Hosting ·

Why your website needs a retention policy

Most providers will tell you they take backups. Far fewer will tell you how long they keep them, or whether they have ever restored one. What to ask, and what a good answer sounds like.

A grass-topped sand bank with dark and pale layers, above a black sand beach with surf and a bush-covered headland beyond.

“Yes, we back it up” is the answer almost everyone gives. It is also nearly useless on its own, because it leaves out the two things that decide whether a backup can save you: how far back it goes, and whether anyone has ever restored from it.

Why how long matters more than how often

Picture a plugin that is quietly compromised in early March. Nothing visible happens. In mid-April someone notices odd redirects and asks for the site to be rolled back.

If your provider keeps 30 days of backups, every copy they hold was taken after the problem started. Restoring one brings the problem straight back. You were backed up every single day, and you still have nothing clean to go back to.

That is what a retention period is for. It is the length of the window you can reach back into, and problems are often found long after they begin. A daily backup kept for a week protects you from a bad afternoon. It does not protect you from anything that took a month to notice.

What the government guidance says

New Zealand’s National Cyber Security Centre publishes backup advice for businesses through Own Your Online. It suggests matching how often you back up to how quickly your data changes, several times a day if new customer information arrives daily. It recommends three copies: one offline, one in a different physical location, and one on different media. And it says to check your backups regularly by actually restoring from them. (Own Your Online, Backups for your business)

Its ransomware guidance makes the offline point sharper. Backups should be “kept offline or disconnected from your computers so that an attacker can’t delete them”. (Own Your Online, Protect your business against ransomware) A backup stored in the same account as the website is not much use if someone gets into that account.

Retention cuts both ways

Longer is not automatically better. If your website collects enquiries, bookings or sign-ups, your backups contain personal information, and the Privacy Act 2020 has something to say about that. Information Privacy Principle 9 says an agency “must not keep that information for longer than is required for the purposes for which the information may lawfully be used”. (Office of the Privacy Commissioner, Principle 9)

So the right retention period is a decision, not a default. It has to reach back far enough to recover from something discovered late, and it should not quietly keep every form submission forever. Writing it down forces someone to make that decision on purpose.

What to ask your provider

How often are backups taken? Daily is a reasonable floor for most small sites.

How long are they kept? You want a number, in writing. “A while” is not a retention period.

Where are they stored? Somewhere separate from the website and the account it runs in, so one compromise cannot take out both.

When was a backup last restored to check it worked? A backup nobody has tested is a hope rather than a plan.

Do the backups include form submissions and other personal information, and how long is that kept?

If you leave, can you have a copy?

A provider who looks after this properly will answer every one of those without having to go and find out. If the answers are vague, that is the most useful thing you learned.

More like this

Surf running up a black sand beach over a line of footprints, with a bush-covered headland under grey cloud.

Search

AI search is sending fewer people to your website

When Google answers a question itself, fewer people click through to a website. What the research shows, what Google says you need to do, and where your effort is better spent.

A rusted bolt set into a weathered timber post, with grey surf and a black sand beach out of focus behind.

Security

The real cost of not updating

Most website break-ins do not need a clever attacker. They need a plugin nobody updated. What the 2025 vulnerability figures say about how quickly that window closes.