{"id":5814,"date":"2018-04-26T23:57:49","date_gmt":"2018-04-26T22:57:49","guid":{"rendered":"https:\/\/www.n-able.com\/?p=5814"},"modified":"2021-07-09T15:34:54","modified_gmt":"2021-07-09T14:34:54","slug":"gdpr-backup-and-retention-strategies","status":"publish","type":"post","link":"https:\/\/www.n-able.com\/pt-br\/blog\/gdpr-backup-and-retention-strategies","title":{"rendered":"GDPR: Backup and Retention Strategies"},"content":{"rendered":"<p>MSPs and IT providers should actively engage their customers about their backup strategy and the potential impact it may have on readiness for the EU General Data Protection Regulation (GDPR). GDPR\u2019s focus on data protection means you and your customer may need to shift the way you architect data and how you need to back things up, and set sound retention policies, including the ability to facilitate any data subject requests. It\u2019s important to have these conversations before the law comes into effect in May.<\/p>\n<p>Here are a few topics that can open the discussion and potentially lead to a better, more compliant solution. This article is written with the assumption that you are processing EU personal data.<\/p>\n<p><strong>1. Are you needlessly backing up \u201cdead data\u201d?<\/strong><\/p>\n<p>Many organizations run daily full system backups as a best practice, but unless the backup is intelligent enough to determine files that are no longer required (such as applied Windows update files), the system could be backing up data that is no longer needed. Another area of concern is when various shared drives on the server contain a multitude of non-critical files. Both of these things may result in unnecessary usage of time, bandwidth, and storage. For larger multi-server environments, there may be an opportunity to run a number of automated clean-up processes to maximize backup efficiency and reduce the size of your daily backups.<\/p>\n<p><strong>2. Can you improve the backup process?<\/strong><\/p>\n<p>Even in 2018, many businesses rely heavily on humans to participate in the backup process. Some businesses may demand an employee insert a tape or take the backup media home with them as an \u201coffsite backup.\u201d Unless the backup program encrypts the data\u2014please be aware that native Windows backup is neither encrypted, nor compressed\u2014this puts you and your customer at a potentially huge risk of exposing personal data if the backups are lost or stolen. If this occurs, and you are the controller of such data, you may have to report it under GDPR.\u00a0 Both you and your customer may face fines. The most elegant solution is a local, encrypted backup combined with a hosted backup that encrypts the data both in transit and at rest.<\/p>\n<p><strong>3. How will you facilitate a GDPR data subject access request with your backups?<\/strong><\/p>\n<p>One of the key rights of data subjects is they can request access to their data at any time. Obviously, if you lose their data or cannot access it, fulfilling an access request will be impossible. Please note, data subjects have additional rights, such as erasure, portability, etc., in regard to their data.\u00a0 While we only address the right to access here, you should also consider these other rights when establishing your [backup systems].<\/p>\n<p>Facilitating a data subject access request is perhaps one of the larger concerns of backup programs in use today. Certain file types in certain locations and certain databases may contain personal data. For example, Outlook PST files located on workstations usually contain an abundance of personal data. In addition, employee payroll databases, customer relationship management systems, accounting and billing applications, and customer-facing system log files all need to be considered in light of the subject access rights of GDPR.<\/p>\n<p>To fulfill requests, you must put some thought into how a customer\u2019s data backups should be structured so you can facilitate access requests. An access request may be fairly easy to facilitate by using third-party search tools on live systems. However, if the search could be disruptive to business operations, you may need to conduct it against a backup or virtualized host.<\/p>\n<p>Consider the following areas where personal data is likely to be found:<\/p>\n<ul>\n<li><b>Billing Database<\/b>\u2014Since<b>\u00a0<\/b>this is a business record of financial transactions, you may need to retain everything for seven or more years. The billing database backup retention period should be disclosed to the customer and aligned with regulatory or governmental requirements.<\/li>\n<li><b>Tech Support Database<\/b>\u2014The transactions in the database may be able to be provided upon a subject access request. However, you may still need to retain the data in the backups for a period of time. You should disclose your retention periods for tech support data to the customer.<\/li>\n<li><b>Marketing Database<\/b>\u2014The marketing database backup retention period should be disclosed to the customer. The retention period should be shortened to facilitate the timely removal of the data subject\u2019s information.<\/li>\n<li><b>Email Correspondence<\/b>\u2014It may be an arduous process to review and access all emails with the data subject\u2019s information and to redact personal data of other data subjects\u2019 from email correspondence in order to promptly respond to this request.<\/li>\n<\/ul>\n<p>Clearly, different data backup retention strategies overwrite policies, and differential backup configurations will play a vital role in determining what information is backed up, how it gets backed up, and how long the backup is retained. MSPs and IT providers will need to work closely with their customers to determine the right backup strategy utilized and the right backup retention policy to be able to meet data subject requests under GDPR.<\/p>\n<p><strong>For even more on GDPR,\u00a0<a href=\"https:\/\/www.solarwindsmsp.com\/resources\/gdpr\" target=\"_blank\" rel=\"noopener\">click here<\/a>\u00a0to visit our GDPR resource center\u00a0<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p><em>This document is provided for informational purposes only and should not be relied upon as legal advice or to determine how the EU General Data Protection Regulation (GDPR) may apply to you and your organization. We encourage you to work with a legally qualified professional to discuss GDPR, how it applies to your organization, and how best to ensure compliance. SolarWinds MSP makes no warranty, express or implied, or assumes any legal liability or responsibility for the information contained herein, including the accuracy, completeness, or usefulness of any information.\u00a0<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>MSPs and IT providers should actively engage their customers about their backup strategy and the potential impact it may have on readiness for the EU GDPR.<\/p>\n","protected":false},"author":24,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"class_list":["post-5814","post","type-post","status-publish","format-standard","hentry","topic-compliance"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.2 (Yoast SEO v27.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>GDPR: Backup and Retention Strategies - N-able<\/title>\n<meta name=\"description\" content=\"MSPs and IT providers should actively engage their customers about their backup strategy and the potential impact it may have on readiness for the EU GDPR.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.n-able.com\/pt-br\/blog\/gdpr-backup-and-retention-strategies\" \/>\n<meta property=\"og:locale\" content=\"pt_BR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"GDPR: Backup and Retention Strategies - N-able\" \/>\n<meta property=\"og:description\" content=\"MSPs and IT providers should actively engage their customers about their backup strategy and the potential impact it may have on readiness for the EU GDPR.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.n-able.com\/pt-br\/blog\/gdpr-backup-and-retention-strategies\" \/>\n<meta property=\"og:site_name\" content=\"N-able\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/NableMSP\" \/>\n<meta property=\"article:published_time\" content=\"2018-04-26T22:57:49+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-07-09T14:34:54+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.n-able.com\/wp-content\/uploads\/2021\/03\/share-image.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"N-able\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@Nable\" \/>\n<meta name=\"twitter:site\" content=\"@Nable\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"N-able\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. tempo de leitura\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.n-able.com\/pt-br\/blog\/gdpr-backup-and-retention-strategies#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.n-able.com\/pt-br\/blog\/gdpr-backup-and-retention-strategies\"},\"author\":{\"name\":\"N-able\",\"@id\":\"https:\/\/www.n-able.com\/pt-br#\/schema\/person\/f46a000e389b6d02bd4b3866e7828a7b\"},\"headline\":\"GDPR: Backup and Retention Strategies\",\"datePublished\":\"2018-04-26T23:57:49+01:00\",\"dateModified\":\"2021-07-09T14:34:54+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.n-able.com\/pt-br\/blog\/gdpr-backup-and-retention-strategies\"},\"wordCount\":946,\"publisher\":{\"@id\":\"https:\/\/www.n-able.com\/pt-br#organization\"},\"articleSection\":[\"GDPR\"],\"inLanguage\":\"pt-BR\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.n-able.com\/pt-br\/blog\/gdpr-backup-and-retention-strategies\",\"url\":\"https:\/\/www.n-able.com\/pt-br\/blog\/gdpr-backup-and-retention-strategies\",\"name\":\"GDPR: Backup and Retention Strategies - N-able\",\"isPartOf\":{\"@id\":\"https:\/\/www.n-able.com\/pt-br#website\"},\"datePublished\":\"2018-04-26T23:57:49+01:00\",\"dateModified\":\"2021-07-09T14:34:54+00:00\",\"description\":\"MSPs and IT providers should actively engage their customers about their backup strategy and the potential impact it may have on readiness for the EU GDPR.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.n-able.com\/pt-br\/blog\/gdpr-backup-and-retention-strategies#breadcrumb\"},\"inLanguage\":\"pt-BR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.n-able.com\/pt-br\/blog\/gdpr-backup-and-retention-strategies\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.n-able.com\/pt-br\/blog\/gdpr-backup-and-retention-strategies#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"GDPR\",\"item\":\"https:\/\/www.n-able.com\/pt-br\/blog\/category\/gdpr\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"GDPR: Backup and Retention Strategies\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.n-able.com\/pt-br#website\",\"url\":\"https:\/\/www.n-able.com\/pt-br\",\"name\":\"N-able\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.n-able.com\/pt-br#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.n-able.com\/pt-br?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"pt-BR\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.n-able.com\/pt-br#organization\",\"name\":\"N-able\",\"url\":\"https:\/\/www.n-able.com\/pt-br\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\/\/www.n-able.com\/pt-br#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.n-able.com\/wp-content\/uploads\/2021\/02\/logo-n-able-vertical-dark.svg\",\"contentUrl\":\"https:\/\/www.n-able.com\/wp-content\/uploads\/2021\/02\/logo-n-able-vertical-dark.svg\",\"width\":\"1024\",\"height\":\"1024\",\"caption\":\"N-able\"},\"image\":{\"@id\":\"https:\/\/www.n-able.com\/pt-br#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/NableMSP\",\"https:\/\/x.com\/Nable\",\"https:\/\/www.linkedin.com\/company\/n-able\",\"https:\/\/www.youtube.com\/channel\/UClnp77HHg4aME-S-3fWQhFw\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.n-able.com\/pt-br#\/schema\/person\/f46a000e389b6d02bd4b3866e7828a7b\",\"name\":\"N-able\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\/\/secure.gravatar.com\/avatar\/e9c468b7c98137ecdd5508befa660c205a7978133257080a37fb0b1362d53411?s=96&d=mm&r=g\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/e9c468b7c98137ecdd5508befa660c205a7978133257080a37fb0b1362d53411?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/e9c468b7c98137ecdd5508befa660c205a7978133257080a37fb0b1362d53411?s=96&d=mm&r=g\",\"caption\":\"N-able\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"GDPR: Backup and Retention Strategies - N-able","description":"MSPs and IT providers should actively engage their customers about their backup strategy and the potential impact it may have on readiness for the EU GDPR.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.n-able.com\/pt-br\/blog\/gdpr-backup-and-retention-strategies","og_locale":"pt_BR","og_type":"article","og_title":"GDPR: Backup and Retention Strategies - N-able","og_description":"MSPs and IT providers should actively engage their customers about their backup strategy and the potential impact it may have on readiness for the EU GDPR.","og_url":"https:\/\/www.n-able.com\/pt-br\/blog\/gdpr-backup-and-retention-strategies","og_site_name":"N-able","article_publisher":"https:\/\/www.facebook.com\/NableMSP","article_published_time":"2018-04-26T22:57:49+00:00","article_modified_time":"2021-07-09T14:34:54+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/www.n-able.com\/wp-content\/uploads\/2021\/03\/share-image.jpg","type":"image\/jpeg"}],"author":"N-able","twitter_card":"summary_large_image","twitter_creator":"@Nable","twitter_site":"@Nable","twitter_misc":{"Escrito por":"N-able","Est. tempo de leitura":"5 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.n-able.com\/pt-br\/blog\/gdpr-backup-and-retention-strategies#article","isPartOf":{"@id":"https:\/\/www.n-able.com\/pt-br\/blog\/gdpr-backup-and-retention-strategies"},"author":{"name":"N-able","@id":"https:\/\/www.n-able.com\/pt-br#\/schema\/person\/f46a000e389b6d02bd4b3866e7828a7b"},"headline":"GDPR: Backup and Retention Strategies","datePublished":"2018-04-26T23:57:49+01:00","dateModified":"2021-07-09T14:34:54+00:00","mainEntityOfPage":{"@id":"https:\/\/www.n-able.com\/pt-br\/blog\/gdpr-backup-and-retention-strategies"},"wordCount":946,"publisher":{"@id":"https:\/\/www.n-able.com\/pt-br#organization"},"articleSection":["GDPR"],"inLanguage":"pt-BR"},{"@type":"WebPage","@id":"https:\/\/www.n-able.com\/pt-br\/blog\/gdpr-backup-and-retention-strategies","url":"https:\/\/www.n-able.com\/pt-br\/blog\/gdpr-backup-and-retention-strategies","name":"GDPR: Backup and Retention Strategies - N-able","isPartOf":{"@id":"https:\/\/www.n-able.com\/pt-br#website"},"datePublished":"2018-04-26T23:57:49+01:00","dateModified":"2021-07-09T14:34:54+00:00","description":"MSPs and IT providers should actively engage their customers about their backup strategy and the potential impact it may have on readiness for the EU GDPR.","breadcrumb":{"@id":"https:\/\/www.n-able.com\/pt-br\/blog\/gdpr-backup-and-retention-strategies#breadcrumb"},"inLanguage":"pt-BR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.n-able.com\/pt-br\/blog\/gdpr-backup-and-retention-strategies"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.n-able.com\/pt-br\/blog\/gdpr-backup-and-retention-strategies#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"GDPR","item":"https:\/\/www.n-able.com\/pt-br\/blog\/category\/gdpr"},{"@type":"ListItem","position":2,"name":"GDPR: Backup and Retention Strategies"}]},{"@type":"WebSite","@id":"https:\/\/www.n-able.com\/pt-br#website","url":"https:\/\/www.n-able.com\/pt-br","name":"N-able","description":"","publisher":{"@id":"https:\/\/www.n-able.com\/pt-br#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.n-able.com\/pt-br?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"pt-BR"},{"@type":"Organization","@id":"https:\/\/www.n-able.com\/pt-br#organization","name":"N-able","url":"https:\/\/www.n-able.com\/pt-br","logo":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/www.n-able.com\/pt-br#\/schema\/logo\/image\/","url":"https:\/\/www.n-able.com\/wp-content\/uploads\/2021\/02\/logo-n-able-vertical-dark.svg","contentUrl":"https:\/\/www.n-able.com\/wp-content\/uploads\/2021\/02\/logo-n-able-vertical-dark.svg","width":"1024","height":"1024","caption":"N-able"},"image":{"@id":"https:\/\/www.n-able.com\/pt-br#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/NableMSP","https:\/\/x.com\/Nable","https:\/\/www.linkedin.com\/company\/n-able","https:\/\/www.youtube.com\/channel\/UClnp77HHg4aME-S-3fWQhFw"]},{"@type":"Person","@id":"https:\/\/www.n-able.com\/pt-br#\/schema\/person\/f46a000e389b6d02bd4b3866e7828a7b","name":"N-able","image":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/secure.gravatar.com\/avatar\/e9c468b7c98137ecdd5508befa660c205a7978133257080a37fb0b1362d53411?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/e9c468b7c98137ecdd5508befa660c205a7978133257080a37fb0b1362d53411?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/e9c468b7c98137ecdd5508befa660c205a7978133257080a37fb0b1362d53411?s=96&d=mm&r=g","caption":"N-able"}}]}},"_links":{"self":[{"href":"https:\/\/www.n-able.com\/pt-br\/wp-json\/wp\/v2\/posts\/5814","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.n-able.com\/pt-br\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.n-able.com\/pt-br\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.n-able.com\/pt-br\/wp-json\/wp\/v2\/users\/24"}],"replies":[{"embeddable":true,"href":"https:\/\/www.n-able.com\/pt-br\/wp-json\/wp\/v2\/comments?post=5814"}],"version-history":[{"count":0,"href":"https:\/\/www.n-able.com\/pt-br\/wp-json\/wp\/v2\/posts\/5814\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.n-able.com\/pt-br\/wp-json\/wp\/v2\/media?parent=5814"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}