Data deletion from backups: when and in what situations?

23 December 2025

Removing individual data from backups poses a significant challenge. For those managing these backups, it is often an almost impossible task, or at the very least, very difficult – requiring a high degree of precision and effort.

When Should We Delete Data from Backups

As a rule, the obligation to delete specific data from backups arises from the GDPR. This obligation occurs in the following cases:

  • when the legal basis for processing the personal data of a specific individual expires,
  • when the data subject exercises their right to be forgotten (although a separate issue remains when such a request should be fulfilled).

One might ask: what does the EU regulation have to do with backups at all? On one hand, the GDPR mandates the creation of backups in Article 32, and on the other hand, it reminds us that merely storing data in backups constitutes processing, which imposes additional requirements regarding backups.

For this reason, all rules for handling personal data arising from the GDPR apply to personal data processed in backups.

Explanation
Processing means any operation or set of operations performed on personal data or on sets of personal data, whether automated or non-automated, such as collection, recording, organizing, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, deletion or destruction – Article 4(2) GDPR.

Theory vs. Practice

In practice, deleting data of individual persons from backups will be a difficult, complicated, and sometimes even impossible process. Much depends on how much data the organization processes and in how many systems – as personal data can be dispersed across many of them. The technology used for creating backups also matters. It is hard to imagine restoring successive backups and then deleting individual records and recreating the backup. Undoubtedly, such an operation directly affects one of the pillars of backup security, namely their integrity.

European Supervisory Authorities on Deleting Data from Backups

The Danish Data Protection Agency indicates that if a person wishes to exercise their right to be forgotten, and the data controller has no legal basis for processing their data, they must also delete that data from backup copies, provided it is technically feasible (e.g., if the backup is not compressed in any way, deleting data from the backup will be as easy as deleting it from the production system). In cases where there is no technical possibility to delete data from the backup, the Danish authority recommends maintaining a register of deletion requests so that, in the event of a need to restore the backup, it is clear that the specified data must be deleted. Such a register should be created in accordance with the principle of data minimization, i.e., without including personal data, but with information that in the event of restoration, a specific data record must be deleted.

DPO Function - it transfers well

The British supervisory authority (Information Commissioner’s Office, ICO) has issued guidelines stating that it is necessary to take actions to ensure the deletion of data from backups. The ICO acknowledges that data may remain in a backup for some time until that backup is overwritten. However, it emphasizes that the minimum action it can accept is not using data from backups, even if they cannot be immediately overwritten.

The Dutch supervisory authority also points out that there is not always a technical possibility to delete specific personal data from a backup. For example, when part of the backup is stored on LTO tapes, the exercise of the right to be forgotten is not feasible.

The French supervisory authority (CNIL) has an even more liberal approach to deleting data from backups. It indicates that in the event of a request for data deletion or when the legal basis for processing expires, the data must primarily be deleted from the production environment, and then the affected individuals must be informed. Data in backup copies will disappear along with the expiration and overwriting of backups, and we are obliged to provide the date of backup deletion. According to the CNIL, backups are primarily intended for data restoration. However, an alternative solution must be provided to ensure that in the event of restoring a backup, the data of the individual who exercised their right to be forgotten will not be restored.

Ministry of Digital Affairs on deleting data from backups

The Ministry of Digital Affairs, in its GDPR guide for the FinTech sector, addressed the question: “When does the obligation to delete personal data from backups of information systems arise?”. The ministry stated that backups are a technical means of securing data for which the data controller has a legal basis for processing. In the event that this basis ceases, the data must be deleted or anonymized, taking into account technological limitations and the risks associated with violating the rights and freedoms of other individuals whose data is concerned. Therefore, according to the Ministry of Digital Affairs, it is acceptable to delete data from the backup along with the entire copy once it is no longer useful. Until that time, the processing of data in the backup should be limited to storage, subject to exceptions arising from the use of the backup in accordance with its intended purpose.

GDPR Training in IT
Migrations, clouds, systems.
GDPR in IT.
GDPR training in IT for Data Protection Officers and IT managers and staff. We invite you!
CHECK DATES
At the same time, the Ministry of Digital Affairs emphasizes that due to the necessity of ensuring the integrity of the backup, personal data contained therein does not have to be deleted selectively, for example, at the request of the individual concerned. The ministry sets the condition that backups must be adequately secured and that the risk of unauthorized access must be minimized. Additionally, the duration of storage for backups must be defined in a manner consistent with technological and industry standards.

The Ministry of Digital Affairs also indicates that in the event of a request for data deletion based on Article 17 of the GDPR, selective deletion from the backup may prove technically impossible or disproportionately costly and require excessive organizational effort in relation to the risk of violating the rights and freedoms of the data subject. Furthermore, such selective deletion of personal data from the backup violates its integrity, which may pose a risk to the rights and freedoms of other individuals whose data is stored in the same copy.

Polish DPA on deleting data from backups

In the November issue of the "UODO Bulletin" (no. 11/11/25), in the article "Deletion of Data from Backup Copies of IT Systems," it was stated unequivocally at the very beginning: "The data controller cannot refuse to fulfill each of our rights to the deletion of personal data if such a request is justified by legal provisions. The data must also be deleted from backup copies of IT systems. Therefore, it is important to use such systems for creating backups in order to comply with this obligation."

The Polish DPA, citing Article 25 of the GDPR, indicates that it is the obligation of the data controller to use systems that allow for the realization of individuals' rights, including the right to be forgotten. The authority emphasizes that according to Article 17 of the GDPR, there are no grounds for refusing to fulfill this right solely because the data is located in a backup copy. Ultimately, the data controller should manually restore backups, delete specific data, and then recreate the archives.

In conclusion, the Polish DPA stated that "the data controller cannot refuse to fulfill our request for the deletion of our personal data (e.g., because it is time-consuming) if our request is justified by legal provisions."

The position of the Polish DPA confirms what is directly stated in the GDPR. However, the problem lies in the practical implementation of the request and is related to the selection of the solution, its capabilities, and costs. Additionally, the advice regarding restoring copies, deleting data, and recreating archives seems impossible to fulfill in practice.

Moreover, a contradiction arises here. Article 32 of the GDPR requires ensuring the integrity and availability of data and providing the ability to quickly restore systems after a failure. Meanwhile, any modification of a backup copy directly violates its integrity.

Requirements of the NIS 2 Directive and the Fight Against Ransomware

The NIS 2 Directive requires essential entities to adopt a specific backup strategy. In practice, it is based on immutable copies, meaning immutable backups. By design, they cannot be edited or deleted for a specified period. This is a fundamental protection for the continuity of an organization's operations. According to the industry-recommended 3-2-1 rule (three copies of data on two different media, with one offsite), and in an extended, safer version: 3-2-1-1-0, at least one copy should be offline.

Implementation of NIS2

The data controller is thus faced with an unsolvable conflict: either it adheres to best practices in cybersecurity, protecting the organization from attacks, or it complies with the position of the Polish DPA, sacrificing the integrity of backup copies. Both paths mutually exclude each other.

Retention Period for Backup Copies

Let us consider how long we should retain personal data in our databases, as well as how long we should keep backup copies. When determining the retention period for backup collections, we must take into account both business requirements and the scope of the data, as well as the duration for which they will be needed in the event of a failure. Another factor influencing the retention period for backups is the justification for further processing of the data contained therein.

Example
Company XYZ processes personal data based on consent. Backups are created on a daily and monthly basis. The daily copy is stored for 10 days, after which it is overwritten. Monthly copies, on the other hand, are overwritten only after a year. The company receives a request from one of the individuals whose data is being processed. They request that the data controller delete all data held about them. The data controller deletes all data from the production systems; however, a problem arises with the data in the backup copies. While the personal data stored in daily copies disappears after 10 days, the issue with the monthly copies remains. They still contain unwanted data that the company continues to process, although it should not. Deleting this data is neither simple nor straightforward.

Integrity of Backup Copies

Theoretically, it is possible to restore each copy and then delete individual data and recompress, but this process is often difficult, time-consuming, and sometimes costly. Deleting records from backup copies is an action that undermines their integrity. The Danish supervisory authority reminds us that the primary purpose of creating backups is to enable data recovery in the event of loss in the functioning system.

Depriving a backup of its integrity may jeopardize the security of other data contained in the copy. This raises the question of whether the realization of one person's rights can occur at the expense of the rights of others. Backups can also serve as evidence that, for example, someone is modifying data in production systems. However, using backup copies as evidence may prove unjustified if the integrity of those copies cannot be demonstrated.

How to Mitigate Risks in the Process of Deleting Data from Backup Copies

It often turns out that the cost and effort required to remove an individual's data from a backup are disproportionate to the outcome. However, there is a difference between merely stating that a given process is irrational and proving it. To mitigate the risks associated with data removal from backups, it is advisable to undertake the following actions within the organization:

  1. Conduct a risk analysis, as well as an analysis of its impact on the business.
  2. Organize internal regulations, procedures, and policies. In this case, ensure there is a procedure for creating, restoring, and deleting backups. If we do not clearly define what to do and what not to do, it may turn out that we will not be able to defend the adopted approach.
  3. Ensure employee education. They should be aware of their obligations regarding personal data protection.
  4. Map all business processes and data resources. It is important to know how and where data is processed.
  5. Ensure that data processing in production systems is compliant with the law. Define the timeframes within which we intend to process data – including in backups. Do not retain backups longer than necessary. If data retention processes do not have solid rules for deleting old data, this may be considered an improper practice.
  6. Implement a data deletion plan. It makes no sense to try to explain why we cannot delete something if we never planned to do so.
  7. If backups contain data that we should not retain, inform the individuals concerned why their data is present there.
  8. Ensure the security of backups: encrypt with strong and up-to-date techniques, restrict access to backups, and store them in a secure location.
  9. Engage top management in the acceptance and control of risks.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.