TL;DR — Key Takeaways

  • Nine PBS legally owned more than 50TB of archival material but still needed court intervention to regain access after its storage provider stopped responding.
  • The case highlights the difference between owning data and having the operational ability to retrieve, restore and use it.
  • Similar incidents involving Nirvanix, Megaupload and StorageCraft show that vendor failure, government action and technical mistakes can make legitimate data inaccessible.
  • Multiple backups are not truly independent if they depend on the same provider, credentials, administrators or control plane.
  • Organizations need portable backups, independent recovery paths, preserved metadata and regular restoration testing to maintain genuine operational sovereignty.

When is a safe backup not a safe backup?

When you need a judge to retrieve it.

That is the situation confronting Nine PBS, the public television station in St. Louis that has spent months trying to recover more than 50 terabytes of programming, photographs, videos and other archival material spanning 70 years of the station’s history.

The archive includes coverage of East St. Louis, the Great Flood of 1993, the COVID-19 pandemic and decades of life across the region. It belongs to Nine PBS. No one seriously disputes that. A Missouri court has already affirmed that the station owns the material and has an immediate right to possess it.

But Nine PBS still could not access it.

The station’s cloud-storage provider, Open Source Storage, stopped responding as the parties approached a March 2026 contract renewal. On the day the existing agreement expired, OSS cut off access to the archive without providing the contractually required 30-day period for Nine PBS to retrieve its data. The station subsequently discovered that the OSS website had disappeared and that the company was listed as delinquent by the Colorado Secretary of State.

Nine PBS eventually learned that its archive was stored on systems housed inside an Iron Mountain data center in Denver. It asked Iron Mountain to preserve and return the material, even offering to pay the reasonable costs of doing so. When that failed to produce the archive, the station sued.

Think about that for a moment. Nine PBS had entrusted its history to a company specializing in storage. The underlying infrastructure was housed in a data center operated by Iron Mountain, one of the most recognizable names in information management. The data apparently remained physically intact. Yet the station needed two lawsuits, judicial intervention and now a technically qualified third party merely to reach property everyone agreed it owned.

That is more than a backup failure. It is a failure of data sovereignty.

Ownership Is Not Control

Iron Mountain is not necessarily the villain here. Its contractual customer was OSS, not Nine PBS. Iron Mountain says it does not have access to the station’s data and has raised legitimate concerns that Nine PBS’s archive may be technically commingled with information belonging to other OSS customers. Turning over the wrong systems or allowing an unfamiliar party to manipulate them could damage or expose someone else’s data.

A Denver judge has now ordered Iron Mountain to cooperate while Nine PBS identifies a third party capable of accessing and extracting the archive safely. That may ultimately produce a satisfactory ending.

But Iron Mountain’s explanation does not weaken the larger argument. It strengthens it.

Nine PBS owned the content, but it did not control the infrastructure containing it. It apparently did not possess an independently usable copy of the metadata, credentials, system knowledge and recovery tools required to retrieve it. The station’s legal relationship was with one company, its data resided inside another company’s facility, and the people who understood how the pieces fit together disappeared.

The archive belonged to Nine PBS in every legal sense. In an operational sense, however, the station was no longer sovereign over it.

That distinction represents an important expansion of what we mean by data sovereignty.

The term is generally used in discussions about geography and jurisdiction. Where is the information physically stored? Which country’s laws apply? Can a foreign government demand access? Do privacy regulations require the data to remain within a particular region?

Those are important questions, but the Nine PBS case exposes another dimension. Data residency asks where the data sits. Legal sovereignty asks whose rules govern it. Operational sovereignty asks whether the purported owner can actually retrieve and use it when the intermediary fails.

Nine PBS’s archive was stored in the United States by American companies. The station held legal title to the material. None of that gave it the independent ability to restore its own backup.

The Problem Predates the Name

Some of the best warnings about this problem occurred before data sovereignty became a regular part of the technology industry’s vocabulary. But the issue already existed. We described pieces of it as disaster recovery, business continuity, vendor risk, data portability, escrow or exit planning.

The underlying question was always the same: Who ultimately controls the information on which the organization depends?

In 2013, cloud-storage provider Nirvanix collapsed after failing to secure additional funding. Customers were initially given roughly two weeks to begin moving enormous volumes of data elsewhere. Nirvanix reportedly held about 40 petabytes and provided services through relationships with larger companies, including IBM.

Customers may have believed they had selected a stable storage service, perhaps one associated with a global technology company. But behind the familiar name was another provider whose financial failure suddenly became their emergency. The data still belonged to the customers. The available time, bandwidth and cooperation required to recover it belonged to someone else.

The 2012 government shutdown of Megaupload revealed a different version of the same problem. Federal authorities were investigating the company and its executives for alleged copyright violations, but shutting down the service also locked innocent customers out of legitimate material stored there.

One of them was sports videographer Kyle Goodwin, who used Megaupload to store professional footage. When his local hard drive failed, he discovered that recovering his lawful material required a prolonged court fight. The government had acted against the provider, but the practical consequence extended to customers who had never been accused of wrongdoing.

Like Nine PBS, Goodwin owned the content. Someone else controlled whether he could reach it.

Then there is the particularly uncomfortable case of StorageCraft, which became part of Arcserve. In 2022, human error during work on its cloud environment compromised critical metadata connecting stored backup data to the systems required to use it. Some customers’ cloud backups became unrecoverable.

The company providing disaster recovery had suffered a disaster from which some of the backups could not be recovered.

These incidents did not necessarily use the vocabulary of operational sovereignty. They did not have to. The principle was already there: Legal ownership of information is of limited value when every practical means of retrieving it remains under someone else’s control.

What has changed is the scale of that dependency.

Organizations once outsourced storage capacity. Today, they may outsource the applications that create the data, the identity service that controls access, the encryption keys that unlock it, the metadata that makes it intelligible, the backup catalog that locates it and the recovery platform required to restore it. They can own every bit on paper while controlling almost nothing needed to make those bits usable.

Three Copies Can Still Be One Backup

This does not mean organizations should abandon the cloud or build their own data centers. Most organizations could not reproduce the security, reliability and operational expertise available from leading cloud providers even if they wanted to.

The lesson is that outsourcing infrastructure cannot mean outsourcing ultimate responsibility.

UniSuper demonstrated the difference in 2024. A Google provisioning error caused one of the Australian pension fund’s private-cloud environments to be automatically deleted. This was not ransomware, sabotage or a natural disaster. A parameter had been left blank during provisioning, resulting in the environment receiving an unintended expiration date.

UniSuper and Google eventually restored operations. Crucially, UniSuper had backups with an additional service provider. According to their joint statement, those backups minimized data loss and significantly improved the recovery effort.

That is operational sovereignty in practice. UniSuper used the cloud but did not make one cloud provider the only possible path back to its information.

Multiple copies do not automatically provide that protection. An organization can maintain three copies in separate regions and still have only one effective backup if all three sit inside the same provider, depend on the same identity system or can be deleted through the same administrative control plane.

Three copies controlled through one account are three copies but one failure domain.

A genuinely independent backup requires separation that matters. It should not depend on the same vendor, credentials, administrators, encryption-key system or contractual relationship as the primary environment. It must use a format that can be moved and restored elsewhere. The organization must possess the metadata and technical knowledge required to reconstruct the information. Contractual exit rights should remain enforceable if the vendor fails, is acquired or stops responding.

Most importantly, the organization must test the restoration process. A backup that has never been restored is not proof of recoverability. It is an assumption.

Seventy Years in Someone Else’s Hands

The Nine PBS story is compelling because the endangered data is not merely a collection of invoices, customer records or application logs. It is part of the recorded history of St. Louis.

The archive documents communities, disasters, public debates, cultural moments and ordinary lives that might otherwise disappear from memory. Technology allowed the station to consolidate and protect that history. The same arrangement then placed it beyond the station’s immediate reach.

Nine PBS may recover everything. The court has created a path forward, Iron Mountain has been directed to cooperate, and there is no indication that the archive has been deliberately destroyed. That would be a welcome outcome.

It would not make the underlying failure any less serious.

An organization should not need to locate former employees of a defunct vendor, untangle competing ownership claims and obtain a judicial order to restore its backup. If that is the recovery plan, it is not a recovery plan.

Data sovereignty did not suddenly appear when governments and technology companies gave it a name. Organizations have always needed to know who ultimately controlled their information. What is changing is our recognition that sovereignty cannot be measured only by where the data resides, which laws apply or whose name appears as owner in a contract.

It must also be measured by what happens when the vendor disappears, the administrator makes a mistake, the government seizes the service or the company controlling the infrastructure refuses access.

Nine PBS owned 70 years of its own history. It did not control the path required to retrieve it.

If you need a judge to restore your backup, the data may legally belong to you. But it was never truly under your control.

Frequently Asked Questions

What happened to Nine PBS’s archive?
Nine PBS lost access to more than 50TB of historical programming, photographs and video after its cloud-storage provider stopped responding and cut off access. The station ultimately needed legal action and assistance from a qualified third party to pursue recovery.
Why are multiple copies not always enough?
Three copies can still represent one failure domain if they all rely on the same cloud provider, account, identity system or administrative controls. A genuinely independent backup needs meaningful separation.
How can organizations make backups more resilient?
Backups should use independent providers or failure domains, portable formats, separate credentials and encryption systems, and preserved recovery metadata. Organizations should also regularly test restoration rather than assuming a backup will work when needed.

SHARE THIS STORY