Immutable backup: how long should data be retained?
The right period for an immutable backup is that of the risk to be covered, not the maximum period sold by the provider. Against ransomware or human error, 30 to 90 days is generally enough; for a legal obligation, it is the period set by law, applied only to the documents concerned.
Updated October 20263 min read5 sources cited
Key points
- Anti-ransomware: 30 days minimum, 90 days if monitoring is light or business is seasonal.
- Legal obligations: the period set by the law of your country (in France, for example: accounting records 10 years, payslips 5 years, patient records 20 years in healthcare facilities).
- These periods change: in France, tax documents go from 6 to 10 years for those whose period expires after 1 January 2027.
- Separate an operational area (short) from an archive area (long, limited to the documents you must be able to produce).
- Data that is immutable for ten years must remain decryptable and readable for ten years: key and format included.
Against ransomware and error: 30 to 90 days
The lock must last longer than the detection time.
- An accidental deletion is usually noticed within a few days. Fourteen to thirty days of immutability cover this case.
- Ransomware preceded by a silent intrusion is often noticed after one to several weeks. Thirty days is a minimum. Ninety days leaves a margin if monitoring is light or if the company closes for several weeks in summer.
- Beyond a few months, locking all the daily backups of all servers is expensive and also freezes personal data you no longer need. You then space out the restore points (one per week) or reserve long immutability for a subset.
Since a compliance lock cannot be shortened, choose the period after measuring the volume. A one-month trial, monitored closely, is better than a ten-year commitment on an entire server. The complementary measures (separate accounts, offline copy, alerts) are described in How do you protect your backups against ransomware?.
To meet an obligation to keep a document: the period set by law
The period is set by the law of your country (accounting, tax, health): check with your accountant or the competent authority. Example: France.
| Document | Retention period | What to lock |
|---|---|---|
| Accounting books and records | 10 years from the end of the financial year (French Commercial Code, Art. L123-22) | The records, not the daily disk image |
| Tax documents | 6 years, extended to 10 years for documents whose period expires after 1 January 2027 | The tax supporting documents |
| Copies of payslips | 5 years (French Labour Code) | The payslips |
| Standard commercial contract | 5 years; 10 years from delivery for a contract of at least €120 concluded electronically | The signed contract |
| Patient record in a healthcare facility | 20 years from the last stay or last outpatient consultation (French Public Health Code, Art. R1112-7) | The record |
These are the periods published by the French authorities for French companies, as consulted in October 2026; they do not apply in other European Union countries. The sector, the client’s country and the contract may require something else. The change in the retention period for tax documents in France, introduced by a law passed in June 2026, shows that a lock applied today sometimes needs to cover a longer period than originally planned: a reasonable margin is better than a lock that is too short.
For personal data, the GDPR requires a period proportionate to the purpose. The CNIL, France’s data protection authority, describes three phases: the active database, intermediate archiving (restricted access, for litigation or a legal obligation), then deletion or permanent archiving. Long-term immutability corresponds to intermediate archiving of a subset, not to keeping everything. Ten years of immutability on a complete mailbox is often excessive under the GDPR, whereas it is appropriate for an accounting ledger. The data protection officer, or a legal adviser, makes the call.
One period, two areas
Area A, operational: daily backups, immutable for 30 or 90 days, then automatic expiry. Objective: roll back.
Area B, archive: only the documents you must be able to produce, immutable for the legal period, in a format that will still be readable when it expires (PDF/A, database export, not an entire operating system). Objective: produce the document.
Mixing A and B under the same ten-year lock multiplies the volume by the number of nights. The distinction between the two uses is explained in What is the difference between backup and archiving?.
The key and the software
Data that is immutable for ten years must remain decryptable for ten years. This requires a key retention procedure that does not depend on people who may leave the company, and a format you will still be able to open. Immutable storage does not update the software needed to read the data.
At WeDoBack
The immutability period is chosen when you subscribe, up to the ten-year limit stated for the IMMUTABLE offer. The public price follows the locked volume: €20 excl. VAT per 100 GB block per month, plus one agent. Example: 500 GB locked costs €100 excl. VAT per month, plus one agent (€6 excl. VAT for a virtual server). When the period ends, a new subscription starts a new period. Nothing on the site allows a running lock to be shortened: this is consistent with WORM, and it must be decided before the data is written. The encryption key stays with the client, who is responsible for keeping it for the entire chosen period.
Frequently asked questions
Can I make my entire email system immutable for ten years?
Technically yes, but it is rarely justified. The GDPR requires a retention period proportionate to the purpose, and the CNIL, France’s data protection authority, distinguishes between the active database, intermediate archiving and deletion. Lock for ten years what a law requires you to keep for ten years, not all of your correspondence.
What happens at the end of the immutability period?
The lock is lifted. The data can then be deleted by the normal retention cycle, or locked again for a new period. Nothing is erased automatically if no deletion rule has been set.
Does the legal period start from the backup date?
No, it starts from the event set by the law, for example in France: the end of the financial year for accounting, the patient’s last stay for medical records, the last transaction for tax documents. A document backed up late must therefore be locked until the correct expiry date, not for ten years after the backup.
Sources
Documents consulted in October 2026.
- What are the document retention periods for businesses? — Entreprendre.Service-Public.gouv.fr (example: France)
- Change to the retention period for tax documents — Entreprendre.Service-Public.gouv.fr (example: France)
- Medical records — Service-Public.gouv.fr (example: France)
- Practical guide: Retention periods (July 2020) — CNIL (French authority)
- IMMUTABLE offer: WORM storage and prices — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
