Microsoft 365 and Google Workspace Backup: What Irish Businesses Get Wrong
“It’s in the cloud, so it’s backed up.”
That line gets repeated in boardrooms and IT reviews across Ireland, and it’s one of the more expensive misunderstandings in business technology. Keeping the lights on is Microsoft’s and Google’s job; keeping your data recoverable is yours — which is exactly why Microsoft 365 and Google Workspace backup has become its own line item on IT budgets, separate from the platforms themselves.
Shared Responsibility: What Microsoft and Google Actually Cover
Both Microsoft and Google operate under what’s known as a shared responsibility model. They are responsible for the infrastructure: the servers stay up, the data centres stay secure, the platform stays available. You are responsible for the data inside it — which means recovering from accidental deletion, insider mistakes, malicious actors, and sync errors falls to you, not to them.
Neither Microsoft nor Google promises full restoration of your data after it’s been deleted, whether that deletion was accidental or malicious. Their job is uptime. Yours is recoverability.
The Native Retention Trap
Both platforms include some recovery options, and this is where most businesses get caught out — the native tools look like backup, but they’re built for short-term accidents, not long-term protection:
- Google Workspace’s Trash typically empties automatically after around 30 days, with a further admin recovery window of roughly 25 days on top — after that, the data is gone
- Microsoft 365’s Exchange retention is commonly set to somewhere between 14 and 30 days for deleted mail
- OneDrive and SharePoint allow longer recycle bin windows, often cited at up to 93 days
These figures vary by licence tier and admin configuration, so it’s worth checking your own tenant settings rather than assuming. But the pattern holds everywhere: once the window closes, native recovery closes with it.
Google Vault and Microsoft Purview Aren’t Backup
This is the mix-up we see most often. Google Vault and Microsoft Purview are retention and eDiscovery tools — built to help you search, hold and export data for legal or compliance reasons. They are not backup. They don’t keep an independent copy of your data, and they govern information in place rather than storing a separate, restorable version of it. If the underlying account or file is compromised, a retention policy doesn’t give you something clean to restore from.
Why This Matters More in 2026
Ransomware recovery has quietly become a backup story rather than a ransom story. A 2026 survey of organisations hit by ransomware found the majority who had their data encrypted were able to recover it from backup, and the share paying the ransom has been falling — but the average recovery bill for the ones who weren’t properly protected still ran into seven figures. Backup isn’t the exciting part of a cybersecurity budget, but it’s consistently the part that decides whether an incident is a bad week or a bad year.
Accidental deletion remains the more common cause day to day — an employee clearing out a shared drive, a departing staff member’s account being wiped before anyone copies what they needed, a sync error that overwrites a file nobody noticed changed. None of that needs a hacker. It just needs a Tuesday.
The GDPR Angle Most Backup Advice Misses
Most backup guidance online is written for a US audience, and it misses something that matters specifically for Irish businesses: GDPR’s storage limitation principle. Under Article 5(1)(e), personal data shouldn’t be kept longer than necessary for the purpose it was collected for — which means “back up everything forever” isn’t actually the safe option it sounds like.
A proper backup strategy for an Irish business needs a defined retention schedule, not just a long one — recoverable far enough back to handle a real incident, but not an indefinite, undocumented pile of personal data sitting outside your stated retention policy. That balance is something generic backup tools rarely think about, and it’s exactly the kind of detail worth getting right before the Data Protection Commission asks about it rather than after.
What Proper Microsoft 365 and Google Workspace Backup Looks Like
Not all backup tools get this right — here’s what we think matters most:
- An independent copy stored outside your Microsoft 365 or Google Workspace tenant, so a compromised admin account can’t reach the backup too
- Point-in-time, granular restore — a single email or file, not just an entire mailbox
- Immutable retention for at least part of the backup window, so ransomware can’t encrypt or delete the backup itself
- A retention schedule that’s actually documented and aligned with your GDPR obligations, not just set to “keep everything”
- Monitoring and alerting, so a failed backup job gets noticed before you need it, not after
Key Takeaways
- Microsoft and Google secure the platform; protecting your data inside it is your responsibility.
- Native recycle bins and retention windows are short and built for accidents, not long-term protection.
- Google Vault and Microsoft Purview are compliance and eDiscovery tools, not backup.
- Backup retention needs a defined schedule under GDPR, not an indefinite one.
- An independent, immutable backup is what actually protects you against ransomware and accidental deletion alike.
Frequently Asked Questions
Does Microsoft 365 have built-in backup?
Not in the way most businesses assume. Microsoft offers short native retention windows and a separate, pay-as-you-go Microsoft 365 Backup service for specific workloads, but full, independent backup of mail, files and Teams data typically still needs a third-party solution.
Is Google Vault enough to protect our data?
No. Vault is a retention and eDiscovery tool for holding and searching data in place — it doesn’t create an independent, restorable copy of your Workspace data the way a dedicated backup does.
How long do Microsoft and Google keep deleted data?
It varies by plan and admin configuration, but native windows are generally measured in weeks, not years. Once that window closes, the data is typically unrecoverable through native tools.
Do we still need backup if we’re already GDPR compliant?
Yes — compliance and backup solve different problems. GDPR governs how long you can lawfully hold personal data; backup governs whether you can recover it if something goes wrong before that. You need both, and they need to agree with each other.
If your current setup is leaning on native retention and hoping it’s enough, now’s a sensible time to check — not after a deletion you can’t undo. Get in touch and we’ll walk you through what proper backup coverage would look like for your Microsoft 365 or Google Workspace environment. It pairs naturally with managed IT support — if you’re reviewing one, it’s worth reviewing both.