Backing up accounting data: the 3-2-1 rule
The 3-2-1 rule (three copies, two media, one offsite copy) protects your accounting data, kept for ten years. Method, link to the FEC file, encryption and restore test, read by a chartered accountant.
Expert note: This article was written by our chartered accountancy firm. Information is current as of 2026. For a personalised review of your situation, contact us.
Quick answer. The 3-2-1 rule sums up a robust backup policy: three copies of the data, on two different types of media, including one copy kept offsite. Applied to accounting, it protects against deletion, failure and disaster, and secures the obligation to keep accounting documents for ten years (Commercial Code, art. L123-22). Two conditions make it genuinely useful: the copies must be encrypted, and the restore must have been tested.
Your accounting data is both vital for the business and mandatory to keep for ten years. A loss disrupts the company and creates a real risk in case of an audit, on the very day the authority asks you to produce the accounting entries file. The 3-2-1 rule is the reference method to protect against it. We set it out here as we apply it in client files, linking it to the two obligations weighing on this data: conservation and presentability.
This is not just an IT subject. It belongs to the overall rigour of accounting obligations, and it takes on a new dimension in the era of cloud migrations and the spread of electronic invoicing.
The 3-2-1 rule, decoded#
The 3-2-1 rule holds in three simple figures, but each one answers a distinct risk.
Three copies: the production data, plus two backups. Redundancy protects against accidental deletion, silent file corruption and ransomware that would encrypt both the database and a poorly isolated backup.
Two different types of media: for example local storage (NAS, disk, server) and cloud storage, so as not to depend on a single technology or a single provider. Two copies on the same disk count as one.
One offsite copy: kept elsewhere than on your premises, it protects against a local disaster (fire, water damage, theft, server failure). It is the copy that saves you when everything else has burned or been stolen.
The strength of the rule is its cross-redundancy: to lose everything, all three copies, on two media and in two places, would have to disappear at once. This is highly improbable, provided the backups are genuinely independent of one another.
Two distinct obligations: conservation and presentability#
Accounting data calls for particular vigilance, because the law imposes two things at once.
First obligation, to keep: accounting documents and supporting documents must be kept for ten years from the closure of the financial year (Commercial Code, art. L123-22). In parallel, tax law sets a conservation period of six years (Tax Procedures Code, art. L102 B). The two periods are independent: applying ten years satisfies both. That is the duration your backups must cover.
Second obligation, to present. In computerised accounting, the company must be able to hand over a copy of its accounting entries file (FEC) in case of an audit (Tax Procedures Code, art. L47 A). The standardised format in which this file must be produced is set by article A47 A-1 of the same code. This handover in dematerialised form is mandatory for any audit whose notice of verification is sent from 1 January 2014. The backup therefore serves not only business continuity: it guarantees that this data stays available, intact and usable throughout the legal period, FEC included.
A company that lost its accounting would face a double penalty: internal disruption, and the inability to respond to the authority. This risk is part of the broader work of accounting bookkeeping and review, where the quality of backups conditions the reliability of the whole.
The forgotten link: testing the restore#
The most neglected point of a backup policy is not the backup, it is the restore.
A backup is only worth its ability to be restored. Too many companies discover, on the day of the incident, that their backups were corrupted, incomplete, encrypted by the same ransomware or simply unreadable. A backup that has never been restored is not a backup: it is a hypothesis.
Regularly testing the restore, on an environment separate from production, is the only way to ensure the chain works end to end. The test must check three things: that the file restores, that it opens in the right software, and that the data is complete (latest year, FEC, supporting documents). This test is an integral part of a well-applied 3-2-1 rule.
| Rule element | Risk covered | Common mistake |
|---|---|---|
| Three copies | Deletion, corruption, ransomware | Two copies on the same disk |
| Two different media | Dependence on a single technology | Everything on one cloud |
| One offsite copy | Local disaster (fire, theft) | Backup stored next to the server |
| Encryption of copies | Theft or leak of personal data | Plaintext backup on an external disk |
| Restore test | Unreadable backup on the day | Never having tried it |
| 10-year coverage | Data erased before the legal period ends | Rotation overwriting old years |
Trade-off: all local, all cloud, or mixed#
One question keeps coming up: where to put these copies? Three approaches coexist, each with its limits.
All local (internal server or NAS) offers direct control and fast restore, but concentrates the risk on a single place: a fire or theft takes out production and backups in one go. All cloud outsources and automates, but creates dependence on a single provider and raises the question of data location. The mixed approach (a local copy plus an offsite cloud copy) faithfully reproduces the 3-2-1 rule and remains our default recommendation for an SME.
The choice of cloud is not neutral. Beyond price, two technical criteria deserve to be read in the contract: encryption of data at rest (ideally AES-256) and in transit (TLS), which protects your backups in case of theft or interception. This data almost always contains personal information (employee names, payroll, customer contacts): encryption is therefore not a luxury, it is the first line of defence against a leak. Also ask your provider whether it offers an immutable or offline copy, which resists ransomware.
Location, in turn, follows two distinct logics that must not be confused. On one hand, your data and invoices must stay quickly accessible from the head office in case of an audit, since the authority may require presentation of the computerised accounting (Tax Procedures Code, art. L47 A): hard-to-reach hosting complicates this obligation. On the other hand, as soon as backups contain personal data, the GDPR applies, and a transfer outside the European Union is lawful only to a country offering an adequate level of protection or framed by appropriate safeguards (CNIL). Hosting within the European Union is therefore not an obligation specific to accounting, but good practice that simplifies both access and GDPR compliance. This logic meets the confidentiality concerns we address when pseudonymising data protects professional secrecy: the location and access to data are not technical details, they are conditions of compliance.
Our view: backup is a governance subject, not a hardware one#
In client files, we rarely see companies with no backup at all. We mostly see backups that are never tested, rotations that silently overwrite old years before the ten-year period ends, copies stored in plaintext, and cloud solutions whose hosting country no one knows. The real subject is not buying one more disk: it is appointing someone responsible, writing a simple procedure, and checking it.
Our advice is consistent: apply the 3-2-1 rule, favour an encrypted cloud copy for the offsite, check that the retention period really covers the ten legal years, and above all schedule a restore test at least quarterly. A well-thought-out backup turns a potentially serious incident into a mere setback. When the accounting changes software, these reflexes become critical: the carry-over of balances during a cloud migration is exactly the moment when poorly backed-up data is lost for good.
A common case: the failure that precedes the audit#
A services SME kept its accounting on a single local server, with a backup permanently connected to the same network. No offsite copy, no encryption, no test. A disk failure, compounded by an electrical incident, made the data inaccessible. A few weeks later, the company received an audit notice and had to produce its FEC.
The reconstruction was long and costly: partial re-entry from bank statements, requests for duplicates from suppliers, disk forensics. The cost far exceeded that of a proper backup solution. We have since put a 3-2-1 rule in place: a local copy, an encrypted offsite cloud copy hosted in the European Union, and a quarterly restore test written into the closing calendar. The data is now protected, and the FEC restorable at any time.
In practice: deploying a 3-2-1 rule on your accounting#
- Inventory what must be backed up: accounting database, FEC by year, dematerialised supporting documents, electronic invoices, and payroll records.
- Set up at least three copies, on two distinct media (for example a local NAS and a professional cloud), including one genuinely offsite copy.
- Require encryption of backups at rest (AES-256) and in transit (TLS), especially once they contain personal data.
- Check the ability to access data quickly from your head office in case of an audit; in the cloud, favour hosting within the European Union to simplify GDPR compliance.
- Set retention to cover ten years: forbid any rotation that would overwrite a year still within the legal period.
- Schedule a restore test at least quarterly, on a separate environment, and keep a written record of each successful test.
- Appoint a named person responsible and document the procedure on one page, accessible in case of absence.
Watch points#
- Rotation that erases too early: a backup keeping only the last 30 days does not cover the ten-year obligation. Distinguish short backup (continuity) from long archiving (legal conservation).
- Ransomware following the backup: a copy permanently connected to the network can be encrypted along with production. An offline or immutable copy protects better.
- The unencrypted backup: an external disk or a plaintext cloud copy exposes your personal data (payroll, customers) in case of theft or leak. Require encryption at rest (AES-256) and in transit (TLS).
- Poorly located cloud: this is not a legal ban specific to accounting, but hosting outside the European Union complicates access in case of an audit and, for personal data, triggers the GDPR transfer safeguards.
- The forgotten FEC: backing up the software database is not always enough; check that the FEC for each year is exportable and kept.
- The never-tested backup: without a documented restore test, you do not know whether your copies are usable.
- The departure of the IT provider: if only one person knows the procedure and the accesses, their departure becomes a continuity risk. Document and share.
Frequently asked questions
What is the 3-2-1 rule?+
It is a backup standard: three copies of the data, on two different types of media, including one copy kept offsite. This cross-redundancy protects against accidental deletion, hardware failure, ransomware and a local disaster such as fire or theft.
How long must accounting data be kept?+
Accounting documents and their supporting documents must be kept for ten years from the closure of the financial year (Commercial Code, art. L123-22). Tax law imposes six years in parallel (Tax Procedures Code, art. L102 B). Applying ten years satisfies both obligations: your backups must therefore cover this period.
Does the backup also protect in case of a tax audit?+
Yes. In computerised accounting, you must be able to hand over a copy of the accounting entries file (FEC), whose presentation is required under article L47 A of the Tax Procedures Code, in the standardised format set by article A47 A-1. A reliable backup guarantees that this file stays available and usable on the day the authority asks for it.
Why is an offsite copy indispensable?+
Because a local disaster (fire, water damage, theft, failure) can destroy the production data and the backups kept on the same premises at the same time. An externalised copy, often cloud, is the only one that survives this type of event.
Is the cloud enough on its own?+
The cloud is an excellent medium for the offsite copy, but the 3-2-1 rule recommends two types of media. Combining local and cloud storage avoids depending on a single technology or provider, and speeds up the restore of recent data. Check that the backups are encrypted at rest and in transit.
Does the GDPR apply to accounting backups?+
Yes, as soon as the backups contain personal data: employee names, payroll items, customer or supplier contacts. The GDPR then imposes security measures (encryption is one of them) and frames any transfer outside the European Union, which is lawful only to a country offering an adequate level of protection or through appropriate safeguards (CNIL).
Where should accounting data be hosted?+
No accounting text imposes a specific country. Two logics guide the choice: the accounting must stay quickly accessible from your head office in case of an audit (Tax Procedures Code, art. L47 A), and, if the backups contain personal data, the GDPR frames any transfer outside the European Union. Hosting within the European Union therefore remains good practice that simplifies both access and compliance.
Key takeaways#
- The 3-2-1 rule: three copies, two different media, one offsite copy, plus encryption and a restore test.
- It covers four risks: deletion, failure, ransomware and local disaster.
- Accounting data must be kept for ten years (Commercial Code, art. L123-22); the six-year tax period (Tax Procedures Code, art. L102 B) is included within it.
- The backup also guarantees the presentability of the FEC in case of an audit (Tax Procedures Code, art. L47 A; format defined by art. A47 A-1).
- Encrypt the copies and, if they contain personal data, comply with the GDPR; hosting within the European Union simplifies access and compliance.
- The quarterly, documented restore test is the step most often forgotten.
Official sources#
- Légifrance: Commercial Code, art. L123-22 (conservation of accounting documents)
- Légifrance: Tax Procedures Code, art. L47 A (presentation of computerised accounting)
- Légifrance: Tax Procedures Code, art. A47 A-1 (format of the accounting entries file)
- BOFiP: conservation of accounting books, documents and records
- CNIL: transferring data outside the European Union
This article is published by Hayot Expertise, a chartered accountancy firm registered with the Ordre des experts-comptables d'Île-de-France. It is for information only; a decision specific to your situation requires a review of your organisation, your hosting contracts and your company's context.

Article written by Samuel HAYOT
Chartered Accountant, registered with the Institute of Chartered Accountants. Certified Pennylane trainer.
Regulated French accounting and audit firm based in Paris 8, built to support companies across France with a digital and decision-oriented approach.
Sources
Official and operational sources cited for this page.
- Légifrance : Code de commerce, art. L123-22 (conservation des documents comptables)
- Légifrance : Livre des procédures fiscales, art. L47 A (présentation de la comptabilité informatisée, FEC obligatoire depuis le 1er janvier 2014)
- Légifrance : Livre des procédures fiscales, art. A47 A-1 (format du fichier des écritures comptables)
- BOFiP : conservation des livres, documents et pièces comptables
- CNIL : transférer des données hors de l'Union européenne (encadrement RGPD des transferts)
This topic is part of our service Tax accountant in Paris | CIT, VAT & tax audits
Need a quote or personalised advice?
Our accountancy firm supports you through all your steps. Get a free quote to review your situation and receive a bespoke fee proposal, or contact us directly.