Immutable backup: how long should data be kept?
The duration of an immutable backup is that of the risk to be covered, not the maximum period sold by the provider. Against ransomware or an error, 30 to 90 days is generally enough; for a legal obligation, it is the period set by the law, applied only to the documents concerned.
Updated October 20263 min read5 sources cited
Key points
- Anti-ransomware: 30 days minimum, 90 days if monitoring is light or activity is seasonal.
- Legal obligation: the period is the one set by the applicable Mauritian law (tax, companies, employment, health), to be confirmed by your accountant or your adviser.
- A legal period can be extended after a reform: allow a margin rather than a lock cut too fine.
- Separate an operational space (short) from an archive space (long, limited to records you must be able to prove).
- Data that is immutable for ten years must remain decryptable and readable for ten years, key and format included.
Against ransomware and errors: 30 to 90 days
The lock must last longer than the detection time.
- An accidental deletion is generally noticed within a few days. Fourteen to thirty days of immutability cover this case.
- Ransomware preceded by a silent intrusion is often noticed after one to several weeks. Thirty days is a minimum. Ninety days leaves a margin if monitoring is light or if the company closes for several weeks in the holiday season.
- Beyond a few months, locking all the daily backups of all servers is expensive and also freezes personal data you no longer need. You then space out the restore points (one per week) or reserve long immutability for a subset.
Since a compliance lock cannot be shortened, choose the period after measuring the volume. A one-month trial, monitored, is better than a ten-year commitment on an entire server. The complementary measures (separate accounts, offline copy, alerts) are described in How to protect your backups from ransomware.
For the obligation to keep a record: the period set by law
| Document | Retention period | What to lock |
|---|---|---|
| Accounting books and records | Period set by Mauritian law (Income Tax Act 1995, Companies Act): to be confirmed by your accountant | The records, not the daily disk image |
| Tax documents | Period provided for by the Income Tax Act 1995 (section 153): to be confirmed by your accountant | The tax supporting documents |
| Copies of payslips | Period set by Mauritian employment law: to be checked with your adviser | The payslips |
| Standard commercial contract | Limitation period applicable to the contract: to be confirmed by your adviser | The signed contract |
| Patient record in a healthcare facility | Sector rules: to be checked with the competent health authority | The record |
This table deliberately gives no figures: in Mauritius, periods depend on several laws (Income Tax Act 1995, Companies Act, employment law, sector rules) and must be confirmed by your accountant or adviser. Your sector, your client’s country and the contract may also impose something different. A reform can extend a legal period: a lock set today may sometimes need to cover a longer period than originally planned, and a reasonable margin is better than a lock that is too short.
For personal data, the Data Protection Act 2017 (section 27) requires data to be destroyed as soon as its purpose has lapsed. In practice, there are three phases: the active database, intermediate archiving (restricted access, for litigation or a legal obligation), then deletion. Long immutability corresponds to the intermediate archiving of a subset, not to keeping everything. Ten years of immutability on an entire mailbox is often excessive under the Data Protection Act 2017, whereas a long period may be justified for an accounting journal. The data protection officer, or an adviser, decides.
One period, two spaces
Space A, operational: daily backups, immutable for 30 or 90 days, then automatic expiry. Goal: roll back.
Space B, archive: only the documents you must be able to prove, immutable for the legal period, in a format still readable at that date (PDF/A, database export, not an entire operating system). Goal: produce the record.
Mixing A and B under the same ten-year lock multiplies the volume by the number of nights. The distinction between the two uses is explained in What is the difference between backup and archiving?.
The key and the software
Data that is immutable for ten years must remain decryptable for ten years. This requires a procedure for keeping the key, independent of people who may leave the company, and a format that can still be opened. Storage immutability does not update the software needed to read the data.
At WeDoBack
The immutability period is chosen at subscription, within the ten-year limit stated for the IMMUTABLE offer. The public price follows the locked volume: €20 excl. VAT per 100 GB block per month, plus one agent. Example: 500 GB locked costs €100 excl. VAT per month, plus one agent (€6 excl. VAT for a virtual server). At expiry, a new subscription starts a new period. Nothing on the site allows a running lock to be shortened: this is consistent with WORM, and it must be decided before the data is placed in storage. The encryption key stays with the client, who is responsible for keeping it for the entire chosen period.
Frequently asked questions
Can I make my entire mailbox immutable for ten years?
Technically yes, but it is rarely justified. The Data Protection Act 2017 (section 27) requires personal data to be destroyed as soon as its purpose has lapsed; in practice, a distinction is made between the active database, intermediate archiving and deletion. Lock for a long time what a law requires you to keep for a long time, not all your correspondence.
What happens at the end of the immutability period?
The lock is released. The data can then be deleted by the normal retention cycle, or locked again for a new period. Nothing is deleted automatically if no deletion rule has been set.
Does the legal period run from the backup date?
No, it generally runs from the event set by the law: the end of the financial year, the end of the contract or the last transaction, for example. A record backed up late must therefore be locked until the correct expiry date, not for the legal period counted from the backup.
Sources
Documents consulted in October 2026.
- Income Tax Act 1995 (consolidated version) — Mauritius Revenue Authority
- Data Protection Act 2017 (section 27) — Data Protection Office (Mauritius)
- Introductory Guide to the Data Protection Act 2017 — Data Protection Office (Mauritius)
- Guideline on devising a personal backup plan (CMSGu2017-03) — CERT-MU
- IMMUTABLE offer: WORM storage and prices — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
