COMPLIANCE & GOVERNANCE
Backup governance aligned with GDPR, NIS2 and DORA.
European law now treats backup as a legal obligation, not a best practice: 7dBackup provides the technical measures these rules call for, encryption, tested restores, documented retention and audit evidence, on infrastructure hosted in certified EU data centers.
GDPR
Reg. (EU) 2016/679
NIS2
Dir. (EU) 2022/2555
DORA
Reg. (EU) 2022/2554
EU
Data residency
REGULATORY MAPPING
What European law asks of your backups
Three major EU frameworks now name backup, restoration and recovery explicitly, and each platform capability below maps to the article that requires it. For healthcare organizations working with US counterparts, the same controls also align with the HIPAA Security Rule, whose §164.308(a)(7) requires a data backup and disaster recovery plan.
GDPR
GDPR, Art. 32
Security of processing: encryption of personal data and the ability to restore availability and access in a timely manner after an incident, Art. 32(1)(a) and (c).
NIS2
NIS2, Art. 21(2)(c)
Backup management and disaster recovery are named minimum measures for essential and important entities, detailed further by Implementing Regulation (EU) 2024/2690.
DORA
DORA, Art. 12
Financial entities must document backup scope and frequency by data criticality, and periodically test restoration and recovery procedures.
GDPR
GDPR, Art. 5
Storage limitation and integrity: documented retention policies per tenant keep backup data only as long as your legal basis allows.
LOG
Audit evidence
Every administrative action and every backup or restore job is tracked: a continuous, reviewable trail for supervisory authorities and auditors.
WORM
Ransomware resilience
Immutable Object Lock copies support the integrity and resilience outcomes NIS2 and DORA expect, even against attackers holding valid credentials.
CONTROL-TO-ARTICLE MAPPING
Controls that map to the letter of the law
Each platform control answers a specific requirement of European legislation, so regulatory evidence is a by-product of daily operations, not an extra project.
- Encryption of personal data, GDPR Art. 32(1)(a)
- Timely restore of availability and access, GDPR Art. 32(1)(c)
- Regular testing of technical measures, GDPR Art. 32(1)(d)
- Backup management and disaster recovery, NIS2 Art. 21(2)(c)
- Documented backup policies and tested recovery, DORA Art. 12
HA
Active-active replicated console
WORM
Anti-ransomware immutable storage
O
Hardware required on client side
Continuity of the backup-restore cycle
EUROPEAN FRAMEWORK
Designed around European requirements
The regulations and standards most often cited in audits, alongside the platform capabilities that answer them.
- GDPR, Reg. (EU) 2016/679
- NIS2, Dir. (EU) 2022/2555
- DORA, Reg. (EU) 2022/2554
- ISO 27001 hosting
- Immutable retention (WORM)
- EU data residency
- Audit logging
- HIPAA-aligned (US healthcare)