Your Cloud Data Might Be Trapped Forever

TL;DR: A public TV station lost access to 70 years of archives after its cloud vendor failed. The data is safe on servers in a third-party data center, but a contractual dispute means no one can legally access it.
Key facts
- Category
- Infrastructure
- Impact
- High
- Published
- Source
- TechRadar
Full summary
A TV station's cloud vendor failed, trapping 70 years of archives in a data center owned by a third party.
A St. Louis public TV station, Nine PBS, is suing to recover 70 years of its digital archives after its cloud storage vendor went out of business. According to reporting from TechRadar, the vendor, Open Source Storage (OSS), ceased operations and cut off access to the station's 50 terabytes of data. The files themselves are not lost; they sit on servers inside a data center operated by Iron Mountain. However, Iron Mountain argues it cannot simply hand over the hardware. Its contract was with the now-defunct OSS, not the TV station. It claims that giving another company's property to a third party would be a breach of contract and could compromise the security of its other clients, creating a legal and logistical nightmare.
This situation highlights a critical but often misunderstood aspect of the cloud: the supply chain. The data is physically safe but contractually inaccessible. Nine PBS had an agreement with OSS for cloud storage. OSS, in turn, did not own its own data centers but leased space, power, and cooling from a colocation provider—in this case, Iron Mountain. This multi-layered model is common in the cloud industry. The problem arises when the middle layer fails. Iron Mountain's legal duty is to its direct customer, OSS. It has no formal relationship with Nine PBS. When OSS collapsed, it created a legal vacuum, trapping the TV station's data behind a contractual wall. Iron Mountain is essentially a landlord who cannot give a tenant's property to a stranger, even if that stranger rightfully owns the contents of the property.
This case is a stark warning for any organization that relies on cloud services, from small startups to global enterprises. It reveals the hidden counterparty risk that exists one or two steps down your vendor's supply chain. Most companies conduct due diligence on their direct vendors, checking their financial stability and security posture. But very few dig deeper to understand who their vendor's critical suppliers are. This incident proves that your data can become collateral damage in a business failure you had no visibility into. For CTOs, founders, and IT leaders, it's a powerful reminder that "the cloud" is not an abstract service; it is a physical stack of hardware, real estate, and legal agreements. A break at any point in that chain can jeopardize your most critical assets.
The primary business takeaway is the need for more sophisticated vendor due diligence and stronger contracts. Companies must now ask their cloud providers pointed questions about their own infrastructure dependencies. Do you own your data centers or lease from a third party? What are the contractual provisions if your company goes out of business? Crucially, is there a legal mechanism for us, the end customer, to recover our data directly from your infrastructure provider in a worst-case scenario? This is often referred to as a "right to recover" or "step-in rights" clause. Without these explicit protections, you are implicitly trusting not just your vendor, but a whole chain of companies you may have never heard of. This case will likely drive a demand for greater transparency and more resilient contracts across the industry.
The outcome of the lawsuit between Nine PBS and Iron Mountain will set an important precedent. If the court sides with the TV station, it could redefine the responsibilities of data center operators to the end-users of their tenants' services. If it sides with Iron Mountain, it will reinforce the existing legal separation between providers in the cloud stack. This would place the burden firmly on customers to architect their disaster recovery plans around multi-vendor or multi-provider strategies. Regardless of the verdict, the story is a clear lesson: a robust disaster recovery plan isn't just about having backups; it's about ensuring you have a legally and logistically sound path to actually access them when your primary vendor disappears.
Why it matters
This is a stark warning about the hidden risks in your cloud vendor's supply chain. It shows that your data can become trapped and inaccessible if your vendor's *vendor* fails, a risk that standard due diligence often misses.
Business impact
This case will force companies to demand deeper transparency from their cloud providers. Expect more scrutiny on contracts, with new clauses allowing customers to recover data directly from third-party data centers in the event of a vendor collapse.
Tags
Related on Notifire
Related stories
Primary source: TechRadar