Datacenter.eu explains why a Luxembourg address proves little on its own, and which seven questions show who really controls your S3 storage.
An Address Is Not A Control
Object storage now holds backups, logs, archives and AI training data, and most of it speaks S3, the de facto standard that Amazon created. “Sovereign S3” appears on many price lists in Luxembourg and across Europe. Too often, the proof offered is an address. An address tells you where the disks are. It does not tell you who can be ordered to open them, who can read what is inside, or how you get your data out.
The risk is not theoretical. In June 2025, a Microsoft France director told a French Senate inquiry that he could not guarantee customer data would never reach US authorities. The US CLOUD Act lets US authorities compel providers subject to US jurisdiction to hand over data in their possession, custody or control, wherever it is stored. The European Commission’s Cloud Sovereignty Framework, published in October 2025 and used in April 2026 to award €180 million in cloud contracts to four provider groups over six years, scores providers on eight objectives and rates them on “SEAL” levels from 0 to 4. But it is a procurement tool, not a certificate. The buyer still has to ask the questions.
Control: Who Can Be Forced, And Who Can Read
The first question is who owns the operator, all the way up the chain. An EU subsidiary of a US group can still be reached through its parent. AWS opened its European Sovereign Cloud in Germany in January 2026, run by EU entities and staff, yet critics argue that the US parent keeps it within reach of the CLOUD Act. Ask for the group structure, and for any non-EU party with operational or contractual control over the service.
The second question is who can decrypt your data, which matters more than whether it is encrypted. If the provider generates and stores the keys, a legal order to the provider reaches your data. Customer-provided keys sent with each request (SSE-C) are a minimum, but the provider still handles the key in memory during every request. The stronger options are client-side encryption, or keys held in an external key store or hardware security module that you control. In a colocation setup, that module can sit in your own rack, a few metres from the storage, under your own access rules.
Operations: Who Runs It, And Where The Copies Go
The third question is where the control plane lives. A bucket can sit in Luxembourg while the console, identity system, billing, monitoring and support tools run elsewhere. Ask where metadata and access logs are stored, from which countries engineers with admin rights work, and which vendors keep remote access to the storage software or hardware. In the Commission framework, operations and supply chain together weigh 35% of the score, more than legal jurisdiction alone.
The fourth question is where the replicas and backups live, and under which law. Resilience is often solved by sending a second copy to another region or another provider, and that copy can quietly undo everything above. A sovereign primary with its backup at a US hyperscaler is not sovereign. Ask how objects are protected across sites (replication or erasure coding), how far apart the sites are, which recovery point and recovery time objectives are written into the contract, and whether the immutable copy stays with an EU operator. The 2021 fire at OVHcloud’s Strasbourg campus remains a reminder that one campus is one risk.
Technology: What “S3-Compatible” Means, And How You Leave
The fifth question is which parts of S3 the service actually supports. Data operations such as upload, download and multipart transfer work almost everywhere. Management features differ. An October 2025 comparison of popular S3-compatible services found that several lacked Object Lock and lifecycle rules. The detail matters: only Object Lock in compliance mode stops even an administrator from deleting data before its retention date, while governance mode can be bypassed with the right permission. Ask for the list of supported API calls, check consistency guarantees and rate limits, and test with your own backup software before you sign. If immutability is a regulatory requirement, ask whether the Object Lock implementation has been independently assessed.
The sixth question is what leaving costs, in money and in time. From 12 January 2027, the EU Data Act bans switching charges, including egress fees, when a customer moves to another provider or back on-premises. It does not cover everyday downloads, and it does not change physics. Moving 500 TB over a 1 Gbit/s link takes about 46 days at full line rate, and longer in practice. The Data Act sets a transition period of at most 30 calendar days. Where that is technically unfeasible, the provider must say so within 14 working days and may extend it to a maximum of seven months. Ask whether bulk export by disk or appliance is available, what bandwidth is reserved for an exit, and how normal egress is priced.
Evidence: What Goes In Writing
The seventh question ties the others together: what will the provider prove, in writing? Ask for the ISO 27001 certificate and check that its scope covers the storage service, not only the building. Ask for independent audit reports, the subprocessor list, audit rights, incident notification times and a contractual commitment on data location and access. For Luxembourg financial entities, this evidence feeds directly into DORA’s register of information and CSSF outsourcing rules. NIS2 brings similar supply-chain duties to many other sectors.
The Gaps That Remain
The market has moved. European providers offer S3 storage in EU data centres, hyperscalers have launched EU-only offerings, and the Data Act is removing exit fees. Three gaps remain. There is no EU-wide label that tells a buyer, in one line, how sovereign a storage service is. National schemes such as SecNumCloud in France and C5 in Germany do not travel across borders. “S3-compatible” still has no shared definition. And exit stays slow for large archives, even when it is free.
Until those gaps close, the work sits with the buyer. The seven questions fit into one meeting. A provider that answers them in writing, with evidence, is one you can plan with. A provider that answers with a postcode is not.
About Datacenter.eu
Datacenter.eu is a Luxembourg-based provider of colocation, cloud, connectivity and cyber resilience services, built up over 25 years. It runs ISO 27001-certified operations from its data centres in Luxembourg, with engineers based at its Luxembourg headquarters. It is part of Emios, a Luxembourg group that also includes the cloud telephony operator Mixvoip and serves more than 5,000 business customers. Its services include S3-compatible object storage operated in its Luxembourg data centres, virtual private cloud, colocation, connectivity, and backup and disaster recovery as a service.
More information: datacenter.eu
