Backup
What happens when your SaaS provider goes down?
You can't fix someone else's platform. You can decide in advance how your business keeps working, and make sure your data doesn't depend on one vendor.

The short answer
You lose access to the application and the data inside it until the provider fixes the problem, and you can't speed that up. SLAs pay service credits, not your losses. Prepare by knowing which processes depend on each SaaS tool, keeping an independent backup outside the provider and agreeing a written workaround plan.
Key takeaways
- During a SaaS outage your data is usually intact but unreachable, and the recovery timeline is entirely in the provider's hands.
- A 99.9% monthly uptime SLA still allows about 43 minutes of downtime a month, and Google Workspace's SLA compensates with service credits, not damages.
- Under the shared responsibility model, Microsoft states that customers always remain responsible for their data, accounts and access management in SaaS.
- The EU Data Act, applicable since 12 September 2025, gives customers switching and data-retrieval rights when they leave a cloud or SaaS provider.
- An independent backup outside the provider protects you against data loss and provider exit; a tested workaround plan covers the outage itself.
What actually happens when a SaaS platform goes offline?
Your people can't open the application or the data inside it, and there's nothing your IT team can repair. You wait for the provider, follow its status page and work around the gap.
It's a normal Wednesday. At midday, Outlook stops syncing, Teams calls drop and OneDrive files won't open. Your network is fine. The problem is somewhere inside your provider's platform, and your helpdesk can only tell people to wait.
That's close to what happened on 29 October 2025. According to Petri, an accidental configuration change in Azure Front Door disrupted Outlook, Teams, OneDrive and Intune across the US, Europe and parts of Asia for more than eight hours. Earlier that year, on 12 June, Google's incident report shows a faulty policy change in its Service Control system affected more than 80 Google Cloud products, with Gmail, Drive, Calendar, Meet and Docs also disrupted.
In most outages your data isn't lost, only out of reach. The bigger risks are what you can't do in the meantime, and what happens if the data really is gone. That's the part an independent backup as a service covers.
What does a SaaS SLA actually cover?
An SLA promises a level of uptime and pays service credits when the provider misses it. It doesn't cover your lost revenue, overtime or missed deadlines, and it says nothing about recovering data you deleted.
Take the Google Workspace SLA. It commits to at least 99.9% monthly uptime. If Google misses it, you get 3, 7 or 15 days of service credit depending on how far uptime fell, with 15 days as the monthly maximum. A 99.9% target still allows about 43 minutes of downtime in a 30-day month.
Data is a separate question. Microsoft's shared responsibility documentation says that whatever the service type, including SaaS such as Microsoft 365, you always keep responsibility for your data, endpoints, accounts and access management. The provider keeps the platform running; protecting what's inside it is your job. Our article on the Microsoft 365 shared responsibility model covers this in detail.
Outage, data loss or provider exit: which risk are you facing?
"The SaaS provider goes down" covers three different situations, and each needs a different answer.
| Situation | What happens to your data | What helps |
|---|---|---|
| Temporary outage | Intact but unreachable for minutes to hours | A workaround plan, a communication channel outside the platform and critical data reachable elsewhere |
| Data loss inside the SaaS | Deleted, overwritten or encrypted by a user, sync error or attacker | An independent, versioned backup with granular restore |
| Provider exit or account lockout | Stuck behind a closed account, a contract dispute or a provider that shuts down | Your own copy, plus a tested exit plan and contractual export rights |
Provider recycle bins help with small mistakes, but only for a limited time. Microsoft 365's recycle bins, for example, keep deleted items for up to 93 days; see does Microsoft 365 back up your data? After that, or after an admin purges them, the provider can't bring the data back.
For the exit scenario, EU law now helps. The Data Act, Regulation (EU) 2023/2854, has applied since 12 September 2025 and includes rules for switching between data-processing services, SaaS included. According to a Garrigues analysis, Article 25 limits the notice period to two months, sets a 30-day transitional period and gives you at least 30 days to retrieve your data, and switching charges disappear from 12 January 2027. Those rights help you leave; they don't keep you working during an outage.
How does independent backup reduce your SaaS dependency?
It puts a copy of your SaaS data outside the provider's platform and admin accounts. If data is lost, you restore it yourself. If you leave, you aren't racing an export deadline.
- Restore on your own terms: recover a single mailbox, file or Teams channel, or a whole site, without a support ticket to the provider.
- Survive account problems: the copy doesn't disappear if your tenant is compromised, suspended or closed.
- Go back in time: versioned backups let you return to a point before the deletion or encryption started.
- Keep data in the EU: we store backups only in our own Tier III data centres in the Netherlands and Germany, under EU law and independent of US hyperscalers.
We back up Microsoft 365 (Exchange, OneDrive, SharePoint and Teams) and Google Workspace (Gmail, Drive, Calendar and Contacts), with granular restore and immutable storage. See Microsoft 365 backup and Google Workspace backup.
Be realistic about what a backup does during a pure outage. If the platform itself is down, you can't restore into it until it's back. That's why the plan below matters as much as the backup.
How do you prepare your business for SaaS downtime?
Decide before the outage who does what, how people communicate and which work can continue without the platform. Then make sure your data has a second home.
- List your SaaS tools: owner, users, what data they hold and which business processes depend on them.
- Rank by impact: how long can each process stop before customers, cash flow or compliance suffer? That's your RTO. Our guide to RTO and RPO explains how to set it.
- Agree a fallback channel: if Teams and Outlook are down, how do managers reach staff? A phone tree or messaging group works.
- Write manual workarounds: paper forms, offline price lists, a local copy of today's appointments.
- Back up the data independently: versioned, immutable and outside the provider.
- Know your exit route: check your contract and your Data Act rights for export and switching.
- Rehearse once a year: a one-hour tabletop exercise shows the gaps quickly.
Outages caused by suppliers aren't unusual. Over nine years of tracking, the Uptime Institute's 2026 outage analysis found that third-party IT and data centre providers, including cloud and internet giants, accounted for about two-thirds of publicly reported outages.
What do NIS2 and GDPR expect for SaaS dependencies?
Both expect you to keep running and recover data when a supplier fails. Relying on a provider's uptime promise isn't the same as having a continuity plan.
NIS2 Article 21(2) lists "business continuity, such as backup management and disaster recovery, and crisis management" in point (c), and supply chain security in point (d). A critical SaaS provider is part of that supply chain; see our guide to NIS2 supply chain security. GDPR Article 32(1)(c) requires "the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident".
In practice, auditors look for a supplier list with criticality, a documented continuity plan for each critical service, and evidence that you can restore the data. Learn more on our NIS2 compliance page.
What to do next
SaaS outages will keep happening, and you can't prevent them. What you control is how long your business stands still and whether your data depends on one vendor. A workaround plan handles the outage; an independent backup handles data loss and provider exit.
Start with the list: your five most important SaaS tools, who owns them and what you'd do if each one disappeared for a day. Then see how backup as a service gives your SaaS data a second home in the EU.
Want to see a Microsoft 365 or Google Workspace restore? Book a free 15-minute demo, with a person, in Dutch, German or English.
This article is information, not legal advice.
Frequently asked questions
Can SaaS providers restore my deleted data?
Only within limits. Most SaaS platforms keep deleted items in a recycle bin or retention area for a set period, such as up to 93 days in Microsoft 365 recycle bins. After that, or once an admin or attacker has purged the data, the provider usually can't recover individual items. Under the shared responsibility model, protecting your data remains your job.
How long do SaaS outages usually last?
Anything from minutes to many hours. Microsoft's Azure Front Door incident on 29 October 2025 disrupted Microsoft 365 services for more than eight hours, while Cloudflare's June 2025 outage lasted about two and a half hours. Plan for at least a full working day without your most important platform, and decide in advance which work can continue.
Does a SaaS SLA compensate me for downtime?
Not for your business losses. A SaaS SLA typically promises an uptime percentage, such as 99.9% a month, and pays service credits when the provider misses it. Google Workspace, for example, offers 3 to 15 days of credit. Credits reduce your next bill; they don't cover lost revenue, overtime or data you can't recover.
Do I need to back up SaaS data like Microsoft 365?
Yes, if losing it would hurt your business. SaaS providers keep the platform available, but deletions, sync errors, ransomware and compromised admin accounts all affect your data, and native recovery windows are limited. An independent backup outside the provider, with versioning and immutable storage, lets you restore on your own terms and survive account or provider problems.
What is a SaaS exit strategy?
A SaaS exit strategy is your plan for leaving a provider, by choice or because it fails. It covers where your data goes, how you export it, how long the move takes and what the contract says. Since September 2025, the EU Data Act sets switching rules such as a maximum two-month notice period and at least 30 days to retrieve data.
Sources
- Global Microsoft Azure outage disrupts Microsoft 365Petri IT Knowledgebase, 2025
- Google Cloud incident report: multiple products impacted, 12 June 2025Google Cloud Service Health, 2025
- Cloudflare service outage June 12, 2025Cloudflare, 2025
- Google Workspace Service Level AgreementGoogle, 2026
- Shared responsibility in the cloudMicrosoft Learn, 2026
- Uptime announces Annual Outage Analysis Report 2026Uptime Institute, 2026
- Regulation (EU) 2023/2854 (Data Act)EUR-Lex, Publications Office of the European Union, 2023
- The Data Act and cloud switching: keys to the new rules on changing cloud service providersGarrigues, 2025
- Directive (EU) 2022/2555 (NIS2 Directive)EUR-Lex, Publications Office of the European Union, 2022
- Regulation (EU) 2016/679 (General Data Protection Regulation)EUR-Lex, Publications Office of the European Union, 2016


