Your Dead Hard Drive Is Still Your Legal Problem: GDPR Rules for Outsourced Data Recovery
Published on 09/14/2026 at 17:31 | Editorial boerse-global.de
Handing a failed server or a corrupted laptop to a specialist recovery firm feels like passing the problem down the line. Under European data protection law, it isn't. The obligations that come with personal data follow that data out of the building — and they start biting well before the courier arrives.
Guidance circulated in mid-September 2026 has restated what companies often overlook: commissioning an outside provider to rescue data does not transfer responsibility under the General Data Protection Regulation (GDPR). The controller stays the controller.
Paperwork first, hardware second
Before any defective drive leaves the premises, a processing agreement has to be in place. Article 28 of the GDPR governs this relationship, and specialists stress that the legal tie must exist ahead of the physical handover — not alongside it.
That contract carries specific demands. The recovery provider must act only on the controller's instructions, and the parties have to pin down the technical and organisational measures (TOMs) that keep the data secure. Two further points belong in the same document: whether the provider may bring in subcontractors at all, and where the processing actually happens — a question that becomes acute if any work is planned outside the European Union.
The copies nobody thinks about
Recovery work rarely touches the original disk directly. Engineers typically produce working copies, often sector-by-sector images of the damaged media, and those images are created on the provider's own systems, beyond the client's direct oversight.
Legal and IT specialists argue this is precisely where rules are needed. How long may the image be kept? Who inside the recovery company is allowed to open it? Answering both questions is what makes the journey of sensitive information traceable from start to finish.
When the job ends — or fails
Completion does not close the file. Under Article 28(3) GDPR, the data must then be deleted or returned in full to the client. Keeping a copy at the provider's site without an explicit legal basis is not permitted. The same applies if the recovery attempt collapses: a failed rescue is not a licence to retain anything.
Breaches trigger their own clock. Should data be exposed during the process — an unauthorised access, a lost drive — the supervisory authority must be notified under Article 33 GDPR, ideally within 72 hours of the controller becoming aware of the personal data breach.
Extra rules for those bound by professional secrecy
Certain professions face requirements that reach past the GDPR altogether. Lawyers, medical practitioners and others who qualify as holders of professional secrecy must weigh criminal law as well when they hand sensitive material to an outside recovery service.
Paragraph 203 of the German Criminal Code (StGB), which protects private secrets, is the provision at stake. Passing data to a recovery provider must not undermine that protection, which puts a premium on choosing the provider carefully and locking the arrangement down contractually. For companies in these fields, the recovery process has to be built so that no protected secret is disclosed without authorisation.
