This category covers file storage and sync, object storage, and backup and recovery services. Organisations use it for shared documents, archives and application data, and as the last line of defence against ransomware, hardware failure and accidental deletion.
A backup is a complete copy of your organisation, usually kept for years, so its sovereignty profile is that of the most sensitive data you own. What matters most is who holds the encryption keys. If the provider manages them, it can technically read the data and may be compelled to disclose it. If you hold them and encrypt on the client side, the provider stores only ciphertext. Lock-in is the second risk: a proprietary object-storage API, large data volumes and egress fees can make leaving expensive, which is why the EU Data Act addresses switching between data processing services.
In a European option, check whether client-side or customer-managed keys are offered, whether backups can be made immutable and kept in separate locations, which regions hold replicas, and whether open standards such as S3-compatible APIs or WebDAV are supported.