A customer calls and asks you to remove their information. You find the record, delete it, and tell them it is done. As far as your live system goes, that is true. The record is gone from the screen, the reports, and search.
It is also still in last night’s backup. And last week’s. And the monthly copy from a year ago, the external drive somebody took home, and the retired server nobody was sure it was safe to wipe. That is not a failure of your backup system. It is the system working as designed, and it raises a question most small businesses have never thought through: what does deletion mean when your job is keeping copies of everything?
Deleting a Record Does Not Delete the Copies
A backup is a photograph of your data at a moment in time. If a customer record existed when the photograph was taken, it is in the photograph. Deleting the original later does not change the picture.
Most businesses have more of these photographs than they realize. Daily copies going back weeks. Weekly copies going back months. Monthly copies somebody set to keep forever because storage was cheap and nobody wanted to delete the wrong thing. Add the cloud service with its own deleted item recovery, the sync tool with version history, and the email archive, and one deleted record can persist in a dozen places.
That redundancy is the entire point. It saves you when ransomware hits or a drive fails, and it is why CISA, the federal cybersecurity agency, recommends the three two one approach for small and mid-sized businesses: three copies of your data, on two kinds of storage, with one kept off-site away from your business location. The problem is not that copies exist. It is that nobody knows how many exist, or for how long.
Retention Policy Versus Backup Retention
Here is where two reasonable ideas collide. A data retention policy says you keep customer information for a defined period, then get rid of it. A backup policy says you keep restorable copies far enough back to survive a problem you did not notice right away. Both are sensible. Left unmanaged, they contradict each other.
We have seen a business with a written policy purging customer records after three years, running backups set to keep monthly copies indefinitely. On paper, three years. In reality, forever. Nobody lied. The person who wrote the policy and the person who set up the backup software never spoke.
The FTC’s guidance treats keeping less as a security measure in its own right. Its Protecting Personal Information guide tells companies that “If you don’t have a legitimate business need for sensitive personally identifying information, don’t keep it,” and adds that “If you have a legitimate business need for the information, keep it only as long as it’s necessary.” Its Start with Security guide repeats the point: “Hold on to information only as long as you have a legitimate business need.” Guidance like that speaks mostly to the systems you use daily and to disposing of old equipment. Backups sit between the two, which is why they get skipped.
Why This Matters: Requests and Exposure
Two situations make this a business question, not a tidiness one.
The first is a deletion request. Someone asks you to remove their information, whether because a rule applies to your business or simply because they asked and you want to say yes. What exactly are you promising? Whether a specific law reaches your business is a question for your attorney. Operationally, know the answer before you make the promise, because it differs for the live system and the archives.
The second is exposure. If backups are stolen or reached by an intruder, the affected people are everyone in those backups, not everyone in your current system. A business that trimmed its live data to three years but holds ten years of monthly backups has ten years of exposure. Old backups are often the least protected copies you own, sitting on unencrypted drives with credentials nobody has rotated. That is the same forgotten corner problem we described in shadow IT and the hidden risk inside your own organization.
How Long Backups Should Actually Be Kept
There is no universal number, and anyone who gives you one without asking about your industry and your records obligations is guessing. You can still decide deliberately instead of by default.
- Start with what recovery requires. CISA advises testing backups so you can restore fully and partially, and specifically so you can “roll back data at least seven days if needed,” since problems are often found days after they start. That sets a floor, not a ceiling.
- Add the records you are obligated to keep. Tax, employment, contract, and industry records have their own timelines. Your accountant and your attorney own that list, not your backup software.
- Separate archives from backups. A backup exists to restore operations. An archive exists to preserve records you must keep. Confusing the two is how businesses end up keeping everything forever to keep a few things properly.
- Then set an expiration and let it run. Most backup tools have a retention setting that deletes copies past a chosen age. Pick the number on purpose, write down why, and let the software enforce it. Retention that depends on someone remembering is not retention.
One more caution. If your backups live with a provider, confirm what they keep and for how long, because their retention becomes yours. Providers also change terms and occasionally have bad days, the argument we made in our post on what it means when the cloud goes down.
The Drives and Archives in the Closet
Almost every office we walk into has them. External drives from an old backup routine. The server replaced but never wiped. Tapes nobody can read. A laptop from a departed employee, holding a full copy of the shared drive.
These are the worst of both worlds. They carry real customer data, they are protected by a closet door, and they offer no recovery value because nobody has checked that they work. The FTC’s Protecting Personal Information guide is direct about the equipment side, advising businesses to “Inventory all computers, laptops, mobile devices, flash drives, disks, home computers, digital copiers, and other equipment to find out where your company stores sensitive data,” and that “When disposing of old computers and portable storage devices, use software for securely erasing data, usually called wipe utility programs.”
Do the inventory once. For each item, decide it is part of your current backup plan, a record kept on purpose in a known place, or something to be securely wiped and disposed of. There is no fourth category, and not being sure is how these sit for a decade.
The Bottom Line
Nobody expects you to surgically remove one customer from a hundred backup sets. That is not how backups work, and claiming otherwise is worse than admitting it. What you can defend is a clear position, stated plainly and applied consistently.
It sounds like this. We delete the record from our live systems promptly. Backups age out on a defined schedule, after which the copies are gone. During that window the data sits only in restricted backup storage, it is not used for any business purpose, and if a backup is restored the deletion is reapplied. That is achievable, it is truthful, and it holds up when a customer or a larger client asks.
The version that does not hold up is the common one: no idea how long backups are kept, no expiration configured, and a closet full of drives nobody has opened in years.
If you want to know how long your backups actually keep data, what is on the old drives, and how to set retention you can honestly describe to a customer, that is work we do every week. Harrison Ward Technology supports businesses across Denton County with backup design, retention cleanup, and secure disposal of old equipment. Contact us today
Sources:
Comments are closed