---
title: GDPR
date: 2026-06-01T17:19:00+02:00
author: Hannes Heckel
canonical_url: "https://www.fast-lta.de/en/glossary/gdpr"
section: Glossar
---
The GDPR has applied directly in all EU member states since 25 May 2018. Several articles are particularly relevant for the technical infrastructure of data storage.

Art. 32 GDPR requires technical and organizational measures appropriate to the risk — including encryption of personal data, pseudonymization, and the ability to rapidly restore the availability, integrity and confidentiality of personal data after an incident. This directly establishes the need for robust backup infrastructure.

Art. 28 GDPR governs data processing agreements: every cloud provider acting as a data processor must be contractually bound. The controller remains responsible for compliance with all GDPR requirements — even when data is held by an external provider. This includes the question of whether the provider is subject to the US CLOUD Act.

Art. 17 GDPR (right to erasure) exists in tension with retention obligations (GoBD, HGB, medical records laws): retention obligations take precedence over the GDPR erasure obligation as long as they apply. After the retention period expires, the GDPR erasure obligation takes effect. Modern WORM systems support deadline-based retention management that meets both requirements within a single system.

### GoBD

The GoBD (Principles for the Proper Management and Storage of Books, Records and Documents in Electronic Form as well as Data Access) is a German Federal Ministry of Finance letter that specifies how tax-relevant documents must be archived electronically in Germany — particularly regarding immutability, completeness and auditability.

[Mehr erfahren →](https://www.fast-lta.de/en/glossary/gobd)

### WORM

WORM (Write Once, Read Many) refers to a storage principle in which data is written once and can technically no longer be altered or deleted — in hardware WORM, this immutability is a physical property of the storage controller, independent of software, operating system or user privileges.

[Mehr erfahren →](https://www.fast-lta.de/en/glossary/worm)

 

## Frequently asked questions

 #### May I retain backups of data I must delete under GDPR?

If statutory retention obligations (e.g., commercial, tax or medical law) apply, they take precedence over the GDPR right to erasure. After the retention period expires, Art. 17 GDPR applies: the data must then be deleted. Modern WORM systems support deadline-based retention management: after the retention period expires, data is released for controlled deletion.

#### May I store backups with US cloud providers?

This is a complex legal question. GDPR Art. 44–49 permits data transfers to third countries only under certain conditions. For the US, the EU-US Data Privacy Framework (2023) serves as the legal basis — but it is legally fragile. European data protection authorities have challenged the use of US cloud services for sensitive data categories in several decisions. For highly sensitive data (patient data, government data), on-premises storage is the most legally secure option.
