Skip to main content
Category: Data Lifecycle and Disposal

Archival Storage

Also known as: Data Archive, Cloud Archive Storage, Archive Storage Tier
Simply put

Archival storage is a place to keep data that an organization does not need for its everyday work but may still have to access occasionally or retain over the long term. Because this data is accessed rarely, it is typically held on lower-cost storage that trades faster retrieval for reduced expense. Archived data remains important and preserved even though it is not frequently used or modified.

Formal definition

Archival storage refers to a storage type or service tier used for long-term retention of data that is not required for an organization's routine operations but may need to be accessed occasionally. Historically it has been associated with removable media such as tape cartridges and optical disks; in cloud environments it is offered as a dedicated tier characterized by ultra-low cost and minimal or delayed retrieval performance. Storage choices, including media type and methodology, are central to preserving archival holdings over time. This definition addresses the storage function and cost/retrieval trade-offs only; it does not cover legal retention-period requirements, records disposition schedules, data protection obligations attaching to any personal data held in an archive, or cross-border transfer considerations, which are governed separately and must be assessed against the applicable jurisdiction and regime.

Why it matters

Archival storage lets organizations preserve data that is no longer part of daily operations while controlling cost, since rarely accessed data can be held on lower-cost media or storage tiers that trade retrieval speed for reduced expense. As guidance from the U.S. National Archives frames it, storage is the first and best means of defense in preserving holdings over time, and the choices made in storage type and methodology have a direct bearing on whether archived data remains accessible and intact for as long as it is needed.

For data protection and governance professionals, the key point is that moving data to an archive does not change its regulatory character. Where an archive contains personal data, the data protection obligations attaching to that data generally continue to apply, and placing it in a low-cost, delayed-retrieval tier does not on its own make it non-personal or exempt from those obligations. Archival storage is a storage function and cost/retrieval decision; it is distinct from, and does not substitute for, records disposition schedules, retention-period rules, or lawful basis and cross-border transfer analysis, which are governed separately.

Because of this separation, archival decisions should be made alongside governance and security controls rather than in place of them. The cost advantages of an archive tier can create an incentive to retain data indefinitely, which can conflict with retention and minimization principles that are addressed under the applicable regime. Treating archival storage purely as an infrastructure choice, without mapping it to the governance policies that determine what may be kept and for how long, is a common gap that professionals should close with demonstrable evidence of the applied schedule.

Who it's relevant to

Information Governance and Records Leads
Governance and records professionals decide what data is moved to an archive and pair that storage decision with retention and disposition schedules. They should note that the archival storage tier itself does not enforce retention rules or disposition, and that demonstrable evidence of an applied schedule is generally needed rather than a stated intent to keep or delete data.
Data Protection Officers and Privacy Professionals
Where an archive holds personal data, the applicable data protection obligations generally continue to apply. Archiving does not remove data from scope, and low-cost or delayed-retrieval characteristics do not make archived personal data non-personal. Lawful basis, retention limits, and any cross-border transfer considerations must be assessed separately against the relevant regime.
Storage, Infrastructure, and Security Teams
These teams implement the media or cloud tier and manage the cost and retrieval trade-offs, including delayed retrieval performance in ultra-low-cost tiers. Their remit centers on confidentiality, integrity, and availability of the stored holdings, which supports but does not replace the governance policies that determine what may be retained and for how long.
Compliance and Legal Teams
Compliance and legal stakeholders map archival holdings to jurisdiction-specific retention requirements and disposition obligations, which sit outside the storage function itself. They typically confirm that keeping data in a cost-efficient archive does not conflict with minimization or retention principles under the applicable regime.

Inside Archival Storage

Long-term retention tier
Archival storage is a storage tier intended to hold data that is no longer in active use but must be preserved, typically for defined periods driven by legal, regulatory, contractual, or business requirements. It is distinct from operational or backup storage in that access is generally infrequent and retrieval may be slower.
Retention and disposition policy linkage
Archived data should be governed by documented retention schedules that specify how long records are kept and what happens at end of life. Archival storage is a mechanism for enforcing retention, but the retention rules themselves derive from governance policy and applicable legal obligations, which vary by jurisdiction and are out of scope for this entry to enumerate.
Personal data status in archives
Where an archive holds personal data, it generally remains personal data and subject to applicable regimes such as the EU GDPR or UK GDPR while retained. Placing data in an archive does not remove it from scope; obligations regarding data subject rights, security, and lawful basis typically continue to apply to archived personal data.
Security controls for archived data
Information security controls addressing confidentiality, integrity, and availability apply to archival storage, including access restriction, integrity verification, and protection against unauthorized alteration. These are security concerns distinct from the governance question of what should be archived and for how long, though the two overlap in practice.
Integrity and durability
Archival storage typically emphasizes durability and the ability to demonstrate that records have not been altered over long periods, which can be important for evidentiary or compliance purposes. Durability of the medium is separate from the accountability requirement to demonstrate governance over the archive.
Findability and cataloging
Effective archival storage generally depends on governance artifacts such as catalogs, indexes, and lineage records so that archived data can be located, understood, and acted upon (for example, to respond to a data subject request or a legal hold). This is a data governance function that complements the storage mechanism.

Common questions

Answers to the questions practitioners most commonly ask about Archival Storage.

Does moving personal data to archival storage mean it is no longer subject to data protection obligations?
No. Archiving changes how and where data is stored, but it generally does not remove data protection obligations. If the archived data remains personal data, obligations relating to lawful basis, retention limits, security, and data subject rights typically continue to apply. Archival status is an operational state, not a legal exemption. Treatment can vary by jurisdiction and by the specific regime involved, and this entry does not address regime-specific archiving derogations in detail.
If archived data is encrypted or tokenized, does that make it non-personal so retention rules stop applying?
No. Encryption and tokenization are security measures that reduce risk, but they do not by themselves make data non-personal. Where the data can still be re-identified or reversed, it generally remains personal data and remains within scope of applicable retention and data protection requirements. Only irreversible anonymization would take data out of scope in most regimes, and encryption or tokenization is not equivalent to anonymization. This entry does not cover the technical thresholds for anonymization.
How should retention periods be enforced for data held in archival storage?
Retention should typically be governed by a documented retention schedule that applies regardless of storage tier, with defined triggers for review, deletion, or further retention. Archival systems generally need mechanisms to locate and dispose of records when their retention period expires. This entry describes the governance principle rather than prescribing specific retention durations, which depend on jurisdiction, purpose, and applicable legal requirements.
Can data subject access and erasure requests be fulfilled against archived data?
In most cases where the archived data remains personal data, applicable rights such as access and erasure may still need to be actioned, subject to any exemptions available under the relevant regime. This generally requires that archival storage be searchable or indexable enough to locate an individual's records within required timeframes. Whether and how specific rights apply, and what exemptions exist, varies by jurisdiction and is outside the scope of this entry.
What security controls are appropriate for archival storage?
Archival storage typically warrants controls addressing confidentiality, integrity, and availability appropriate to the sensitivity of the data, which may include access restrictions, encryption at rest, integrity verification, and controlled disposal. These are information security measures and should be coordinated with, but distinguished from, the governance decisions about ownership, retention, and lawful basis. No single control guarantees compliance; appropriateness depends on context and risk.
How should archived records be reflected in governance documentation such as records of processing?
Archived personal data should generally be accounted for in governance records where an organization maintains records of processing activities, so that storage location, purpose, and retention are demonstrable. Accountability under governance frameworks typically requires evidence rather than stated intent, so archival arrangements should be documented and reviewable. Note that a records of processing obligation is a governance requirement and is distinct from any particular data inventory tool used to satisfy it.

Common misconceptions

Data placed in archival storage is out of regulatory scope and no longer counts as personal data.
Archiving generally does not change the legal status of data. Personal data typically remains personal data while retained, and obligations under applicable regimes such as the EU GDPR or UK GDPR generally continue to apply, including in most cases the ability to respond to data subject rights unless a specific exemption applies. Treatment differs across jurisdictions and this entry does not enumerate those exemptions.
Encrypting or tokenizing archived data makes it non-personal, so it can be retained indefinitely without further obligation.
Encryption and tokenization are security or risk-reduction measures and do not, on their own, render data non-personal. Encrypted or tokenized archives generally remain personal data because the underlying information can be recovered. Indefinite retention also typically conflicts with retention-limitation principles found in many regimes.
Archival storage is the same as backup.
The two serve different purposes and should not be conflated. Backup generally supports operational recovery and business continuity of active data, while archival storage supports long-term preservation of data that is no longer actively used. Retention policy, access patterns, and governance treatment typically differ between them.

Best practices

Link archival storage to a documented retention and disposition schedule so that data is retained only as long as a legal, regulatory, contractual, or business justification exists, and is disposed of in a demonstrable, auditable manner at end of life.
Maintain the ability to identify and act on personal data within archives, including support for data subject rights and legal holds, since archived personal data generally remains in scope of applicable regimes.
Apply proportionate security controls to archived data covering confidentiality, integrity, and availability, and verify integrity over time, while recognizing that these controls do not change the data's legal status.
Keep governance artifacts such as catalogs, indexes, and lineage records for archived data so it remains findable and understandable, rather than relying on the storage medium alone.
Distinguish archival storage from backup in policy and design, assigning each its own objectives, access model, and retention treatment.
Document ownership, stewardship, and evidence of governance over the archive, since accountability under governance frameworks generally requires demonstrable evidence rather than stated intent, and validate that treatment aligns with the specific jurisdictions and regimes that apply to the data.