Is Your Email Actually Backed Up?

Backing up your email isn’t just sensible. Under UK GDPR, it’s something the law expects you to be able to do.

What UK GDPR actually says

UK GDPR Article 32(1)(c) requires organisations to have the ability to restore access to personal data promptly if something goes wrong, whether that’s an accidental deletion, a technical fault, or an attack. The ICO’s own security guidance points organisations to this same article. In practice, having backup, archiving, or both isn’t just good practice – it’s a legal requirement. [SEE HERE]


It’s easy to assume this is already covered. If your email is hosted with Microsoft 365 or Google Workspace, you might assume the platform is quietly backing everything up behind the scenes. It’s a fair assumption, and for many organisations it’s an entirely wrong one.

Microsoft 365 and Google Workspace are both pretty robust and reliable platforms, and both give you a short window to recover something deleted by mistake. But neither is designed to be a long-term backup. Once that window closes – usually a matter of weeks – whatever has gone is gone for good. If you’re on other platforms such as a Zimbra server or even plain old IMAP, that grace period may be shorter or may not exist at all.

What Microsoft and Google Say

Microsoft’s own Services Agreement recommends that customers regularly back up their content and data, or store it using third-party apps and services. In other words, Microsoft looks after the infrastructure: keeping the servers running, the platform available, and your account secure from outside attack. What happens to the contents of your mailbox, once it’s in there, is down to you.

Microsoft Services Agreement – Paragraph 6 – Service Availability – “We strive to keep the Services up and running; however, all online services suffer occasional disruptions and outages, and Microsoft is not liable for any disruption or loss you may suffer as a result. In the event of an outage, you may not be able to retrieve Your Content or Data that you’ve stored. We recommend that you regularly backup Your Content and Data that you store on the Services or store using Third-Party Apps and Services.”

Google takes a similar position, though less bluntly worded than Microsoft’s contract. Google Cloud’s own shared responsibility documentation, which names Google Workspace directly as an example, states that for software-as-a-service platforms like Workspace, Google owns the bulk of the security responsibilities, but customers remain responsible for their access controls and the data they choose to store. It’s Workspace Admin Help tells us more:

Google Workspace Admin – Troubleshooting – “When the 30-day period after deleting ends, admins have an additional 25 days to restore messages. This 25-day period starts 30 days after a message was deleted – it does not start from the day a message was sent or received – and applies to messages of any age. When the additional 25-day period ends, messages are permanently deleted from your Google Workspace account and can’t be restored by an admin or by Google.”

That 55-day window is genuinely useful, and it’s more generous than most people assume. But it’s a grace period for catching mistakes quickly, not a substitute for backup. If something’s noticed later than that, whether it’s an audit, a dispute, or simply nobody checking a leaver’s mailbox in time, there’s nothing left to recover.

It’s Other Platforms Too

If you’re using other platforms, whether it’s Zimbra mailboxes, IMAP mailboxes, or anything else, the responsibility for email backup lies with you.

What Could Go Wrong?

It’s worth being specific about what that actually means in practice, because “something might go wrong” doesn’t feel as real as the ways it actually does go wrong. A member of staff empties a folder by mistake, sometimes a whole year’s worth of client correspondence in one go. An account gets hacked, and whoever’s got access starts deleting messages, either to cover their tracks or as part of a wider attack on the server. Someone leaves the organisation and their account gets removed before anyone’s checked what was in it. Migrating to a new server, or syncing between devices, can quietly delete messages instead of copying them. And occasionally, someone leaving on bad terms deletes things deliberately, on their way out (we’ve seen it).

None of those are exotic scenarios, they’re the everyday reasons mailboxes get wiped. The trouble is, most of them aren’t noticed straight away. By the time someone spots a missing folder, or a gap turns up during a dispute, weeks or months have often passed, well beyond the short recovery window either platform offers natively. Without a backup, whatever’s lost in that moment is lost for good.

Backup and Archiving Are Not the Same Thing

This is where it gets useful, because “email protection” isn’t one thing. It’s two different jobs, solving two different problems.

Backup is a scheduled, point in time copy of your mailbox. Think of it as a snapshot taken at intervals, once a day or a few times per day depending upon the backup solution. If someone accidentally deletes an important email, a member of staff leaves and their mailbox needs restoring, or you’re hit by ransomware, backup is what lets you roll back to a recent copy and recover what was lost.

It has one small blind spot. Because it’s a snapshot, not a continuous recording, there’s a gap between each backup. An email that’s sent and then deleted from Sent Items before the next snapshot runs could, in theory, fall through that gap.

Archiving works differently. Rather than taking periodic snapshots, it captures every single email as it passes in or out of your mail server, in real time. Nothing waits for the next scheduled run, so there’s no gap for anything to slip through. It creates a complete, permanent, searchable record of everything sent and received.

Archiving isn’t really about disaster recovery. It’s about having an accurate, tamper proof record you can call on, whether that’s for a compliance requirement, an audit, a Subject Access Request, or simply settling an argument about what was actually said in an email six months ago.

And unlike backup, which is usually tied to a specific platform like Microsoft 365 or Google Workspace, archiving can work with pretty much any email system, including older or simpler setups like Zimbra or plain IMAP.

Which One Do You Need?

Honestly, it depends on what you’re trying to protect against.

  • If your main worry is losing emails to accidental deletion, a leaver, or a ransomware attack, backup is what covers you.
  • If you need a complete, unbroken record of everything that’s ever been sent or received, for compliance, legal, or peace of mind reasons, archiving is what covers you.
  • If both of those matter to you, the two work well together: backup for recovery, archiving for the record.

Not every organisation needs both. It genuinely depends on your size, your sector, and what you’d need to prove if something ever went wrong. That’s a conversation worth having rather than a box to tick.

Talk to Us

If you’re not sure whether your email is properly protected, or you know it isn’t and want to fix it, get in touch. We’ll take a look at what you’ve got, explain what’s actually covered and what isn’t, and talk you through the options, in plain English, with no pressure to buy more than you need.

Scroll to Top