Backup
How should schools and non-profits back up their data?
Pupil records, safeguarding files and donor data deserve the same protection as any bank's. Here's how to get there with one part-time administrator.

The short answer
Start with the data that would hurt most to lose, such as pupil records, safeguarding files and donor data. Back it up automatically to an independent, immutable copy outside Google Workspace or Microsoft 365, stored in the EU, and test a restore every term. GDPR applies to small organisations too, so keep a short written policy as evidence.
Key takeaways
- GDPR applies to the data, not the size of the organisation: GDPR Article 32(1)(c) requires the ability to restore personal data in a timely manner, and Recital 38 says children merit specific protection.
- Google Workspace for Education and Microsoft 365 Education keep the service running, but protecting your content is your responsibility under their shared responsibility models.
- In Sophos's 2025 education survey, 59% of lower-education organisations whose data was encrypted used backups to recover it.
- Kennisnet's 2025 threat assessment for Dutch primary and secondary schools names ransomware among the five main threats and stresses a good backup and recovery plan.
- An affordable, audit-ready setup has four parts: automated immutable backups of priority data, a one-page policy, termly test restores and an annual review.
Why do schools and non-profits need their own backup?
Because they hold some of the most sensitive personal data there is, and the law and their insurers expect them to be able to recover it. The platform they use doesn't do that for them.
Picture a primary school whose Google Workspace tenant holds pupil records, safeguarding notes, individual education plans and years of parent correspondence. IT is one person who also looks after the Wi-Fi and the digiboards. When the board asks, prompted by the insurer, whether pupil data could be recovered after a ransomware attack, the honest answer is no. That isn't negligence. Nobody was ever given the time to make it yes, which is what a simple backup as a service setup can fix.
Size doesn't change the rules. GDPR Article 32(1)(c) requires "the ability to restore the availability and access to personal data in a timely manner", Article 5(2) requires you to be able to demonstrate compliance, and Recital 38 states that "children merit specific protection with regard to their personal data". A school or charity has the same accountability as a large company.
Which data should schools and non-profits protect first?
The data whose loss would harm people, breach a legal duty or stop your work. Rank it, then protect from the top down.
| Priority | Schools | Non-profits |
|---|---|---|
| 1. Highest | Safeguarding files, pupil health information, individual education plans | Beneficiary case files, especially health or social care data |
| 2. High | Pupil records and results, staff HR files | Donor details and gift history, staff and volunteer records |
| 3. Medium | Attendance, parent correspondence, finance | Finance, grant reports, contracts |
| 4. Lower | Lesson plans, internal notes | Operational documents, marketing |
Retention periods differ per category and per country, so write down a simple schedule for each one rather than deciding case by case. Lesson plans can wait. The safeguarding file can't.
Doesn't Google or Microsoft already back up school data?
No. Both keep the service available and offer short recovery windows, but both place responsibility for your content with you.
Google's Workspace for Education data protection implementation guide says Google "protects the infrastructure underlying Google Workspace for Education", while the school is "responsible for the security of components that you provide or control, such as the content you put in" the services. Native recovery is time-limited. Deleted Gmail stays in trash for 30 days, and admins then have 25 more days to restore it. A deleted pupil or staff account can be restored for only 20 days: Google's help page on restoring users says "after 20 days, the data is gone". On Microsoft 365, the recycle bin keeps deleted items for up to 93 days.
The practical test: could you restore one pupil's complete file from two years ago for an accreditation review? With native tools alone, you can't. Read more in the gaps in Google Workspace's native recovery and does Microsoft 365 back up your data?
How big is the ransomware risk for schools?
Real and well documented. Education is a frequent target because defences are thin and the data is sensitive, and backups are what most victims fall back on.
Sophos's State of Ransomware in Education 2025 surveyed 441 IT and security leaders in education across 17 countries. In lower education, attackers encrypted data in 29% of attacks, and 59% of those whose data was encrypted used backups to recover. In higher education, 58% of attacks led to encryption and 47% recovered from backups. Phishing was behind 22% of attacks in lower education.
Closer to home, Kennisnet's Dreigingsbeeld Cybersecurity primair en voortgezet onderwijs 2025 lists DDoS attacks, supplier dependency, infostealers, phishing and ransomware as the five main threats to Dutch schools. It notes that School-CERT has seen digital attacks rise since the 2023 assessment, and stresses that a good plan for backup and recovery is of great importance, including backups that don't depend on your main supplier.
What does an affordable, audit-ready backup setup look like?
Automated backups of your priority data, a one-page policy, and a test restore every term. One or two part-time administrators can run it.
- Inventory in an afternoon. List where sensitive data lives, such as the Workspace or Microsoft 365 tenant, the student or donor system and local file shares, and tag each with its priority and retention.
- Automate backup of the top tiers. Daily, with no appliance to maintain and no tapes to carry home.
- Insist on immutable, EU-hosted copies. Immutable means nobody, including an attacker with admin rights, can change or delete the copy. EU hosting keeps the copy under EU law.
- Write the one-page policy. What is backed up, how often, where, how long, who's responsible and how you test. That page plus system reports is your audit file.
- Test one restore per term. Recover a mailbox or a folder, note the date and how long it took, and keep the report. Our guide on how to verify your backup works explains what to record.
The UK Department for Education's cyber security standards for schools and colleges are a useful benchmark even outside the UK. They ask schools to keep three copies of data, two on separate devices and one off-site, to make backups immutable, and to test them termly. That matches the 3-2-1-1-0 rule we use.
| Scenario | Native Workspace or Microsoft 365 tools | Independent EU backup |
|---|---|---|
| File deleted, noticed months later | Gone once the recovery window closes | Restorable from the backup |
| Leaver's or pupil's account deleted | Gone after the grace period | Kept according to your policy |
| Ransomware empties trash, then encrypts | No clean recovery path | Clean immutable copy |
| Auditor or insurer asks for restore evidence | Nothing to show | Termly test reports |
How does Mindtime help schools and non-profits?
We take the technical work off a small team's plate and give you the evidence to show the board, the auditor and the insurer.
- Workloads: Google Workspace backup (Gmail, Drive, Calendar, Contacts) and Microsoft 365 backup (Exchange, OneDrive, SharePoint, Teams), plus servers, NAS and endpoints.
- Where your data lives: only in our own Tier III data centres in the Netherlands and Germany, under EU law and independent of US hyperscalers.
- Protection: immutable backups with Object Lock plus an air-gapped copy, scanned for malware, with every backup job checked automatically and monitored 24/7.
- Paperwork: a GDPR Data Processing Agreement with every contract, and ISO 27001 and NEN 7510 audits.
- People: personal support in Dutch, German and English, with no offshore call centres or chatbots.
Unlimited backup jobs and unlimited storage mean you don't have to choose which year's records to keep because of a storage limit.
What to do next
Schools and non-profits hold sensitive data and get no regulatory discount for doing it on a small budget. The workable answer isn't enterprise infrastructure. It's clear priorities and automation: protect safeguarding files, pupil records and donor data first, with immutable EU-hosted backups that produce their own evidence, under a policy that fits on one page.
This term, pick one dataset from your top tier and try to restore it from two months ago. If you can't, start with the basics of backup as a service.
Want help sizing a setup for your school or charity? Ask us for a free assessment and we'll think it through with you.
This article is information, not legal advice.
Frequently asked questions
Do small schools and charities have to comply with GDPR?
Yes. GDPR applies to any organisation processing personal data of people in the EU, whatever its size or budget. Schools and charities often hold children's data, health information and safeguarding records, which need extra care. Article 32 requires the ability to restore personal data after an incident, and Article 5(2) requires you to be able to demonstrate it.
Is Google Workspace for Education automatically backed up?
No. Google keeps the service available and offers limited recovery: deleted Gmail stays in trash for 30 days, admins can restore it for 25 days after that, and deleted accounts can be restored for 20 days. Under Google's shared responsibility model, protecting your content is the school's job. Multi-year retention and point-in-time restores need an independent backup.
How often should a school test its backups?
At least once a term, and after any significant change to your systems. Restore a real mailbox or folder, check the files open, and record the date and how long it took. The UK Department for Education's cyber security standards ask for termly testing, which is a sensible benchmark for schools elsewhere in Europe too.
What does an audit-ready backup look like for a small organisation?
Four things: automated daily backups of your priority data to immutable, EU-hosted storage; a one-page policy naming the responsible people and retention per data category; termly test restores with the reports saved; and an annual review. That setup runs with one or two part-time administrators and produces the evidence auditors, funders and insurers ask for.
Where should a school's backup be stored?
Outside the platform you're backing up, so one incident can't take out both, and in data centres under EU law, so the copy of pupils' personal data stays within the same legal framework as the original. Make sure the copy is immutable and that you have a Data Processing Agreement with the backup provider.
Sources
- Regulation (EU) 2016/679 (GDPR)EUR-Lex, 2016
- Google Workspace for Education data protection implementation guideGoogle Cloud, 2023
- Restore a user's permanently deleted emailGoogle Workspace Help, 2026
- Restore a recently deleted userGoogle Workspace Help, 2026
- The State of Ransomware in Education 2025Sophos, 2025
- Dreigingsbeeld Cybersecurity primair en voortgezet onderwijs 2025Kennisnet, 2025
- Cyber security standards for schools and collegesUK Department for Education (GOV.UK), 2026


