GDPR and data recovery.
Protecting personal data includes making it available again after an incident. Backup tests help you assess your ability to do this.
Art. 32(1)(c) and (d) GDPR covers the timely restoration of availability and access to personal data, as well as regular testing of the effectiveness of safeguards. Which measures are appropriate depends on the risks of the processing.
What this means for your backups
Restore tests help you assess whether your backups will serve their purpose in an incident. Art. 32 does not set a fixed testing interval. Plan the frequency and scope to suit the data involved and its protection needs.
Test restores and review the results
RestoreTrust restores selected database backups to a temporary test database and runs your checks. You can see which steps succeeded and where errors occurred. Tests run in your Kubernetes cluster.
Protect your test data
Include test copies in your access and deletion policies. Align data flows and any required data processing agreements with how you use the service. Credentials for your backup sources stay in your cluster as Kubernetes Secrets.
How RestoreTrust helps
- Restore tests on your schedule
- Documented checks and results
- Execution in your Kubernetes cluster
How to put the tests into practice
- Match tests to your data’s protection needs
- Define access and deletion rules for test copies
- Include results in your data protection reviews
Part of your approach to data protection
With RestoreTrust, you regularly test and document whether your backups can be restored. This forms part of your measures to secure data processing. Together with access controls, deletion policies, and other safeguards, these tests help protect personal data.