Skip to main content
Category: Essential Records and Continuity

Remote Backup

Also known as: Online Backup, Managed Backup Service, Remote Backup Service
Simply put

Remote backup is the practice of copying data to servers or storage located away from the original system, so that the information can be recovered if the primary copy is lost. It is often used to guard against risks such as hardware failure, natural disasters, or cyberattacks. Depending on the arrangement, it may be delivered as a managed service that handles backup, storage, and recovery on the user's behalf.

Formal definition

Remote backup refers to the storage of backup copies of files or data on remote servers, typically geographically separated from the source environment, to support recovery in the event of loss. It commonly takes the form of a remote, online, or managed backup service that provides a system for the backup, storage, and recovery of computer files. Remote backup should be understood as a data protection and continuity measure rather than as a recordkeeping control; the presence of a remote backup copy does not, by itself, establish the authenticity, reliability, integrity, or usability required of an authoritative record, and organizations should distinguish backup copies retained for recovery from records managed under retention and disposition policies. The specific mechanisms, retention of backup sets, and recovery guarantees depend on the solution and organizational policy.

Why it matters

Remote backup addresses a fundamental risk to organizational information: the loss of primary copies through hardware failure, natural disasters, or cyberattacks. By holding copies of data on servers or storage located away from the source environment, organizations create a means of recovery when the original system becomes unavailable or compromised. For records and information professionals, this contributes to business continuity and resilience, supporting the availability of information that operations, obligations, and decision-making depend upon.

At the same time, it is important not to overstate what remote backup accomplishes. A backup copy exists to support recovery, not to serve as an authoritative record. The presence of a remote backup does not, by itself, establish the authenticity, reliability, integrity, or usability that recordkeeping requires. Backup sets are typically overwritten, rotated, or retained according to recovery objectives rather than retention and disposition schedules, which means backups and records serve different purposes and should be governed separately. Treating a backup as though it were a managed record can create confusion during discovery, audits, or freedom of information responses, depending on jurisdiction and sector.

Organizations should therefore be deliberate about the boundary between data protection measures and recordkeeping controls. Relying on remote backup as a substitute for records management may leave gaps in defensible disposition, while ignoring backup entirely leaves the organization exposed to data loss. The specific mechanisms, retention of backup sets, and recovery guarantees vary by solution and by organizational policy, so professionals should confirm how a given arrangement behaves rather than assuming a uniform standard.

Who it's relevant to

Records Managers
Records managers need to distinguish backup copies held for recovery from records managed under retention and disposition policies. Remote backup can support the availability of information, but it does not confer the authenticity, reliability, integrity, or usability required of an authoritative record, so it should not be treated as a substitute for records management controls.
Information Governance Officers
Within the broader accountability framework of information governance, remote backup contributes to resilience and continuity by protecting against loss from hardware failure, disasters, or cyberattacks. Governance leads should ensure policies clarify how backup interacts with, but does not replace, retention, disposition, and recordkeeping obligations.
IT and Business Continuity Teams
Those responsible for continuity rely on remote backup as a data protection measure supporting recovery. They should confirm how backup sets are scheduled and retained and what recovery guarantees a given service provides, since these vary by solution and organizational policy.
Compliance and Legal Leads
Because backups may capture data that is subject to legal holds, discovery, or freedom of information requests, compliance and legal professionals should understand how backup retention behaves. Requirements differ across jurisdictions and sectors, so the treatment of backup copies in legal and regulatory contexts should be assessed against applicable local obligations rather than assumed.

Inside Remote Backup

Offsite Storage Location
Remote backup involves copying data to a physically or logically separate location from the primary system, such as a cloud service or a geographically distant data center, so that a single site-level event does not affect both the original and the backup.
Backup Copies
The data held in a remote backup is typically a copy created for continuity and recovery purposes. In recordkeeping terms, such a copy is generally distinct from the authoritative record, and organizations should be clear about which instance carries evidential status.
Transmission and Synchronization
Remote backup usually depends on transferring data over a network, often on a scheduled or continuous basis. Synchronization arrangements determine how current the remote copy is relative to the source at any given point.
Integrity and Encryption Controls
To preserve the usability and integrity of backed-up data, remote backup arrangements often incorporate controls such as encryption in transit and at rest, along with verification mechanisms to confirm that copies are complete and uncorrupted.
Recovery Capability
A defining element is the ability to restore data from the remote copy following loss, corruption, or unavailability of the primary source. The value of a remote backup depends substantially on the reliability and tested nature of this restoration process.
Retention and Scope Parameters
Remote backup configurations typically define what data is included, how long backup copies are kept, and how older copies are rotated or overwritten. These parameters should be set in a manner consistent with, but distinct from, the organization's records retention decisions.

Common questions

Answers to the questions practitioners most commonly ask about Remote Backup.

Is a remote backup the same as a records retention or archiving solution?
No. A remote backup is a copy of data held offsite primarily to support recovery after loss, corruption, or disaster. It is not, in itself, a records retention or archiving mechanism. Retention concerns keeping records for defined periods to meet business, legal, or regulatory requirements, while archiving typically involves managing records that must be preserved over the long term with controls for authenticity and accessibility. A backup is generally a point-in-time operational copy, often overwritten on a rotating schedule, and its purpose, controls, and lifecycle differ from those applied to authoritative records held under a retention schedule. Relying on backups as a substitute for records retention can be problematic, since backups may not preserve the classification, metadata, or disposition controls that records management requires.
Does having a remote backup mean an organization has satisfied its recordkeeping obligations?
Not necessarily. The existence of a remote backup addresses the availability and recoverability of data, but recordkeeping obligations typically extend well beyond the ability to restore a copy. Depending on jurisdiction, sector, and organizational policy, obligations may include maintaining the authenticity, reliability, integrity, and usability of records, applying agreed retention periods, and carrying out defensible disposition. A backup copy is often not managed as an authoritative record and may lack the metadata, access controls, or evidential qualities that distinguish a record from mere information. Organizations generally need distinct records management arrangements in addition to backup arrangements, and the two should not be treated as interchangeable.
How does a remote backup relate to a legal hold?
When a legal hold is in place, relevant records and information typically must be preserved and protected from alteration or destruction, and this may affect how remote backups are handled. Because many backup systems rotate or overwrite copies on a schedule, an organization may need to identify whether responsive material exists within backups and take steps to prevent its loss during the hold. Whether and how backups fall within the scope of a legal hold depends on jurisdiction, the nature of the matter, and organizational policy, so this is generally a question to address with legal and compliance advisors rather than by assumption.
What should be considered when setting the frequency and rotation of remote backups?
Frequency and rotation are typically driven by how much data loss an organization can tolerate and how quickly it needs to recover, sometimes expressed through recovery objectives. More frequent backups can reduce potential data loss but may increase storage and processing demands, while rotation schemes determine how long earlier copies are retained before being overwritten. It is worth noting that aggressive rotation can conflict with retention or hold requirements if material that must be preserved exists only in backups. Decisions in this area generally depend on organizational risk appetite, the criticality of the systems involved, and any applicable retention or legal obligations.
How should the security of remotely stored backups be addressed?
Because remote backups place copies of data outside the primary environment, controls are generally needed to protect their confidentiality and integrity, both in transit and at rest. Common considerations include encryption, access restrictions, and monitoring, as well as ensuring that the integrity of backed-up data can be verified so that a restored copy is trustworthy. Where backups are held by a third party or in another jurisdiction, additional privacy, contractual, and data location considerations may apply, and these depend on the applicable legal and regulatory environment and on organizational policy.
How can an organization confirm that its remote backups are usable?
A backup provides limited assurance unless it can actually be restored. Organizations often address this through periodic restoration testing, verifying that data can be recovered and that recovered data is complete and intact. Testing may also confirm that recovery can be achieved within the timeframes the organization requires. From a records perspective, it is worth checking that any restored material retains the qualities needed for it to remain usable and reliable. The appropriate scope and frequency of testing generally depend on the criticality of the systems, organizational risk tolerance, and any relevant obligations.

Common misconceptions

A remote backup satisfies records retention and disposition requirements.
Backup and records retention serve different purposes. Backup supports operational continuity and recovery, whereas retention is a records management decision about how long a record is kept for its evidential, legal, or business value. Depending on jurisdiction and organizational policy, holding data in backup does not by itself demonstrate compliant retention, and backup cycles may overwrite data on schedules unrelated to retention rules.
The remote backup copy is the same as the authoritative record.
A remote backup typically holds a copy rather than the authoritative record. The properties that make something an authoritative record, such as authenticity, reliability, integrity, and usability, are not automatically preserved simply because a copy exists offsite. Organizations should establish which instance is treated as the record and how its integrity is maintained.
Having a remote backup means data can always be recovered.
Recovery is not guaranteed by the existence of a backup alone. Restoration may fail due to incomplete copies, corruption, incompatible formats, or untested procedures. In many cases the reliability of recovery depends on regular verification and testing rather than on the backup's mere presence.

Best practices

Distinguish clearly between backup copies and authoritative records, documenting which instance carries evidential status and how its authenticity and integrity are maintained.
Set backup retention and rotation parameters deliberately, and reconcile them with records retention and disposition decisions rather than assuming backup cycles fulfill retention obligations.
Test restoration from remote backups periodically to confirm that copies are complete, usable, and recoverable, rather than relying on the existence of the backup alone.
Apply appropriate integrity and confidentiality controls, such as encryption in transit and at rest and verification of copied data, in a manner consistent with organizational security and privacy requirements.
Consider how legal holds and jurisdiction-specific obligations interact with backup overwriting, since routine deletion of backup data may affect data subject to preservation duties depending on the applicable regime.
Document the scope, schedule, location, and responsibilities for remote backup so that continuity arrangements are auditable and aligned with broader information governance policy.