If you run a business, at least some of your important information is probably sitting on someone else’s servers. A recent survey commissioned by the Office of the Privacy Commissioner of Canada found that 50% of surveyed Canadian businesses that collect customer personal information store it off-site with a third party, such as a cloud service. Major cloud providers include Amazon Web Services (AWS), Google Cloud, and Microsoft Azure, although businesses can choose from many other data storage providers.
That arrangement is convenient right up until it is not. Cloud storage can keep a business running smoothly, but it can also put accounting records, client files, contracts, source code, customer information, and digital archives just out of reach. And this isn’t just about cybersecurity threats or artificial intelligence. You may own those records, yet still be unable to get them back if the company storing them shuts down, goes bankrupt, loses access to its infrastructure, or stops cooperating.
A recent dispute involving Nine PBS, a public broadcaster in St. Louis, shows how messy that can get. The station says it lost access to its archival footage after its cloud-storage vendor became defunct. Nine PBS says it owns the material, but it still had to fight over how to retrieve it from the data center where it was stored. PCMag covers the dispute here.
The takeaway is not that businesses should swear off using other companies for data management. It is that a contract saying you own your data is only step one. You also need a realistic plan for getting it back.
Owning It Is Not Enough
A cloud-services agreement should clearly state that the customer owns its data, but it’s not enough. Ownership language alone does not ensure access or recovery. A business may still be unable to retrieve its records if the provider controls the account credentials, encryption keys, export tools, storage hardware, or technical support required to access them. The provider may also depend on data centers and subcontractors with whom the customer has no direct contract, adding another obstacle if the service fails or the relationship breaks down.
The agreement should define customer data broadly. It may include not only uploaded documents, but also attachments, metadata, activity logs, account settings, configurations, and information generated through use of the platform. It should limit the provider’s use of that data to operating, maintaining, supporting, and securing the service unless the customer expressly agrees to other uses.
Can You Get It Back?
Don’t put too much faith in an “export” button, either. Cloud service providers may host unstructured data, use a proprietary format, scatter data among different services, strip it of useful metadata, or it may be too large to move quickly without the provider’s help.
That’s why your contract should address portability: Require the provider to make data available in a documented, commonly used, machine-readable format, along with the information needed to make the export work in the real world. A law firm may need folder structures, document metadata, search indexes, and audit trails. A retailer may need customer records, order histories, product information, and transaction data.
UNCITRAL’s guidance on cloud-computing contracts explains that interoperability and portability are not necessarily guaranteed by statute. In other words, if the contract does not require export help or a workable format, the customer may be left to figure it out alone at the end of the relationship.
So, try the exit before you need it. Download a representative data set, open it outside the platform, and make sure it is complete and usable.
Vanishing Vendors
When evaluating a cloud provider, it’s easy to focus on features, price, and security. But business owners need to add one more question to the list: What happens if the company disappears?
Your agreement should require advance notice before a provider discontinues a product or materially reduces service. It should also give you enough time after termination to export and migrate data before deletion. For a business with years of records or a complex system, a seven- or 30-day retrieval window might be a countdown clock, not a meaningful off-ramp.
For critical systems, ask for a written business-continuity or vendor-failure plan. It should cover access if the provider becomes insolvent, is acquired, shuts down, or loses access to a key subcontractor. It should also identify the subcontractors that store or process your data.
The Nine PBS dispute shows why those details matter. The station says it lost access to about 50 terabytes of footage collected over roughly 70 years after Open Source Storage became defunct. The archive remained in an Iron Mountain data center under an arrangement between the two companies. Iron Mountain said it provided infrastructure, not direct access to the data, while Nine PBS sought to recover the material it says it owns. A judge initially sided with Nine PBS, but recovering the archive remained a practical and legal tangle.
Keep Your Own Copy
A good contract still requires a backup plan.
Keep independent copies of critical records through encrypted local backups, a separate cloud provider, periodic exports to a repository you control, or some combination of the three. The important word is independent. A backup held in the same provider’s environment — or one that requires the same credentials or software to restore — may be no help during a vendor outage or dispute.
This is especially important for legal professionals and regulated businesses. Client files, financial records, personnel documents, litigation materials, and records subject to retention or production duties may need to be searchable, preserved in original form, and available quickly. UNCITRAL’s guidance recognizes that cloud customers may need original-form data for investigations, audits, and evidentiary purposes.