Google Workspace runs on some of the most reliable infrastructure on the internet, and losing access to the platform itself is not the risk most small businesses actually face. The risk is losing specific data, a folder, a mailbox, an entire user's account, and discovering that the recovery window already closed. Google Workspace does retain deleted data for a period of time, and understanding exactly what that period covers, and what it doesn't, is the difference between a five-minute recovery and a permanent loss.
Shared responsibility: Google secures the platform, you're responsible for your data
Every major cloud provider, Google included, operates on a shared responsibility model. Google is responsible for keeping Workspace running, patched, and protected against infrastructure-level failures and attacks. You, the customer, are responsible for how your organization configures sharing, who has access, and whether the data your business depends on is recoverable if something goes wrong on your side of that line: a deleted file, a compromised account, an employee who removes something they shouldn't have. Google's own support documentation describes retention windows and recovery tools for exactly these situations, but a retention window is not the same thing as a backup, and the distinction matters more than it sounds.
Drive and Gmail trash: 30 days for users, then a short admin-only window
When a file is moved to the Trash in Google Drive, it stays recoverable by the user for up to 30 days, and files moved to the Trash are deleted forever after 30 days, whether a person emptied the trash manually or the 30-day clock simply ran out (Google Drive Help: Delete files in Google Drive). What's less well known is that this isn't quite the true end of the line. A Workspace admin can still recover deleted items from Drive for an additional 25 days after a user empties their trash, using the Admin console's data recovery tool; after that 25-day window, Google purges the items from its systems and they can't be recovered (Google Workspace Admin Help: Recover deleted files and folders for Drive users). Gmail has a similar admin-only extension. A deleted message sits in the user's Trash for up to 30 days, and once that period ends, admins have an additional 25 days to restore messages using the Admin console's Restore data tool, a window that starts 30 days after the message was deleted, not from when it was sent or received, and applies to messages of any age; once that additional 25-day period ends, messages are permanently deleted (Google Workspace Admin Help: Restore a user's permanently deleted email). So the realistic outside limit, if nobody notices sooner, runs to roughly 55 days from deletion for Gmail, and 25 days after Drive trash is emptied. That's still not a backup: it's a fixed, one-time window, it depends entirely on an admin with console access noticing and acting before that date, and it only reaches inside the same Workspace account that had the problem. Even 55 days isn't generous once you consider how businesses actually discover a problem: an invoice folder cleaned up in Q1 that isn't missed until year-end reconciliation, or a client's project files deleted by mistake and not noticed until the client asks for them months later. By then, both windows have usually already closed.
What happens to a deleted user's data, and the transfer window
When an admin removes a user from your Workspace, such as when an employee leaves, Google doesn't erase everything the instant the account is deleted. According to Google's own admin documentation, some data, including Gmail messages, the user's primary calendar, and Drive files they owned, is retained for 20 days, during which an admin can restore the deleted account or transfer the user's files to another owner (Google Workspace Admin Help: Delete or remove a user from your organization). That 20-day window is also when files owned by other people, but sitting in the deleted user's folders, are still findable through Drive search; after 20 days, those files are automatically moved into their real owners' My Drive, and anything belonging to the deleted user that was never transferred is gone for good. If your offboarding process depends on remembering to transfer a departing employee's files inside those 20 days, a busy month is all it takes to miss it.
Admin restore windows are recovery tools, not backup
The 20-day account restore, the 30-day user trash window, and the roughly 25-day admin-only extension on top of it are all genuinely useful, and every Workspace admin should know they exist. But notice what they have in common: each is a single, fixed window tied to the deletion event itself, not a repeatable point-in-time restore. There's no way to reach back to how a mailbox or a Drive folder looked on a specific date last quarter, only whatever still falls inside that roughly 55-day ceiling for Gmail or 25-day-after-emptying ceiling for Drive. The recovery only reaches inside the same Workspace account that had the problem in the first place, and it depends entirely on an admin noticing and acting before the window quietly closes. A recovery window protects you from an accident caught quickly. It does not protect you from an accident, or an attack, discovered after the window has already run out.
Why Google Vault is retention and eDiscovery, not backup
Google Vault gets mistaken for a backup product more often than any other part of Workspace, largely because it's the tool most associated with keeping data around long term. It isn't a backup. Google's own overview describes Vault as "an information governance and eDiscovery tool for Google Workspace" that lets you "retain, hold, search, and export users' Google Workspace data," and it specifically notes that Vault "isn't a data archive" (Google Workspace Help: Google Vault overview). Two details matter here. First, Vault only retains what you've configured a retention rule or legal hold for; nothing is captured automatically until you set that up. Second, Vault's job is to preserve data for legal, compliance, and search purposes, which is a different job than restoring a mailbox or a shared drive to exactly how it looked before something went wrong. Vault can be genuinely important for the compliance side of a business. It is not a substitute for backup.
Ransomware, and files deleted through sync
A file deleted by a person, a script, or an attacker who has taken over an account all look identical to Google Workspace: a file that moved to trash and, unless an admin catches it inside the recovery window, which can run to roughly 55 days total for Gmail or 25 days after Drive trash is emptied, it's gone once that window closes. Ransomware that spreads through a synced Drive folder, or an account takeover where an attacker deletes or encrypts files and then empties the trash to cover their tracks, can outrun even that admin-extended window entirely, especially if the incident isn't discovered for a couple of months. Google's platform-level protections defend the infrastructure; they don't reach back in time to reverse account-level deletions once the recovery window, including the admin-only extension, has run out.
The departing employee scenario, in practice
This is the single most common way small businesses actually lose data in Google Workspace: an employee leaves, their account is suspended and eventually deleted, and in the scramble of offboarding, nobody transfers their Drive files or checks their Gmail for anything the business still needed. Twenty days pass. The files that weren't transferred are gone, not archived somewhere Google can retrieve them, just gone. It's rarely malicious; it's almost always a process gap, and it's exactly the kind of loss a backup with its own retention schedule would have prevented.
What a third-party cloud backup actually adds
A backup layered on top of Google Workspace isn't duplicating what Google already does. It's covering what Google's retention windows were never designed to cover:
- Point-in-time restore. Instead of only being able to recover whatever trash currently contains, you can restore a mailbox, a Drive folder, or an entire user's data as it existed on a specific date.
- Retention beyond Google's windows. Data that Google would have permanently deleted after its 20-day, 30-day, or roughly 25-day admin-extension windows close is still recoverable months or years later.
- An independent copy. Backup data lives outside your live Workspace environment, so a compromised admin account, a ransomware event, or a deletion inside Workspace itself can't also destroy your only copy.
A short checklist
- Confirm what your offboarding process actually does inside the 20-day window when a user is deleted, and whether anyone is responsible for checking it.
- Know that an admin-only recovery window of about 25 more days exists after trash empties, roughly 55 days total for Gmail, 25 days after Drive trash is emptied, and confirm someone with admin access actually knows to use it before it closes too.
- Don't assume Google Vault, if you have it, is protecting you the way a backup would; check whether retention rules are even configured.
- Ask whether your business could recover a specific folder or mailbox as it looked three months ago. If the honest answer is no, that's a backup gap, not a Google Workspace failure.
- Put a real, independent backup in place for anything the business genuinely couldn't afford to lose permanently.
Frequently asked questions
Does Google Workspace have built-in backup?
No. Google Workspace has retention windows, like 30 days of user trash in Drive and Gmail with about 25 more admin-only days after that, plus a separate 20-day window to restore a deleted user's account and data, but those are recovery windows built for accidents caught quickly, not a backup. Once those windows close, the data is gone.
Is Google Vault a backup?
No. Google's own documentation describes Vault as an information governance and eDiscovery tool for retaining, holding, searching, and exporting data, not a data archive. Vault only retains what you configure it to retain, and it does not give you point-in-time restore of a mailbox or Drive the way a backup does.
What happens to a departing employee's Drive files and email?
When an admin deletes the user, Google retains their Gmail, primary calendar, and owned Drive files for 20 days, during which an admin can restore the account or transfer their files to another owner. After 20 days, anything not transferred is permanently deleted and unrecoverable.
Can ransomware or a compromised account delete data that Google can't get back?
Yes. Admins get an extra recovery window after user trash empties, about 25 more days, so roughly 55 days total from deletion for Gmail and 25 days after Drive trash is emptied, but once that window has closed, whether the files were deleted by a person, a script, or an attacker with access to the account, Google Workspace itself has no way to bring that data back. An independent backup copy is what restores it.
What does a third-party backup add on top of Google Workspace?
Point-in-time restore to a specific date rather than just whatever trash still contains, retention that extends well beyond Google's 20-day, 30-day, and 25-day admin-extension windows, and an independent copy of your data stored outside Google's own systems so a problem inside your Workspace account can't also take out your only copy.
Not sure what your Google Workspace retention actually covers?
Talk directly to the owner about cloud backup for Google Workspace, built to cover what Google's own retention windows don't. See current pricing or read more about backup and disaster recovery.
Book your free assessmentNonprofit running on Google Workspace? See our IT support for nonprofits on Google Workspace. Locking down sharing and sign-in settings first? Read Google Workspace security settings for small business. Prefer to talk first? Email sales@ghosxt.com or call (831) 204-0501.