DRP and BCP
Outsourced DRP: pros and cons
An outsourced DRP entrusts a provider with the place where servers restart and, often, with keeping the copies. It saves an SME from buying a second server room. It does not spare it from knowing who triggers the plan, where the key is, and whether the last test succeeded.
Updated in October 20264 min read5 sources cited
Key points
- Pros: no second building, cost mainly tied to usage, copies already off site, tests without in-house hardware.
- Cons: the RPO remains that of the backup, the RTO depends on people and hours, and the key is your responsibility.
- The ANSSI, France’s national cybersecurity agency, recommends encrypting before sending to the provider and checking that the restore time is compatible with your maximum tolerable downtime.
- The contract must list the hosting locations, provide for reversibility and, if personal data is processed, include the clauses of Article 28 of the GDPR.
- An automatic start-up test is not a business test.
Pros
- No second building. The instances exist at the provider’s premises. On the day of the disaster, nobody rushes out to buy a server.
- Cost mainly tied to usage. In a model where activation is billed per day, incident-free months cost the preparation (storage, agents, addresses), not a fleet of running machines.
- Copies already off site. The DRP and the off-site backup feed each other. No tapes need to be transported.
- Technical tests possible without in-house hardware. Starting an image at the provider’s site does not require a test server in the cupboard.
- Chosen geographical area. Useful when the law or a contract requires a specific country, provided the contract actually says so. The ANSSI recommends requiring the provider to list all data storage locations, including the primary site and standby sites.
Cons
- The RPO is not magic. It remains equal to the age of the chosen backup. The provider does not reconstruct data entries that were never copied.
- The RTO depends on people. If the only authorised person cannot be reached, the instance does not start. Outsourcing does not create an on-call service you have not paid for. With a provider open from 9:00 to 17:30 on weekdays, a disaster on a Saturday evening has to wait, unless the contract says otherwise. The ANSSI calls for vigilance on this point: the restore time at the provider must be compatible with your maximum tolerable period of disruption.
- The key. If you alone can decrypt, you alone can restore. The ANSSI specifically recommends encrypting backups using the organisation’s own means before sending them to the provider. This protects against unauthorised reading. It is also a responsibility: lose the key and the DRP is unusable. An honest provider will not offer to keep the key “to help you out” without explaining that it would then be able to read the data.
- The network. Users must be able to reach the standby. An outsourced DRP with no planned IP address and no tested VPN restores unreachable servers.
- The return. Moving back to the repaired site, with the data entered in the meantime, is a project in itself. Contracts say a lot about the outbound failover and little about the return.
- A start-up test is not a business test. An automatic monthly check that verifies start-up is a real plus. It does not prove that the business software works.
- Dependency. Changing provider requires re-reading the copies. The contract must state within what timeframe and in what form you leave with your data: this is what the ANSSI calls reversibility, the ability to take back the outsourced function or entrust it to a third party, with the provider’s assistance during the migration.
What the contract must contain
The ANSSI guide on outsourcing recommends appending a security assurance plan to the contract and providing for audits of backup and recovery procedures. When the copies contain personal data, which is almost always the case, the provider is a processor within the meaning of the GDPR. Article 28 then requires a written contract, and the processor’s guide published by the CNIL, France’s data protection authority, details its content.
| Item | Why | Where to check it |
|---|---|---|
| Hosting locations, primary and standby | Legal or contractual data location requirement | Contract, security assurance plan |
| Support and activation hours | They are part of the real RTO | Service terms |
| Tests included and tests on quotation | Measure the RTO before a disaster | Commercial offer |
| Who holds the encryption key | Confidentiality and ability to restore | Contract, internal procedure |
| Reversibility | Leave with your data if you change provider | Dedicated clause |
| What happens to data at the end of the contract | GDPR: return or destruction of all copies | Data processing agreement |
| Sub-processors | GDPR: prior written authorisation | Data processing agreement |
| Breach notification | GDPR: the processor informs the customer | Data processing agreement |
Article 32 of the GDPR also requires the ability to restore the availability of and access to personal data in a timely manner, as well as a process for regularly testing the effectiveness of the measures. An outsourced DRP contributes to this, if it is actually tested.
When it is the right choice
An SME with no second server room, one to a few servers whose downtime is counted in hours rather than minutes, and a wish not to invest in idle hardware. When downtime is counted in minutes, look instead at a BCP, bearing in mind its ongoing cost: see Outsourced BCP: pros and cons.
At WeDoBack
The outsourced DRP corresponds to the published DRP offer: storage from 175 € excl. VAT per TB per month, agents, public IP addresses at 0.54 € excl. VAT per month, instances, activation during a disaster billed per day, a monthly start-up test that does not affect production, and a real-conditions test of up to 10 hours on quotation. Data is encrypted on the machine before sending, with a key held by the customer, and stored on servers dedicated to backup, made redundant across several European countries or in the area required by the customer’s legislation. The data centres and solutions used are ISO 27001 and HDS (French health data hosting) certified, and processing complies with the GDPR. Human support is available from 9:00 to 13:00 and from 14:00 to 17:30 (Paris time). These hours are part of the real RTO. They should be read before signing, not after the disaster.
Frequently asked questions
Which clauses should be checked in an outsourced DRP contract?
The hosting locations (primary and standby), support and activation hours, the triggering procedure, the tests included, reversibility (in what form and within what timeframe you get your data back) and, for personal data, the GDPR clauses: documented instructions, security, sub-processors, and what happens to the data at the end of the contract.
Can the provider keep the encryption key for extra security?
It can, but it will then be able to read your data. If you alone hold the key, nobody else can decrypt the copies, but you must keep it in a safe place, off site, with at least two people able to retrieve it. The ANSSI, France’s national cybersecurity agency, recommends encryption using the organisation’s own means before sending.
Is an outsourced DRP enough to comply with the GDPR?
It contributes to Article 32, which requires the ability to restore the availability of personal data in a timely manner and a process for regularly testing the measures. It is not enough on its own: you also need a data processing agreement compliant with Article 28, a breach register and documented tests.
Sources
Documents consulted in October 2026.
- Outsourcing and information system security: a guide to managing the risks (2010) — ANSSI (French agency)
- Information system backup: the fundamentals (ANSSI-BP-100, v1.1, 27 November 2025) — ANSSI (French agency)
- General Data Protection Regulation: guide for processors (September 2017 edition) — CNIL (French authority)
- Regulation (EU) 2016/679 (GDPR), Articles 28 and 32 — EUR-Lex
- DRP offer: recovery after a disaster — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
