BorgBase vs Amazon S3
BorgBase is a European alternative to Amazon S3: same cloud & hosting use case, headquartered in Malta and governed by EU GDPR, while Amazon S3 (Amazon) is based in the United States.
By the EU Alternatives team Last updated
Host Borg and Restic backup repositories with append-only protection, monitoring, and alerts. Starts at 10 GB free, with EU or US datacenter choice.
- Jurisdiction
- EU / EEA
- Primary privacy law
- EU GDPR
- US CLOUD Act exposure
- No
- Open source
- No
- Free tier
- Yes
Object storage that became the default API for the industry, so almost every backup tool, CDN and data pipeline speaks S3 first. Standard storage runs about 0.023 dollars per GB a month in US East, with 100 GB of monthly egress free and traffic above that billed up to 0.09 per GB. Amazon Web Services, Inc. sits in Seattle, while EU accounts contract with AWS EMEA SARL in Luxembourg.
- Jurisdiction
- United States
- GDPR by default
- Requires DPA + TIA
- US CLOUD Act exposure
- Yes
BorgBase vs Amazon S3 at a glance
| BorgBase | Amazon S3 | |
|---|---|---|
| Headquarters | Malta | United States |
| Data jurisdiction | EU / EEA | United States |
| Primary privacy law | EU GDPR | Requires DPA + transfer assessment |
| US CLOUD Act exposure | No | Yes |
| Best for | Teams that need cloud & hosting built for European data-protection requirements | Teams already invested in the Amazon ecosystem |
Choose BorgBase if…
- You want a provider governed by a European privacy regime
- GDPR or public-sector data-protection requirements apply to you
- You want to start free and scale up later
- You'd rather back the European tech ecosystem
Stick with Amazon S3 if…
- You depend on integrations only available in the Amazon ecosystem
- Your organisation has no EU data-residency constraints
- Migration costs outweigh the jurisdiction benefits for now
About BorgBase
BorgBase is a Maltese-registered backup hosting service built specifically for Borg and Restic, the two most widely used deduplicated, encrypted backup tools for Linux and macOS. Backups are encrypted client-side before any data leaves your machine, and append-only mode prevents any process (including ransomware) from modifying or deleting existing archives.
Each repository gets continuous monitoring: if a backup hasn't run within the configured window, BorgBase triggers alerts via email, Pushover, or webhook. A clean REST API automates repository provisioning for infrastructure-as-code workflows. Native support for Borgmatic, Vorta, and Pika Backup integrates the broader ecosystem without glue code.
Key benefits:
- Borg and Restic hosting for the two leading open-source deduplicated backup tools
- Client-side encryption so the server never has access to backup data
- Append-only mode to protect archives from ransomware or accidental deletion
- Backup monitoring with configurable alerts via email, Pushover, or webhooks
- Deduplication and compression to reduce storage footprint and transfer time
- REST API for automating repository creation and SSH key management
- 10 GB permanently free with no credit card required
- Choice of EU or US datacenter for latency and data residency requirements
BorgBase is operated by Peakford Ltd, headquartered in Naxxar, Malta, an EU member state. The service is fully GDPR-compliant, and customers using EU datacenter options keep all backup data within European jurisdiction. Technical support comes directly from active maintainers of the Borg ecosystem.
Ideal for system administrators, self-hosters, and developers who need reliable encrypted offsite backups with transparent pricing and no proprietary lock-in.
Why choose BorgBase over Amazon S3?
The decisive argument is data jurisdiction. Amazon S3 is headquartered in the United States, which means personal data processed through it can be subject to non-EU legal regimes: the US CLOUD Act, FISA 702, or similar laws depending on the provider. After the 2020 Schrems II ruling, EU organisations must carry out a transfer impact assessment for every such data flow.
BorgBase removes that overhead. As a Malta-based provider, it operates under EU GDPR, and data stays inside the EU/EEA by default. For regulated sectors such as health, public administration, and finance, that's not a nice-to-have but a requirement. For everyone else, it's concentration-risk insurance: you avoid depending on a single jurisdiction that can change the rules without warning.