Back to Blog
Backup & DR21 August 2026

Google Workspace Backup for Australian Businesses

Cloud Ready SolutionsKeepit

Google Workspace backup in Australia gets confused with Google Vault more often than any other SaaS backup question CRS partners field. The two do genuinely different jobs. Vault preserves email and files for legal holds and eDiscovery; it was never built to restore your business after someone deletes the wrong Shared Drive. Understanding that difference, and where your backup data actually needs to live for an Australian business, is the whole point of this guide.

What Google Vault Actually Does (and Doesn't)

Vault is Google's built-in eDiscovery and retention tool, included with most Workspace editions. Set a retention rule and Vault will hold Gmail, Drive, Chat, Meet recordings and Voice content against deletion, searchable and exportable for legal or compliance purposes, for as long as the rule says.

What it will not do is act as a safety net for data you did not think to protect in advance. Google's own Vault FAQ is explicit that Vault has no automated recovery tools, and that a genuine backup, something that protects data against human error, insider damage or a ransomware attack, is a separate concern Vault was never designed to solve. If nobody set a retention rule before a file was deleted, Vault has nothing to hand back. There is no version history browser, no bulk point-in-time restore, no way to roll an entire organisational unit back to how it looked yesterday morning.

That gap is the reason "Google Workspace backup" and "Google Vault" keep getting typed into the same search box by IT admins who have just discovered they are not the same product.

The Deletion Scenarios That Actually Hurt

Google's native retention windows are generous by consumer standards and short by business-continuity standards.

Delete a file or empty a folder in Google Drive and it sits in Trash for 30 days before Google purges it permanently, a policy Google itself announced and rolled out in 2020 and still runs today. Gmail works the same way: messages in Trash are gone for good after 30 days, and neither window can be extended by an end user.

Offboarding is the sharper edge. When an admin deletes a user account, Google gives you 20 days to restore that account and its data from the Admin console's "Recently deleted users" list. Miss that window, whether because the offboarding process was rushed, the ticket sat unactioned over a long weekend, or nobody realised the account held the only copy of a departing employee's Drive files, and the account and everything in it is unrecoverable. No support ticket to Google reopens it.

Bulk changes carry the same risk without ever looking like a deletion. A Google Groups clean-up that accidentally strips sharing permissions from a Shared Drive, a bulk organisational-unit move that resets inherited access, or a script that mass-updates file ownership ahead of an offboarding round, none of these trigger Google's Trash at all, so there is nothing sitting in a 20- or 30-day window to recover from. The data still exists somewhere in Google's systems, but nobody in the organisation can get to it, and Vault's retention rules do not cover configuration or permissions in the first place.

None of this is a flaw in Google's design. Workspace is not marketed as a backup platform, and 30 and 20 days are reasonable defaults for a productivity suite. The problem is what happens when a business assumes those windows are longer than they are, or assumes Vault is quietly covering the gap.

Data Sovereignty: Where Your Google Workspace Backup Should Live

For Australian organisations, particularly those in regulated industries or with government and enterprise customers who ask where data physically sits, the location of a backup copy matters as much as its existence.

A genuine third-party backup should store its copy outside Google's own infrastructure entirely, so that a compromised Workspace tenant, whether from a phishing attack, a malicious insider or a misconfigured admin policy, cannot reach the backup along with the production data. Keepit takes that further for Australian buyers specifically: it runs its own independent cloud infrastructure rather than sitting on top of a hyperscaler, with a data centre in Sydney as one of seven regions it operates globally, so Australian Workspace data can be backed up and restored without leaving the country. That matters for the same reasons covered in more depth in our guide to data sovereignty for cloud backups.

Choosing a Google Workspace Backup Platform for Australian Businesses

A handful of things separate a backup platform worth paying for from one that only looks like it does the job:

  • Independent infrastructure. The backup copy should not live inside Google's own systems, and ideally not on the same hyperscaler stack (AWS, Azure, GCP) a competing product quietly runs on underneath its own branding.
  • Native-format restore. Google Docs, Sheets and Slides should come back as Google Docs, Sheets and Slides, not as generic exports that break formatting, comments and sharing permissions.
  • Granular scope. You should be able to back up and restore at the level of an organisational unit, a group, or an individual mailbox and Drive, not just the entire tenant in one all-or-nothing operation.
  • Australian data residency. For anything touching government, health, finance or a customer contract with a data-location clause, the backup copy itself needs a real answer to "which country is this actually stored in", not just "which region did we tick in a dropdown".
  • Predictable pricing. Per-GB storage fees and egress charges turn backup into a variable cost that grows with exactly the data you are trying to protect. Keepit for Google Workspace runs on flat per-user pricing instead, with unlimited storage and no charge to actually get your data back.

Independent, third-party SaaS backup covering Google Workspace alongside Microsoft 365, Salesforce and the rest of an organisation's SaaS stack from one platform is worth weighing too, particularly for businesses that are not purely Google, since running one backup console instead of two or three is a genuine reduction in operational overhead, not just a sales pitch.

Getting It Through Your MSP

Most Australian businesses running Google Workspace do not buy backup directly from a vendor. They get it, or should get it, bundled through whichever MSP already manages their Workspace tenant, alongside the endpoint protection, email security and identity tools that partner already sells.

That is the right model. It also means the client never has to evaluate a Google Workspace backup vendor on their own, compare per-GB storage pricing across three tabs, or discover after an incident that the plan they picked does not actually cover Shared Drives. An MSP that already has admin access to a client's Workspace tenant can scope and switch on backup in minutes, fold the monthly cost into an existing managed-services invoice instead of adding a separate vendor relationship for the client to manage, and be the first call when a restore is actually needed rather than a support ticket the client has to raise themselves at 2am on a Sunday. For MSPs weighing whether to add Google Workspace backup to their stack, the case is much the same as the one we made for Microsoft 365: Google's own documentation already tells you the native retention windows are not backup, so a client asking "are we covered?" deserves a real answer, not a reassurance that assumes Vault is doing a job it was never built for.

If your organisation runs Google Workspace and does not currently know how far back you could restore a deleted file or a deleted user account, that is worth finding out before it becomes an incident rather than during one. Get in touch to talk through Google Workspace backup options through a CRS partner.

Sources: Google Vault FAQ, Google Drive trash auto-delete after 30 days, Gmail Trash 30-day retention, Restore a recently deleted user (20-day window)

Related Vendors