the EU |
| Copies | Replicas, erasure-coded fragments, platform backups | Second copy in another region or with another operator |
| Exit | Export formats, bandwidth, fees, contract terms | A legal right to leave, but no tested method |
A service can be strong on one layer and weak on another. Data location alone covers only part of the first and fifth rows.
Encryption at rest is standard everywhere. The question that matters is who can use the key. The S3 API offers several models, and providers support them to different degrees.
| Model | Where the key lives | Can the provider decrypt without you? |
| SSE-S3 | Provider key store, managed by the provider | Yes |
| SSE-KMS | Provider key management service, access set by your policies | Technically yes, so check who operates the KMS and where |
| SSE-KMS with external key store or HSM | Key service you control, or a separate third party | Only while your key service allows it |
| SSE-C | You send the key with each request; the provider does not store it | Only while a request is being processed |
| Client-side encryption | You encrypt before upload | No |
Two practical notes. First, AWS has disabled SSE-C by default on new buckets since April 2026 and points most customers to SSE-S3 or SSE-KMS instead. If your design depends on SSE-C with any provider, confirm that it is supported and enabled. Second, client-side encryption gives the strongest control, but you carry the full risk of key loss, and the provider cannot run content-based features on your data.
Object Lock stores objects in write-once-read-many (WORM) mode for a set retention period. It requires versioning. There are two modes:
Governance mode: users with a specific permission can shorten or remove the retention.
Compliance mode: nobody can shorten or remove the retention until it expires, including administrators.
A legal hold works separately and has no end date until someone removes it.
Implementations differ between providers, so test before you rely on it:
Can a provider-side administrator override compliance mode? Ask how the platform enforces it.
Does your backup software detect and use the lock, or only write to the bucket?
What happens to locked objects if the contract ends? They usually stay billable until the retention expires, which affects your exit plan.
Often, yes. Object names, tags, custom metadata and access logs regularly contain personal data: customer numbers in file names, email addresses in paths, IP addresses in logs. The GDPR applies to them in the same way as to the object content.
If the console, logging or monitoring runs outside the EU, this data can leave the EU even when every object stays in Luxembourg. That is a transfer under Chapter V of the GDPR and needs a legal basis. The GDPR also states that a court or authority order from a third country is only recognised if it is based on an international agreement (Article 48). This does not stop a foreign authority from ordering a provider in its own jurisdiction. It means the provider may face conflicting legal duties, which is why ownership and control matter.
| Rule | Who it applies to | Relevance for S3 storage |
| DORA, Regulation (EU) 2022/2554 | EU financial entities | ICT third-party risk management; every ICT contract in the register of information; contract terms on data location and exit |
| CSSF Circular 25/882 | CSSF-supervised DORA entities | Luxembourg rules on the use of ICT third-party services, including reporting and the register of information |
| CSSF Circular 22/806, as amended | CSSF-supervised entities outside DORA; DORA entities only for business process outsourcing | Outsourcing rules, including ICT and cloud outsourcing for non-DORA entities |
| Luxembourg NIS2 law of 5 May 2026 | Essential and important entities; ILR for most sectors, CSSF for finance | Supply-chain security in risk management; incident reporting within 24 hours, 72 hours and one month |
| GDPR, Regulation (EU) 2016/679 | Anyone processing personal data | Processor contracts (Article 28), international transfers (Chapter V), foreign orders (Article 48) |
| EU Data Act, Regulation (EU) 2023/2854 | Customers of cloud and other data processing services | From 12 January 2027, no switching charges, including egress fees linked to a switch |
One Luxembourg detail is worth knowing. For entities under Circular 22/806, the CSSF asks for a risk-based approach to where data is stored and processed, and for the storage locations to be written into the contract. It does not set a fixed EU-only rule. Choosing a sovereign setup is therefore a documented risk decision, not a box the regulator ticks for you.
Is "sovereign S3" a certification?
No. No EU or Luxembourg certificate exists for it. The Commission's Cloud Sovereignty Framework is a procurement assessment method, not a label a provider can hold.
If my data is stored in Luxembourg, does only Luxembourg law apply?
Not necessarily. The provider's group structure and the location of the control plane and support teams also matter. See Data residency vs data sovereignty.
Which S3 features should I test before signing?
Object Lock in both modes, versioning, lifecycle rules, multipart upload, bucket policies and the encryption model you need. Test them with your own backup and archive software, not only with a generic S3 client.
Will leaving a provider be free from 2027?
Switching charges will be banned from 12 January 2027. Normal egress, early-termination fees and your own migration work are not covered. See Cloud exit without chaos.
Legal note: This article provides general technical and regulatory information. It is not legal advice. Sources checked on 30 September 2026.
If you are reviewing where your backups should live, see our Backup as a Service options.