Home›Guides›DRP and BCP

DRP and BCP

Outsourced DRP: pros and cons

An outsourced DRP entrusts a provider with the place where servers restart and, often, with keeping the copies. It saves an SME from buying a second server room. It does not save it from knowing who triggers the plan, where the key is, and whether the last test succeeded.

Updated October 20264 min read5 sources cited

Key points

  • Pros: no second building, cost mainly tied to usage, copies already off site, tests without in-house hardware.
  • Cons: the RPO remains that of the backup, the RTO depends on people and hours of service, and the key is your responsibility.
  • The ANSSI, France’s national cybersecurity agency, recommends encrypting before sending data to the provider and checking that the restore time is compatible with your maximum tolerable downtime.
  • The contract must list the hosting locations, provide for reversibility and, if personal data is processed, include the written contract required by section 31 of the Data Protection Act 2017 (Mauritius).
  • An automatic start-up test is not a business test.

Pros

  • No second building. The instances exist at the provider. On the day of the disaster, nobody rushes out to buy a server.
  • Cost mainly tied to usage. In a model where activation is billed per day, months without incident cost only the preparation (storage, agents, addresses), not a fleet kept running.
  • Copies already off site. The DRP and the outsourced backup feed each other. No tapes to transport.
  • Technical tests possible without in-house hardware. Starting an image at the provider does not require a test server in the cupboard.
  • Chosen geographic area. Useful when the law or a contract requires a specific country, provided the contract actually says so. The ANSSI recommends requiring the provider to list all data storage locations, including the main site and standby sites.

Cons

  • The RPO is not magic. It remains equal to the age of the chosen backup. The provider cannot reconstruct entries that were never copied.
  • The RTO depends on people. If the only authorised person cannot be reached, the instance does not start. Outsourcing does not create an on-call service you have not paid for. With a provider open from 9:00 to 17:30 on weekdays, a disaster on a Saturday evening has to wait, unless the contract says otherwise. The ANSSI calls for vigilance on this point: the restore time at the provider must be compatible with your maximum tolerable period of disruption.
  • The key. If only you can decrypt, only you can restore. The ANSSI specifically recommends encrypting backups with the organisation’s own means before sending them to the provider. This protects against unauthorised reading. It is also a responsibility: lose the key and the DRP is unusable. An honest provider will not offer to keep the key “to help you out” without explaining that it will then be able to read the data.
  • The network. Users must be able to reach the standby. An outsourced DRP with no planned IP addresses and no tested VPN restores unreachable servers.
  • Failback. Returning to the repaired site, with the data entered in the meantime, is a project in itself. Contracts say a lot about failover, and little about failback.
  • A start-up test is not a business test. An automatic monthly check that verifies start-up is a real plus. It does not prove that the business software works.
  • Dependency. Changing provider means re-reading the copies. The contract must state how quickly and in what form you leave with your data: this is what the ANSSI calls reversibility, the ability to take back the outsourced function or hand it to a third party, with the provider’s assistance during the migration.

What the contract must contain

The ANSSI guide on outsourcing recommends attaching a security assurance plan (PAS) to the contract and providing for audits of backup and recovery procedures. When the copies contain personal data, which is almost always the case, the provider is a “processor” within the meaning of the Data Protection Act 2017 (Mauritius). Section 31 then requires a written contract: the provider acts only on the customer’s instructions and remains bound by the same security obligations. The Data Protection Office publishes an introductory guide to the Act.

ItemWhyWhere to check it
Hosting locations, main and standbyLegal or contractual location requirements (transfers outside Mauritius: section 36)Contract, PAS
Support and activation hoursThey are part of the real RTOTerms of service
Included tests and tests on quotationMeasure the RTO before a disasterCommercial offer
Who holds the encryption keyConfidentiality and ability to restoreContract, internal procedure
ReversibilityLeave with your data if you change providerDedicated clause
What happens to the data at the end of the contractReturn or destruction of all copies (no retention beyond the purpose, section 27)Data processing agreement
Sub-processorsKnow who else has access to the copies: prior written authorisationData processing agreement
Breach alertThe customer must notify within 72 hours where feasible (section 25): the provider informs it without delayData processing agreement

Section 31 of the Data Protection Act 2017 also requires the means to restore the availability of and access to personal data in a timely manner, as well as a process for regularly testing the effectiveness of the measures. An outsourced DRP contributes to this, provided it is actually tested.

When it is the right choice

An SME without a second server room, one to a few servers whose downtime is counted in hours rather than minutes, and a wish not to invest in idle hardware. When downtime is counted in minutes, look instead at a BCP, aware of its ongoing cost: see Outsourced BCP: pros and cons.

At WeDoBack

The outsourced DRP corresponds to the published DRP offer: storage from €175 excl. VAT per TB per month, agents, public IP addresses at €0.54 excl. VAT per month, instances, activation during a disaster billed per day, a monthly start-up test that does not touch production, and a live test of up to 10 hours on quotation. Data is encrypted on the machine before it is sent, with a key held by the customer, and stored on servers dedicated to backup, made redundant across several European countries (storage outside Mauritius is a transfer governed by section 36 of the Data Protection Act 2017) or in the area required by the customer’s legislation. The data centres and solutions used are ISO 27001 and HDS (French health data hosting) certified, and WeDoBack processes the copies on the customer’s instructions, as a “processor”. Human support can be reached from 9:00 to 13:00 and 14:00 to 17:30 (Paris time, i.e. 11:00 to 15:00 and 16:00 to 19:30 in Mauritius during European summer time, one hour later in winter). These hours are part of the real RTO. They should be read before signing, not after the disaster.

Frequently asked questions

Which clauses should be checked in an outsourced DRP contract?

Hosting locations (main and standby), support and activation hours, how the plan is triggered, included tests, reversibility (in what form and how quickly you get your data back) and, for personal data, the written contract required by section 31 of the Data Protection Act 2017 (the provider acts only on your instructions and applies the same security measures), supplemented by sub-processors and what happens to the data at the end of the contract.

Can the provider keep the encryption key for added security?

It can, but it will then be able to read your data. If you alone hold the key, nobody else can decrypt the copies, but you must keep it in a safe place, off site, with at least two people able to retrieve it. The ANSSI, France’s national cybersecurity agency, recommends encryption with the organisation’s own means before sending.

Is an outsourced DRP enough to comply with the Data Protection Act 2017?

It contributes to section 31, which requires the means to restore the availability of personal data in a timely manner after an incident and a process for regularly testing the measures. It is not enough on its own: you also need a written contract with the provider (section 31), a breach notification procedure (section 25) and documented tests.

Sources

Documents consulted in October 2026.

  1. Outsourcing and information system security: a guide to managing the risks (2010) — ANSSI, France’s national cybersecurity agency
  2. Information system backup: the fundamentals (ANSSI-BP-100, v1.1, 27 November 2025) — ANSSI, France’s national cybersecurity agency
  3. Data Protection Act 2017 (sections 25, 27, 31 and 36) — Data Protection Office (Mauritius)
  4. Introductory Guide to the Data Protection Act 2017 — Data Protection Office (Mauritius)
  5. DRP offer: recovery after a disaster — WeDoBack

Planning a backup, DRP or BCP project?

More than 20 years of experience protecting business data.

Request a quote+33 9 72 50 78 28

Protect your data with WeDoBack

Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.