COMPLIANCE & GOVERNANCE

Backup governance aligned with GDPR, NIS2 and DORA.

European law now treats backup as a legal obligation, not a best practice: 7dBackup provides the technical measures these rules call for, encryption, tested restores, documented retention and audit evidence, on infrastructure hosted in certified EU data centers.

GDPR

Reg. (EU) 2016/679

NIS2

Dir. (EU) 2022/2555

DORA

Reg. (EU) 2022/2554

EU

Data residency

REGULATORY MAPPING

What European law asks of your backups

Three major EU frameworks now name backup, restoration and recovery explicitly, and each platform capability below maps to the article that requires it. For healthcare organizations working with US counterparts, the same controls also align with the HIPAA Security Rule, whose §164.308(a)(7) requires a data backup and disaster recovery plan.

GDPR

GDPR, Art. 32

Security of processing: encryption of personal data and the ability to restore availability and access in a timely manner after an incident, Art. 32(1)(a) and (c).

NIS2

NIS2, Art. 21(2)(c)

Backup management and disaster recovery are named minimum measures for essential and important entities, detailed further by Implementing Regulation (EU) 2024/2690.

DORA

DORA, Art. 12

Financial entities must document backup scope and frequency by data criticality, and periodically test restoration and recovery procedures.

GDPR

GDPR, Art. 5

Storage limitation and integrity: documented retention policies per tenant keep backup data only as long as your legal basis allows.

LOG

Audit evidence

Every administrative action and every backup or restore job is tracked: a continuous, reviewable trail for supervisory authorities and auditors.

WORM

Ransomware resilience

Immutable Object Lock copies support the integrity and resilience outcomes NIS2 and DORA expect, even against attackers holding valid credentials.

CONTROL-TO-ARTICLE MAPPING

Controls that map to the letter of the law

Each platform control answers a specific requirement of European legislation, so regulatory evidence is a by-product of daily operations, not an extra project.

  • Encryption of personal data, GDPR Art. 32(1)(a)
  • Timely restore of availability and access, GDPR Art. 32(1)(c)
  • Regular testing of technical measures, GDPR Art. 32(1)(d)
  • Backup management and disaster recovery, NIS2 Art. 21(2)(c)
  • Documented backup policies and tested recovery, DORA Art. 12

HA

Active-active replicated console

WORM

Anti-ransomware immutable storage

O

Hardware required on client side

Continuity of the backup-restore cycle

EUROPEAN FRAMEWORK

Designed around European requirements

The regulations and standards most often cited in audits, alongside the platform capabilities that answer them.

  • Z
    GDPR, Reg. (EU) 2016/679
  • Z
    NIS2, Dir. (EU) 2022/2555
  • Z
    DORA, Reg. (EU) 2022/2554
  • Z
    ISO 27001 hosting
  • Z
    Immutable retention (WORM)
  • Z
    EU data residency
  • Z
    Audit logging
  • Z
    HIPAA-aligned (US healthcare)