| name | backup-retention-erasure |
| title | Backup Retention and Erasure Management |
| description | Manages backup and archive data under retention schedules and erasure obligations. Covers the technical infeasibility exception for backup deletion, backup cycle alignment with retention periods, restore-and-delete procedures, and interim protective measures during backup retention. Activate for backup deletion, archive erasure, backup retention, restore and delete, technical infeasibility queries. |
| author | mukul975 |
| author_url | https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/backup-retention-erasure |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | general |
| practice | data-protection |
| language | en |
Backup Retention and Erasure Management
Overview
Backup and archive systems present unique challenges for data retention and erasure compliance. Unlike primary systems where individual records can be selectively deleted, backup media typically stores data as monolithic sets that cannot be surgically modified without restoration. When a data subject exercises the right to erasure under GDPR Article 17 or when a retention period expires, the organization must address personal data residing in backups. The technical infeasibility of granular deletion from backups is a recognized limitation, but it does not exempt organizations from their obligations — it requires documented interim measures and eventual deletion through backup rotation or restore-and-delete procedures. This skill provides the operational framework for managing backup data under retention and erasure obligations.
Legal Context
GDPR Recital 66 — Erasure in Online Environments
The right to erasure should extend to cases where the controller has made the personal data public — the controller should take reasonable steps to inform other controllers processing the data. In the backup context, this principle requires that erasure obligations extend to backup copies even when immediate deletion is technically infeasible.
GDPR Article 17(1) — Right to Erasure
The controller shall erase personal data "without undue delay." The EDPB and national DPAs have acknowledged that backup systems may require a longer timeframe, but have not granted an indefinite exception. The expectation is that backup deletion occurs within the next backup rotation cycle.
ICO Guidance on Backup Deletion
The UK ICO has stated that where it is not technically feasible to erase data from backup systems immediately, the organization should:
- Put the backup data "beyond use" — ensure it cannot be accessed or used for any purpose.
- Ensure the data is deleted when the backup is next overwritten or rotated.
- Document the approach and timeframe.
- Inform the data subject of the backup deletion timeline.
EDPB Position
The European Data Protection Board has acknowledged in various guidelines that backup systems may present technical challenges for erasure. The general position is:
- Immediate deletion from live/primary systems is expected.
- Backup deletion should occur within a reasonable timeframe aligned with the backup rotation cycle.
- During the interim period, the data in backups must be "beyond use" — not accessed for any purpose.
Backup System Types and Erasure Approach
Erasure Strategy by Backup Type