How Long Should a Business Keep Backups?
"How long should we keep backups" comes up in almost every conversation we have about business continuity, and the honest answer is: it depends on the type of data, your industry, and what you are protecting against. This guide walks through the factors that should actually drive that decision.
Backup retention should be set by data type rather than a single company-wide number: daily backups for a rolling 2 to 4 weeks, weekly backups for 3 to 12 months, and monthly or yearly backups for 1 to 7 years depending on financial, legal, or regulatory requirements specific to your industry.
Retention is not the same as RPO or RTO
Recovery point objective (RPO) is how much data you can afford to lose, which determines how often backups run. Recovery time objective (RTO) is how quickly you need to be back online, which determines your recovery method and infrastructure. Retention is a separate question: once a backup exists, how long do you keep it before it is deleted or overwritten?
A business can have an aggressive RPO of one hour and still have a short retention window, or a relaxed nightly backup schedule with years of retention for compliance reasons. The three settings need to be decided independently, not assumed to be the same thing.
Grandfather-father-son scheduling
Most backup platforms, including Acronis Cyber Protect Cloud, use a grandfather-father-son (GFS) rotation to keep retention manageable. Daily backups ("son") are kept for a short rolling window. Weekly backups ("father") are kept longer. Monthly or yearly backups ("grandfather") are kept longest, often for years, but with far fewer restore points to manage storage costs.
This structure lets a business restore a file from yesterday easily, restore from three weeks ago if needed, and still have a monthly snapshot from a year ago for audit or legal purposes without keeping 365 daily copies.
Legal and regulatory drivers in Ontario and Canada
Retention requirements vary by industry, record type, and applicable legislation, and they change over time. This section is general information, not legal advice. Confirm specific retention obligations with your accountant, lawyer, or regulatory body before finalizing a policy.
That said, some general patterns are worth knowing. The Canada Revenue Agency generally expects businesses to retain financial records for a period of years after the relevant tax year. Regulated professions such as law and healthcare often have record retention rules set by their governing college or law society. Personal information handled under PIPEDA should only be retained as long as it is needed for the purpose it was collected, which is a reason not to keep data indefinitely by default.
Not sure what your current retention policy actually covers?
We review existing backup retention settings against your industry's typical requirements and flag gaps before they become a problem.
Request a Retention ReviewRetention needs by industry
- Accounting firms typically need financial records retained for several years to support tax filings and potential audits, see our accounting firm IT support page for related considerations
- Legal practices often have file retention obligations set by their law society that extend well beyond typical backup defaults, see law firm IT support
- Healthcare providers handle personal health information with retention rules set provincially and by regulatory colleges, see healthcare IT support
- Construction firms often need project and contract records available for years to cover warranty and liability periods, see construction IT support
Recommended retention by data type
| Data type | Daily retention | Weekly retention | Monthly/yearly retention |
|---|---|---|---|
| File server / general documents | 14 to 30 days | 3 months | 12 months |
| Financial and accounting records | 30 days | 6 months | 7 years (confirm with accountant) |
| Email and Microsoft 365 mailboxes | 30 days | 3 to 6 months | 1 to 7 years depending on industry |
| Legal or client files (regulated) | 30 days | 12 months | As required by governing body, often years |
| Line-of-business database | 14 to 30 days | 3 months | 12 months, longer if audited |
Storage cost trade-offs
Longer retention means more storage, and cloud backup storage is billed on an ongoing basis, so retention policy is also a budgeting decision. GFS rotation keeps costs sane by thinning out older restore points, but businesses with strict compliance needs should expect retention-driven storage to be a real, recurring line item rather than a one-time cost.
It is worth reviewing retention settings annually. Data that no longer needs to be retained under any legal, tax, or contractual obligation is safe to age out, which keeps both cost and risk down, since data you no longer hold cannot be breached or subpoenaed.
Microsoft 365 retention vs backup
Microsoft 365 includes retention policies and a recycle bin, but these are compliance and short-term recovery tools controlled from within the same tenant an attacker or a mistaken admin action can affect. They are not a substitute for an independent backup with its own retention schedule stored outside the Microsoft 365 environment. We cover this distinction in more depth in Microsoft 365 backup: why it's necessary and offer dedicated SaaS backup to fill that gap.
Sources and further reading
Frequently asked questions
Is there a legal minimum backup retention period in Ontario?
There is no single retention law for backups specifically, requirements come from tax, industry, and privacy rules that apply to the underlying records, so confirm specifics with your accountant, lawyer, or regulator.
Should we keep backups forever to be safe?
No. Keeping data indefinitely increases storage cost and privacy risk without a corresponding benefit once legal and business needs for that data have passed.
Does longer retention mean better ransomware protection?
Not directly. Ransomware protection depends more on immutability and how far back you can go to find a clean restore point than on total retention length, though very short retention can leave you without a clean copy if an infection goes undetected for weeks.
How is retention different from how often backups run?
How often backups run is your RPO, retention is how long each of those backups is kept before it is deleted, the two are set independently.
Do Microsoft 365 retention policies count as backup retention?
No, Microsoft 365 retention policies govern compliance holds and recycle bin behaviour inside the same tenant, they do not replace an independent backup with its own retention schedule.
Joshua Arimoro
Joshua Arimoro is the Principal Consultant at Nickel City Tech Solutions, a managed IT and cybersecurity provider based in Lively, Ontario, serving businesses across Greater Sudbury and Northern Ontario. He works hands-on with Microsoft 365, server and network infrastructure, endpoint management, and backup and recovery for small and mid-sized organisations.
More about our teamSet a retention policy that fits your industry, not a generic default
We help Northern Ontario businesses set backup retention schedules that balance compliance, storage cost, and real recoverability.
Related services, locations, and resources
Related services
- Backup & Disaster Recovery
Backup strategy, monitoring, and recovery testing.
- Managed IT Services
Proactive monitoring, patching, and predictable monthly support.
- Cybersecurity Services
Endpoint protection, MFA, email filtering, and M365 hardening.
- Microsoft 365 Support
Exchange, Teams, SharePoint, OneDrive, and licensing.
Related service areas
Related resources
- The 3-2-1 Backup Rule Explained for Small Businesses
A plain-English breakdown of the 3-2-1 backup rule, why it evolved into 3-2-1-1-0, and how to map it onto a…
- What Happens When a Business Server Fails?
A realistic look at what actually happens, hour by hour, when a business server goes down, and why the outc…
- Ransomware Recovery: What Should a Business Do First?
A step-by-step response for the first hour after discovering ransomware, who to notify in Canada, the risks…
- Disaster Recovery Planning for Northern Ontario Businesses
How to build a disaster recovery plan that actually accounts for the realities of operating across Northern…
