Backup Compliance Standards for HIPAA, GDPR, DORA, NIS2, APPI

Regulators in the US, UK, EU, and Japan increasingly treat backup as a legal obligation, not just good IT hygiene. HIPAA's Contingency Plan standard requires a documented Data Backup Plan. UK GDPR Article 32 requires the ability to restore data "in a timely manner" after an incident. The EU's DORA regulation spells out backup isolation and recovery testing in explicit technical detail. None of these laws were written with a specific software product in mind — but they all describe the same underlying capability: reliable, scheduled, encrypted, logged, and recoverable backups.

This is exactly what automatic backup software is built to provide. Below is a region-by-region breakdown of the major standards that touch on data backup, what Handy Backup's core features help you satisfy, and — just as important — what you still need to handle outside the software, since no backup tool by itself makes an organization "compliant."

A note before we start: none of the standards below have an official certification that a piece of software itself can hold (with the partial exception of UK Cyber Essentials, which certifies organizations, not products). Compliance comes from an organization's overall policies, procedures, and technical controls — backup software is one component, not a substitute. Handy Backup is not a certified compliance product, and this article is not legal advice.

United States

HIPAA (Health Insurance Portability and Accountability Act)

Healthcare providers, insurers, and anyone handling Protected Health Information (PHI) often start their search for HIPAA compliant backup software here: HIPAA's Security Rule requires covered entities and their business associates to protect the confidentiality, integrity, and availability of PHI, and the Contingency Plan standard (45 CFR § 164.308(a)(7)) specifically requires a documented Data Backup Plan and Disaster Recovery Plan as part of that program.

How Handy Backup helps:

  • Scheduled, unattended backups satisfy the "data backup plan" requirement without relying on staff to remember manual backups.
  • AES encryption of backup archives supports the confidentiality requirement for PHI at rest.
  • Detailed logs and email notifications give you the audit trail HIPAA reviewers expect to see.
  • Choice of storage destination lets you keep PHI backups on infrastructure you control (local drive, NAS, or a specific cloud region) rather than an unknown third-party location.

What you still need beyond the software:

  • A signed Business Associate Agreement (BAA) with any cloud storage provider you back up to, if that provider will handle PHI (Handy Backup itself is desktop software that doesn't host your data, so the BAA relationship is with your storage destination, not with Handy Backup).
  • A written risk assessment and HIPAA security policy covering more than backup — access controls, workforce training, device encryption, breach notification procedures.
  • A tested restore procedure, not just a backup schedule — HIPAA auditors ask for evidence that recovery actually works.
  • Appointment of a HIPAA Security Officer responsible for the overall program.

GLBA / FTC Safeguards Rule

The Gramm-Leach-Bliley Act applies to a broad definition of "financial institutions" — banks, but also mortgage brokers, non-bank lenders, tax preparers, and retailers offering financing. The FTC's updated Safeguards Rule (16 CFR Part 314, in force since June 2023) requires a written information security program covering encryption, access controls, data retention/disposal schedules, and incident response.

How Handy Backup helps:

  • Encrypted backups address the Safeguards Rule's explicit requirement to encrypt customer information at rest and in transit.
  • Scheduled backups with versioning support the retention controls the rule expects.
  • Logging supports the documentation financial regulators request during examinations.

What you still need beyond the software:

  • A written risk assessment identifying internal and external risks to customer information (a Safeguards Rule requirement, not something backup software produces).
  • Annual penetration testing and semi-annual vulnerability scanning.
  • A documented data disposal policy — the rule requires secure disposal of customer information no later than two years after it's last needed.
  • A designated Qualified Individual overseeing the information security program.

CCPA / CPRA (California)

California's privacy law doesn't mandate specific backup technology. Still, it requires "reasonable security procedures" to protect personal information and gives consumers rights to access, delete, or correct their data — which has direct implications for how backups are structured and retained.

How Handy Backup helps:

  • Configurable retention and versioning make it easier to align backup copies with a defined data retention policy rather than keeping data indefinitely.
  • Exclusion filters let you scope backups away from data you don't need to retain.

What you still need beyond the software:

  • A data inventory identifying where California residents' personal information lives, including in backups.
  • A documented process for honoring deletion requests across live systems and backup archives — one of the harder practical problems in CCPA compliance.
  • Updated privacy notices disclosing your data and backup retention practices.

United Kingdom

UK GDPR and the Data Protection Act 2018

Since Brexit, the UK operates its own version of GDPR (the "UK GDPR"), read alongside the Data Protection Act 2018. Article 32 requires "the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident" — in plain terms, a working, tested backup and recovery capability. The UK's Information Commissioner's Office (ICO) can and does examine backup practices after a reported breach, and can issue fines of up to £17.5 million or 4% of global turnover for serious failures.

How Handy Backup helps:

  • Scheduled backups directly address Article 32(1)(b)'s requirement for "resilience of processing systems".
  • Encryption in transit and at rest supports the "appropriate technical measures" language throughout Article 32.
  • Choice of storage location helps address data residency considerations under UK GDPR's international transfer rules.
  • Detailed logs support demonstrating "accountability" — a core UK GDPR principle — if the ICO ever asks how a data loss incident was handled.

What you still need beyond the software:

  • Regular, documented restore testing — the ICO's own guidance and independent research both point to the same problem: a large share of UK businesses have never tested whether their backups actually restore.
  • A lawful basis and documented purpose for processing the personal data you're backing up.
  • A process to honor Article 17 "right to erasure" requests across both live systems and backup copies, not just the live database.
  • A 72-hour breach notification procedure to the ICO, which a backup tool doesn't create for you.

Cyber Essentials / Cyber Essentials Plus

Cyber Essentials is the UK government's NCSC-backed cybersecurity certification scheme. It isn't generally a legal requirement, but it is a prerequisite for many UK government contracts and is increasingly requested by cyber insurers and enterprise customers. The scheme's technical controls don't mandate backups outright, but recent versions (v3.3) explicitly recommend them as best practice, including keeping copies off the primary device.

How Handy Backup helps:

  • Automated backups to a separate destination (external drive, NAS, or offsite storage) satisfy the "copies off the primary device" recommendation.
  • Scheduling removes the human-error risk assessors look for when reviewing backup practices.

What you still need beyond the software:

  • The five other Cyber Essentials technical controls (firewalls, secure configuration, user access control, malware protection, patch management) — backup software addresses none of these directly.
  • A Cyber Essentials self-assessment questionnaire (or independent audit for Cyber Essentials Plus) submitted through a certified assessor.

European Union

GDPR

The EU's GDPR is the direct predecessor and near-twin of the UK GDPR, and the backup-relevant provisions are essentially the same: Article 32 (security of processing, including the ability to restore availability after an incident), Article 25 (data protection by design), and Article 17 (right to erasure). The main practical difference from the UK version is around international transfer mechanisms and which supervisory authority applies.

How Handy Backup helps: the same features that help with UK GDPR — encryption, scheduled and versioned backups, storage location choice, and logging — apply directly here.

What you still need beyond the software: the same organizational work as UK GDPR above — lawful basis documentation, tested recovery procedures, an erasure process that covers backups, and a breach response plan (72-hour notification to your national Data Protection Authority).

NIS2 Directive

NIS2 has applied across EU member states since October 2024 and significantly widened the range of "essential" and "important" entities it covers — not just critical infrastructure, but many mid-sized companies in sectors like healthcare, digital infrastructure, manufacturing, and public administration. It requires documented risk management measures, business continuity planning, and incident reporting within 24 hours of detection. Backup and recovery capability sits squarely inside its business continuity requirements.

How Handy Backup helps:

  • Scheduled, automated backups reduce the operational gap NIS2 targets — recovery depending on staff remembering to run backups manually.
  • Support for offsite and cloud destinations helps meet the "backup detached from the primary system" expectation regulators and auditors look for.
  • Logging and notifications support the documentation NIS2 expects organizations to maintain to demonstrate their risk management measures.

What you still need beyond the software:

  • A formal risk assessment covering your ICT supply chain, not just your own systems.
  • An incident response plan capable of meeting the 24-hour initial notification deadline.
  • Regular resilience testing — NIS2 guidance consistently emphasizes proving recovery works, not just claiming a backup exists.
  • Immutable/air-gapped storage for your most critical systems, since NIS2-focused guidance increasingly flags ransomware resilience specifically.

DORA (Digital Operational Resilience Act)

DORA applies specifically to EU financial entities (banks, insurers, investment firms, payment providers) and their ICT providers, and has been enforceable since January 2025. It is the most technically prescriptive of the EU regulations discussed here: Article 11 requires financial entities to define and test backup policies with backup systems isolated from production systems, plus defined Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) for critical systems. Article 12 requires backup data to be protected against unauthorized modification or deletion, including by compromised administrator accounts.

How Handy Backup helps:

  • Support for storage destinations separate from the source system (external drives, NAS, FTP/SFTP, cloud) supports the Article 11 isolation requirement.
  • Encryption supports the Article 12 protection-against-modification requirement, especially when combined with storage that offers immutability (e.g., S3 with Object Lock).
  • Scheduled backups with defined frequency give you the basis for setting and meeting an RPO.

What you still need beyond the software:

  • Formally defined RTOs and RPOs per system — a backup schedule alone doesn't constitute this; it needs to be a documented decision tied to business impact analysis.
  • Regular, documented recovery testing — DORA is explicit that entities must prove recoverability, not just assert it.
  • Immutable storage at the destination level (Object Lock or equivalent) for full Article 12 compliance, since immutability is a property of the storage target, not something backup software alone can guarantee on ordinary local or network storage.
  • Third-party ICT risk management documentation if you use any external backup destination, since DORA extends obligations to your ICT providers.

Japan

APPI (Act on the Protection of Personal Information)

APPI is Japan's core data protection law, most recently strengthened by 2022 amendments. It applies to any business handling personal information of individuals in Japan, regardless of where the business is located. The Personal Information Protection Commission (PPC) requires "necessary and appropriate" security control measures to prevent leakage, loss, or damage of personal data, and its guidelines break this down into seven categories, including organizational, physical, and technical controls. It also imposes strict conditions on transferring personal data outside Japan, requiring disclosure and often consent.

How Handy Backup helps:

  • Encrypted backups directly support the "technical security control measures" category in the PPC's guidance.
  • Local or in-region storage destinations help address APPI's cross-border transfer restrictions by keeping backups within Japan when required.
  • Logging supports the accountability and transparency principles that run through APPI.

What you still need beyond the software:

  • A documented basic policy for handling personal data and internal rules governing it — APPI explicitly expects both organizational and physical security measures, not just technical ones.
  • A cross-border transfer assessment if any backup destination is located outside Japan, including obtaining consent or confirming an approved transfer mechanism.
  • A breach notification process to the PPC and affected individuals, which the 2022 amendments made mandatory in a wider range of cases than before.

The Big Picture

Across every one of these frameworks, the pattern is the same: regulators describe an outcome — data that's encrypted, recoverable, tested, and logged — without prescribing a specific product. Automatic backup software like Handy Backup is built to deliver that outcome reliably, which is why its core features (scheduling, AES encryption, flexible storage destinations, detailed logging, and version retention) map onto compliance requirements across all four regions almost feature-for-feature.

What backup software cannot do is the organizational half of compliance: risk assessments, written policies, staff training, tested (not just scheduled) recovery, breach response procedures, and — where required — formal agreements with your storage or cloud providers. Treat backup software as the technical foundation your compliance program runs on, not the compliance program itself.

Who uses Handy Backup?