Explainers

Sovereign S3 storage: what the term covers

Sovereign S3 is a market term, not a certificate. See which layers matter, which S3 settings keep control with you, and which Luxembourg rules apply.

Sovereign S3 storage: what the term covers

The short answer

Sovereign S3 is a market term, not a standard. No EU certificate defines it. In practice, it describes S3-compatible object storage where EU law applies, EU-based teams run the service, and the customer keeps control of the encryption keys, the copies and the exit. Each of these points can be checked in the contract and in the settings.

Is there a sovereign S3 standard or certificate?

No. S3 is an API. It defines how applications write, read and manage objects. It says nothing about who owns the provider, where the metadata sits or who can decrypt the data.

The closest official reference is the European Commission's Cloud Sovereignty Framework. It turns sovereignty into scored criteria for public procurement, and the Commission applied it to its own cloud tender in April 2026. It is an assessment method, not a label: a provider cannot hold a "sovereign" certificate under it. The Commission does encourage private organisations to use the framework, which makes it a useful reference for any buyer.

Some countries run their own qualification schemes for cloud services, such as SecNumCloud in France. These are national, cover a whole cloud service and are not specific to S3.

So when a provider writes "sovereign S3", the useful next step is to ask which layers the claim actually covers.

Which layers decide whether S3 storage is sovereign?

LayerWhat it coversCommon gap
JurisdictionLegal entity, full ownership chain, law governing the contractLocal company inside a non-EU group
KeysWho creates, stores and can use the encryption keysProvider-managed keys by default
Control planeConsole, identity, API endpoints, metadata, access logsObjects in the EU, management plane elsewhere
OperationsAdmin and support staff, subcontractors, vendor remote accessSupport with admin rights from outside the EU
CopiesReplicas, erasure-coded fragments, platform backupsSecond copy in another region or with another operator
ExitExport formats, bandwidth, fees, contract termsA legal right to leave, but no tested method

A service can be strong on one layer and weak on another. Data location alone covers only part of the first and fifth rows.

Which S3 encryption option keeps the keys with you?

Encryption at rest is standard everywhere. The question that matters is who can use the key. The S3 API offers several models, and providers support them to different degrees.

ModelWhere the key livesCan the provider decrypt without you?
SSE-S3Provider key store, managed by the providerYes
SSE-KMSProvider key management service, access set by your policiesTechnically yes, so check who operates the KMS and where
SSE-KMS with external key store or HSMKey service you control, or a separate third partyOnly while your key service allows it
SSE-CYou send the key with each request; the provider does not store itOnly while a request is being processed
Client-side encryptionYou encrypt before uploadNo

Two practical notes. First, AWS has disabled SSE-C by default on new buckets since April 2026 and points most customers to SSE-S3 or SSE-KMS instead. If your design depends on SSE-C with any provider, confirm that it is supported and enabled. Second, client-side encryption gives the strongest control, but you carry the full risk of key loss, and the provider cannot run content-based features on your data.

How does Object Lock protect backups, and what should you test?

Object Lock stores objects in write-once-read-many (WORM) mode for a set retention period. It requires versioning. There are two modes:

  • Governance mode: users with a specific permission can shorten or remove the retention.

  • Compliance mode: nobody can shorten or remove the retention until it expires, including administrators.

A legal hold works separately and has no end date until someone removes it.

Implementations differ between providers, so test before you rely on it:

  • Can a provider-side administrator override compliance mode? Ask how the platform enforces it.

  • Does your backup software detect and use the lock, or only write to the bucket?

  • What happens to locked objects if the contract ends? They usually stay billable until the retention expires, which affects your exit plan.

Is metadata also personal data?

Often, yes. Object names, tags, custom metadata and access logs regularly contain personal data: customer numbers in file names, email addresses in paths, IP addresses in logs. The GDPR applies to them in the same way as to the object content.

If the console, logging or monitoring runs outside the EU, this data can leave the EU even when every object stays in Luxembourg. That is a transfer under Chapter V of the GDPR and needs a legal basis. The GDPR also states that a court or authority order from a third country is only recognised if it is based on an international agreement (Article 48). This does not stop a foreign authority from ordering a provider in its own jurisdiction. It means the provider may face conflicting legal duties, which is why ownership and control matter.

Which Luxembourg and EU rules apply to object storage?

RuleWho it applies toRelevance for S3 storage
DORA, Regulation (EU) 2022/2554EU financial entitiesICT third-party risk management; every ICT contract in the register of information; contract terms on data location and exit
CSSF Circular 25/882CSSF-supervised DORA entitiesLuxembourg rules on the use of ICT third-party services, including reporting and the register of information
CSSF Circular 22/806, as amendedCSSF-supervised entities outside DORA; DORA entities only for business process outsourcingOutsourcing rules, including ICT and cloud outsourcing for non-DORA entities
Luxembourg NIS2 law of 5 May 2026Essential and important entities; ILR for most sectors, CSSF for financeSupply-chain security in risk management; incident reporting within 24 hours, 72 hours and one month
GDPR, Regulation (EU) 2016/679Anyone processing personal dataProcessor contracts (Article 28), international transfers (Chapter V), foreign orders (Article 48)
EU Data Act, Regulation (EU) 2023/2854Customers of cloud and other data processing servicesFrom 12 January 2027, no switching charges, including egress fees linked to a switch

One Luxembourg detail is worth knowing. For entities under Circular 22/806, the CSSF asks for a risk-based approach to where data is stored and processed, and for the storage locations to be written into the contract. It does not set a fixed EU-only rule. Choosing a sovereign setup is therefore a documented risk decision, not a box the regulator ticks for you.

Frequently asked questions

Is "sovereign S3" a certification?

No. No EU or Luxembourg certificate exists for it. The Commission's Cloud Sovereignty Framework is a procurement assessment method, not a label a provider can hold.

If my data is stored in Luxembourg, does only Luxembourg law apply?

Not necessarily. The provider's group structure and the location of the control plane and support teams also matter. See Data residency vs data sovereignty.

Which S3 features should I test before signing?

Object Lock in both modes, versioning, lifecycle rules, multipart upload, bucket policies and the encryption model you need. Test them with your own backup and archive software, not only with a generic S3 client.

Will leaving a provider be free from 2027?

Switching charges will be banned from 12 January 2027. Normal egress, early-termination fees and your own migration work are not covered. See Cloud exit without chaos.

Legal note: This article provides general technical and regulatory information. It is not legal advice. Sources checked on 30 September 2026.

If you are reviewing where your backups should live, see our Backup as a Service options.

References

  1. European Commission: Sovereign Cloud Framework explained (1 June 2026)

  2. AWS: Using server-side encryption with customer-provided keys (SSE-C)

  3. Regulation (EU) 2022/2554 (DORA)

  4. Circular CSSF 25/882 on the use of ICT third-party services

  5. Circular CSSF 22/806 on outsourcing arrangements, as amended

  6. ILR: NIS2 in Luxembourg

  7. Regulation (EU) 2016/679 (GDPR)

  8. Regulation (EU) 2023/2854 (Data Act)

Ready to get started?

A short line lowering the barrier to the next step.