Your Cloud Backup Isn't What You Think It Is

Whether you run Microsoft 365 or Google Workspace, the platform keeps deleted data around for a while — but “a while” is a lot shorter than most compliance frameworks require, and neither one is designed to be a real backup.
Default retention before permanent deletion, by workload
Workload | Default retention before permanent deletion |
Exchange Online | 14–30 days |
OneDrive / SharePoint | 93 days |
Entra ID objects | 30 days |
Gmail | 30 days + 25-day admin window (~55 total) |
Google Drive | 30 days + 25-day admin window (~55 total) |
Most compliance obligations run into years, not days.
We get some version of the same question from almost every client, regardless of which productivity suite they run: “We're on Microsoft 365 (or Google Workspace) — doesn't that already back everything up?” It's an easy assumption, and neither vendor goes out of its way to correct it in the marketing. The short answer is no. What both platforms ship by default is retention, not backup, and the two behave very differently once a regulator, an auditor, or a ransomware note is involved.
What Microsoft 365 actually keeps, and for how long
Every Microsoft 365 workload has its own recycle bin and its own clock. None of them were built with compliance retention schedules in mind — they exist so a user can undo an accidental delete, not so an auditor can pull a record from three years ago.
Exchange Online (email)
When a message is deleted, it moves to the Deleted Items folder, and from there to a Recoverable Items folder once that's emptied. The default window on Recoverable Items is 14 days, and an admin can extend it to a maximum of 30 days. After that, the message is gone — no admin console, no support ticket, brings it back.
OneDrive and SharePoint (files)
Deleted files pass through a first-stage recycle bin and then a second-stage, site-collection recycle bin, for a combined 93 days. That window is fixed and isn't configurable downward or upward through the recycle bin itself — it can only be extended by layering a separate retention policy on top. Once a site collection is deleted outright, Microsoft holds it for that same 93 days before it's unrecoverable through normal means.
Microsoft Teams
Teams doesn't have its own storage layer — chat files live in OneDrive and SharePoint, so the same 93-day clock applies to anything shared in a channel or a chat.
Microsoft Entra ID (user and group objects)
A deleted user or group sits in a soft-deleted state for 30 days, during which it can be restored. After that, it's a hard delete, and along with it goes the mailbox, OneDrive, and Teams membership tied to that identity.
A recycle bin is not a backup. Recovery through the built-in tools is short-term, self-service, and tied to the same tenant that got compromised. It has no immutability, no independent point-in-time restore, and no protection if the deletion — accidental or malicious — happens inside the retention window itself. Ransomware that syncs and encrypts files before anyone notices will happily encrypt the recycle bin's contents too.
What Google Workspace actually keeps, and for how long
Google's defaults follow a similar shape to Microsoft's, though the specific windows and the admin recovery mechanics differ. Google standardized most of its consumer-facing retention windows to 30 days a few years ago, specifically to make behavior predictable across Gmail, Drive, and the rest of the suite — but “predictable” and “compliant” aren't the same thing.
Gmail
A deleted email moves to Trash, where Gmail automatically purges it after 30 days. Emails in Spam follow the same 30-day clock. Once a message is gone from a user's Trash, a Workspace admin can still restore it from the Admin console for an additional 25 days — after that, it's permanently gone unless the organization has Google Vault in place.
Google Drive and Shared Drives
Files moved to Trash are automatically deleted after 30 days. As with Gmail, an admin has a further 25-day window to restore a user's trashed files from the Admin console before they're purged for good. This applies equally to personal Drive and Shared Drive content.
Google Calendar and Contacts
These are handled separately and are notably not covered by Google Vault, Google's retention and eDiscovery add-on. If a calendar event or a contact is deleted, there's no compliance-grade retention layer sitting behind it at all — only the standard trash behavior of the app itself.
Google Vault
Vault is Google's answer to Microsoft Purview — a licensed add-on that lets admins set custom retention rules (from 1 day up to roughly 100 years) for Gmail, Drive, Chat, and Meet recordings, plus apply legal holds that override the standard deletion clock. It's a meaningful upgrade over the defaults, but it's opt-in, it costs extra per user, and — like Purview — it's retention tooling inside the same tenant, not an independent backup copy stored somewhere a compromised admin account can't reach.
The pattern repeats across both platforms: a short, self-service trash window (roughly 14–30 days), a slightly longer admin-recovery window layered on top (25–93 days depending on the service), and then permanent, unrecoverable deletion — unless you've paid for and configured a separate retention product. Neither vendor's default state was designed around a compliance calendar.
Why measuring in weeks isn't good enough for most businesses
Retention windows measured in weeks collide with compliance obligations measured in years. If your business handles health records, cardholder data, financial statements, or personal data covered by state or federal privacy law, the platform defaults — Microsoft's or Google's — will not satisfy what you're required to keep, and just as often won't satisfy what you're required to be able to delete on demand and prove you deleted.
Framework | Who it applies to | What it typically requires |
HIPAA | Healthcare providers, health plans, and their business associates | Retain relevant records and documentation for 6 years from creation or last effective date. Some states extend this further for the medical records themselves. |
PCI DSS | Anyone storing, processing, or transmitting cardholder data | Keep audit trail history for at least 12 months, with at least 3 months immediately available for analysis. Cardholder data itself should be retained only as long as business or legal need requires. |
SEC Rule 17a-4 / FINRA 4511 | Broker-dealers and other regulated financial firms | Retain electronic communications and books and records for a minimum of 3–6 years, the first 2 years in an easily accessible place, often in WORM (write-once, read-many) format. |
Sarbanes-Oxley (SOX) | Public companies and their auditors | Retain audit and financial review records for 7 years, with controls to prevent alteration or premature deletion. |
GLBA / FTC Safeguards Rule | Banks, lenders, and other financial institutions holding consumer financial data | No single fixed number, but requires a documented information security program covering retention, secure disposal, and incident response for customer financial records. |
FERPA | Schools and institutions holding student education records | No universal fixed period, but requires records be kept as long as needed for their educational purpose, with strict controls over access and disclosure. |
GDPR | Any organization handling EU residents' personal data | No fixed number — the “storage limitation” principle requires data be kept only as long as necessary for its stated purpose, with a documented retention schedule and the ability to fully erase data on request. |
State privacy laws (CCPA/CPRA and similar) | Businesses handling residents' personal data in states with privacy statutes | Requirements vary by state, but generally call for a defined retention schedule and a reliable way to honor deletion requests — something a 30- or 93-day auto-purge actively works against. |
Notice the pattern: most of these frameworks ask for retention measured in years, and several ask for immutability — proof that a record wasn't altered or deleted early. Neither platform's native tools do that out of the box. Both are tuned for the opposite problem: getting rid of data efficiently once it's no longer wanted, not proving it existed unchanged for a decade.
Microsoft 365 vs Google Workspace: where the native tools stop
Microsoft 365 — native ceiling
Recycle bins are self-service, tenant-bound, and capped at 93 days without add-ons
Microsoft Purview adds custom retention labels and legal holds, licensed separately (typically E5 or add-on SKUs)
Microsoft 365 Backup is a newer, separately licensed product built for longer, immutable protection and faster large-scale restores
Restores from Microsoft's own infrastructure after a bin expires are limited to whole site collections, not individual files, and aren't guaranteed
Google Workspace — native ceiling
Trash windows are a flat 30 days across Gmail and Drive, plus a 25-day admin recovery buffer
Google Vault adds custom retention (1–36,500 days) and legal holds for Gmail, Drive, Chat, and Meet — licensed per user
Vault does not cover Calendar or Contacts at all, which is easy to miss when planning a retention schedule
Neither Vault nor the default trash gives you an independently stored, immutable copy outside the Workspace tenant
Closing the gap
None of this means either platform is insecure — it means neither one was sold to you as a compliance archive, and neither should be treated like one. A few things close most of the gap, regardless of which suite you're on:
Add independent, immutable backup. A third-party backup solution — or the vendor's own add-on, like Microsoft 365 Backup or a configured Google Vault policy — stores point-in-time copies outside the tenant's own retention clock, so a compromised admin account or a ransomware event can't reach them.
Write a real retention schedule. Map each data type your business handles — email, contracts, PHI, cardholder data — to the specific regulation that governs it, and configure Purview or Vault (or your backup tool) to match, not the platform default.
Test restores, not just backups. A backup that's never been restored is a hypothesis. Schedule periodic restore tests so recovery time is a known number, not a guess made during an incident.
Separate legal hold from storage duration. Litigation holds and eDiscovery needs can require freezing data indefinitely — make sure your retention tooling can hold specific items past their normal expiry without resetting the clock on everything else.
Don't forget the gaps in coverage. Google Calendar and Contacts, and certain Microsoft workloads outside the core mail/file/chat set, may not be covered by either vendor's retention add-on at all. Confirm what's actually protected before assuming it is.
If you're not sure what your current retention posture actually covers, that's usually the first thing worth finding out — most businesses discover the gap during an audit or a breach, which is the most expensive possible time to learn it.
Frequently asked questions
Does Microsoft 365 or Google Workspace back up my data automatically?
Both platforms retain deleted data for a limited window as a safety net against accidental deletion, but neither runs a full, independent backup by default. Long-term, immutable protection requires a paid add-on (Microsoft 365 Backup, Google Vault) or a third-party backup product.
How long does Microsoft keep deleted emails?
Exchange Online keeps deleted items in the Recoverable Items folder for 14 days by default, extendable to a maximum of 30 days by an admin. After that, the message can't be recovered through standard tools.
How long does Google keep deleted emails and files?
Gmail and Google Drive both purge Trash after 30 days, with an additional 25-day window in which a Workspace admin can restore items from the Admin console — about 55 days total before permanent deletion.
Is a 90-day retention window enough for compliance?
For most regulated industries, no. Frameworks like HIPAA, SOX, and SEC/FINRA rules typically require retention measured in years, not months, and several require immutability that a standard recycle bin doesn't provide.
Talk to GingerSec
GingerSec works with businesses on Microsoft 365 and Google Workspace to close the space between what the platform keeps by default and what compliance actually requires — backup strategy, retention policy design, and audit-ready documentation. Reach out to have your current environment reviewed.
This article is general information, not legal or regulatory advice; confirm specific requirements with your compliance counsel.




Comments