SaaS backup requirements: GDPR, NIS2 and compliance explained
Your CRM holds customer relationships. Your project management apps hold delivery plans, decisions and deadlines. When that information disappears, a compliance policy is only useful if your team can put it into practice.
Do you need SaaS backups for compliance? GDPR requires security appropriate to risk, including timely restoration and regular testing where appropriate. It does not universally require a third-party backup vendor, daily backups or a fixed retention period. NIS2 explicitly includes backup management and disaster recovery for entities within its scope, through national implementation. Your task is to identify the applicable requirements, choose suitable controls and demonstrate that recovery works. GDPR Article 32; NIS2 Article 21.
ProBackup can support that work with independent daily backups of supported SaaS data. Your organisation still owns its risk assessment, policies and recovery decisions.
Which requirements apply to your organisation?
Start with the data you process, the services you provide and the countries in which you operate. Using a cloud app does not, by itself, put every business under the same rules.
EU GDPR
Personal-data processing within its material and territorial scope. This includes processing connected to an EU establishment and certain non-EU processing involving offering goods or services to people in the EU or monitoring their behaviour there.
When buying a backup tool, understand which personal data is involved, the risks to people, your controller or processor role, and the recovery and deletion controls needed. See Articles 2, 3 and 32
NIS2 and national implementing laws
Specified entity types in Annexes I and II, generally medium-sized or larger, with exceptions that bring some entities into scope regardless of size.
When choosing a backup vendor, review your precise sector, entity type, size calculation, national rules and competent authority. See Articles 2–3 and Annexes I–II.
UK GDPR
A separate UK legal regime. The ICO guidance discussed below is UK-specific.
Which UK obligations and guidance apply to your backup and erasure process. See the ICO’s right-to-erasure guidance.
SOC 2 assurance
An examination and reporting framework for service-organisation controls; it is not legislation.
The report’s system boundary, criteria, period, findings and customer responsibilities. See AICPA’s SOC guidance.
ISO/IEC 27001
An information security management system standard, not a law. Adoption or certification may be a contractual expectation.
How backup fits your risk treatment and the scope of your information security management system. See ISO/IEC 27001.
DORA
Financial-sector organisations should also assess . Where Article 12 applies, it addresses documented backup policies and restoration procedures, including periodic testing. Scope, exemptions and simplified-framework provisions matter. A general SaaS backup policy is only one part of that assessment. DORA, Articles 2, 12 and 16.
GDPR: choose recovery controls that match the risk
Article 32 addresses both controllers and processors. Its risk-based approach includes protecting confidentiality, integrity, availability and resilience; restoring access after physical or technical incidents; and regularly assessing whether safeguards work. GDPR Article 32.
For a SaaS buyer, the practical question is: could we recover the personal data needed to resume this process, within a time we can justify?
Consider a CRM import that replaces customer contact details with incorrect values. Check whether your recovery method can recover the affected records, identify a usable earlier version and preserve legitimate changes made since the import. A backup that exists but cannot support that workflow leaves a gap in your recovery plan.
An independent service can help address such gaps. The choice should follow your risk assessment and recovery tests. Purchasing a backup subscription does not establish compliance by itself.
NIS2: backup management belongs in the continuity plan
Article 21(2)(c) expressly includes business continuity, backup management, disaster recovery and crisis management. Article 21 also addresses supply-chain security and evaluating the effectiveness of cybersecurity measures. NIS2 Article 21.
Scope matters. Covered sectors include energy, transport, health, digital infrastructure and specified manufacturing activities, among others. The detailed entity definitions and size rules apply; some smaller entities are covered under exceptions. Being an EU business, or selling to one, is not enough on its own to establish direct scope. NIS2 Article 2 and Annexes I–II.
Check your country's implementing law and regulator guidance. The EU transposition deadline was 17 October 2024, but national implementation has not followed a uniform timetable. The European Commission maintains NIS2 implementation information and country transposition information.
Certain digital and ICT service providers also face more detailed requirements under Implementing Regulation (EU) 2024/2690. Its backup provisions address matters such as recovery times, protected storage, retention and testing. These additional requirements have their own scope. Regulation 2024/2690, Article 1 and Annex section 4.2.
For a project management system, turn this into a concrete exercise: identify which delivery workflows depend on it, nominate the recovery owner and test a representative project. Record what was recovered, what needed manual rebuilding and whether the team could resume work.
Retention and erasure: plan for the whole data lifecycle
Choose retention deliberately. GDPR's storage-limitation principle and erasure rules apply to personal data; a backup label does not create a general exemption. Relevant legal duties and exceptions may affect what you must keep or delete. GDPR Articles 5(1)(e) and 17.
Build a schedule by data category and purpose. Explain how long an undetected error might take to surface, which records have separate legal retention duties and when old copies should expire. Review that schedule when the business process changes. More available backup history is not, on its own, a reason to retain everything longer.
UK-specific guidance: the ICO says a valid erasure request, with no applicable exemption, also requires steps concerning backups. Where immediate overwriting is not possible, its guidance discusses putting the data “beyond use” until replacement under an established schedule, explaining the treatment to the individual and not using the retained data for another purpose. This is context-specific UK guidance, not a blanket EU permission to keep erased data indefinitely. ICO: erasure from backup systems.
Make avoiding reintroduction part of your restore procedure. For example, if a contact was validly erased after a CRM backup was captured, a later recovery should not quietly return that contact to active sales workflows. Keep a proportionate, access-controlled record of deletion decisions; check recovered records against it before releasing them for normal use. Test this process, including connected apps that could copy the data again. This is a recommended operational safeguard, not a claim that ProBackup automatically performs erasure reconciliation.
For EU processing, agree the approach with your privacy team using applicable EU law and relevant supervisory-authority guidance. Confirm the provider's actual deletion mechanisms and timing before promising a particular outcome to an individual.
Storage location is one part of the assessment
Identify where backup content, metadata and other service data are processed, which subprocessors are involved and who can access them. GDPR's international-transfer rules may apply; choosing an EU storage region does not settle every processing or transfer question. GDPR Chapter V.
Include separately managed copies, such as exports or Google Drive copies, in that assessment. Review ProBackup's security documentation, DPA and processor information and privacy policy.
Independent, immutable and air-gapped mean different things
- Independent backup: a copy held outside the source SaaS platform. Assess its separate credentials, administrators and dependencies as well as its storage location.
- Immutable backup: a copy protected against alteration or deletion for a defined period by specific technical controls. Encryption and version history alone do not establish immutability.
- Air-gapped backup: a copy isolated from network access, classically through physical disconnection. A connected cloud-to-cloud sync is not a physical air gap.
Ask suppliers to identify the mechanism and limits behind each claim. CISA's ransomware guidance separately discusses offline backups, testing and immutable storage; these are distinct protections. CISA #StopRansomware Guide.
ProBackup provides an independent backup layer. This page does not represent its backups or optional Google Drive sync as immutable or air-gapped. For broader planning, read our guides to the 3-2-1 backup rule and SaaS ransomware protection, assessing each control separately.
What ProBackup contributes, and what your team owns
ProBackup connects through supported apps' APIs and runs automated daily backup cycles. You can browse retained versions and restore supported data using the recovery options available for each integration. Coverage depends on the supported data types, authorised account access and selected scope. API-accessible does not mean every API-exposed object is supported, or that every backed-up type can be restored. Check the backup process explanation and your app's documentation in the Help Center.
Daily backups provide captured recovery versions. They do not provide recovery to every arbitrary instant between captures. Base your recovery plan on the latest successful capture of the affected data; delays, incomplete runs and lost authorisation can increase the gap. Restoring into an app also depends on that app's availability, permissions and API behaviour.
Retention depends on your subscription and settings. Confirm the available history and deletion behaviour for your account against your approved schedule. ProBackup offers regional backup storage selection during onboarding; confirm the scope of that selection for your processing requirements. See plans and features and data security.
Your team remains responsible for defining scope, reviewing permissions, responding to backup problems, approving restores and testing the result. The supplier's assurance documents support your due diligence; they do not confer compliance on your organisation. Review ProBackup's audit reports and DPA in that context.
A practical SaaS backup checklist
1. Define scope and ownership
List the CRM and project workflows that matter, their owners and the records, files, comments and relationships required to resume work. Identify unsupported types and excluded workspaces. Our guide to hidden SaaS data risks can help frame the scenarios.
2. Set retention and erasure rules
Document the reason for each retention period, exceptions, backup expiry and handling of erasure requests. Include exports and additional copies.
3. Protect access
Review who can browse, export, restore or delete backups. Use available multifactor authentication and document how authorised responders gain access if the usual administrator is unavailable.
4. Agree RPO and RTO
Recovery point objective is the maximum data-loss interval you aim to tolerate. Recovery time objective is the target time to resume the defined service. Check actual capture times against RPO; measure the whole recovery workflow against RTO. Neither is established merely by saying “daily backup.”
5. Run a safe restore test
Use approved sample data and a suitable test destination or supported non-destructive method. Check fields, attachments, relationships, access and the consequences for automations. Record anything the integration cannot recreate.
6. Keep evidence and close gaps
Record the snapshot, scope, operator, elapsed time, validation results and follow-up work. Repeat tests at an interval justified by risk and after material changes. Assign someone to review backup failures between exercises.
For example, a project test might show that tasks are usable again while a particular automation must be recreated manually. That is valuable evidence: update the runbook and include the extra work in your recovery-time estimate. Our SaaS backup and recovery guide provides more background for planning these exercises.
Frequently Asked Questions
Does GDPR require SaaS backups?
GDPR requires risk-appropriate security, including recovery capability and regular evaluation where appropriate. Backups may be necessary to achieve that outcome for your processing. Article 32 does not universally prescribe a third-party service, daily frequency or fixed retention duration. GDPR Article 32.
Does NIS2 apply to every business in the EU?
No. Check the listed sector and entity type, size rules and exceptions, then the relevant national law. Smaller businesses can be covered in specified cases. Customers may also impose supplier requirements contractually; that is a separate question from your direct legal scope. NIS2 Articles 2–3 and 21.
How long should we retain SaaS backups?
There is no universal GDPR backup-retention period. Document a duration that meets justified recovery needs and applicable retention duties, while respecting storage limitation and erasure rights. Confirm that your provider's settings and deletion process support the policy. GDPR Articles 5 and 17.
Are my cloud app's native backups enough?
They may meet a particular recovery need. Check the app's current documentation and contract, then test the exact scenario: accidental deletion, an incorrect import, compromised access or an outage. Establish what you can recover, the available history, who can initiate recovery and how long it takes. Infrastructure recovery, a recycle bin and customer-controlled record recovery are different capabilities. Use independent backup where your assessment identifies a gap.
Does using a SOC 2-audited or ISO 27001-certified supplier make us compliant?
No. SOC 2 provides assurance about controls within a defined examination scope; ISO/IEC 27001 concerns an information security management system. Neither is a law or a transfer of the supplier's assurance to its customers. Read the relevant scope and findings, and implement your own responsibilities. AICPA SOC guidance; ISO/IEC 27001.
Can daily backups recover a change made minutes before an incident?
Only if the required data was captured in an available backup version. A daily schedule cannot promise every intervening state. If your business needs a shorter recovery point objective, assess a method that can meet it and test the result.


Put your recovery plan to the test
Start with one important app, confirm what is backed up and run a representative restore. Use what you learn to set a realistic recovery plan and build evidence your team can explain.
Comparing requirements first? Review security documentation, plans and the Help Center to check your app's coverage and recovery options.

