Restoration of Availability
Restoration of availability refers to the ability to bring systems and data back into a usable, accessible state after a failure, outage, or disaster. It is a reactive capability, meaning it is concerned with recovering normal operations as quickly as possible once something has gone wrong, rather than preventing the disruption in the first place. In practice it typically relies on measures such as backups, failover processes, and documented disaster recovery procedures.
Restoration of availability is the capacity to recover access to systems, services, and data and return them to normal operating conditions following an incident such as an outage, hardware failure, or disaster. It is generally distinguished from high availability, which is preventive and aims to avoid downtime, whereas restoration is a reactive disaster recovery function that seeks to restore operations within defined durability and service objectives; in cloud contexts this may be handled through platform-level failover and repair processes, sometimes managed by the provider without customer action. In data protection practice, the concept aligns with the security principle that appropriate technical and organisational measures should enable the timely restoration of availability of and access to personal data in the event of a physical or technical incident; readers should verify the precise wording and any relevant article references against the current official GDPR text, as the sources in this evidence packet address the concept from an IT resilience and business continuity perspective rather than the Regulation itself.
Why it matters
When systems or data become unavailable due to an outage, hardware failure, or disaster, the consequences can extend well beyond inconvenience. In a data protection context, availability is a recognised dimension of information security alongside confidentiality and integrity, and the ability to restore access to personal data in a timely manner after a physical or technical incident is generally treated as part of the appropriate technical and organisational measures expected under the GDPR's security principle. Readers should verify the precise wording and any relevant article references against the current official GDPR text, as the underlying sources here approach the concept from an IT resilience and business continuity perspective rather than from the Regulation itself.
Restoration of availability matters because it is fundamentally reactive: it is what an organisation relies on once prevention has failed. Business continuity is generally described as the state in which a business can continue operations during failures, outages, or disasters, and disaster recovery is typically the reactive process intended to restore normal operations as quickly as possible. Without documented recovery procedures, tested backups, and clear objectives for how quickly and how completely data must be recovered, an organisation may struggle to demonstrate that it has taken adequate account of the risk of accidental or unlawful loss of personal data.
The practical stakes vary by context and should be assessed case by case. In some cloud arrangements, restoration may be handled at the platform level by the provider without customer action, while in others the customer retains significant responsibility for backups and recovery. Understanding where that boundary falls is important both for operational resilience and for allocating responsibilities between parties, though the specific division depends on the service model and contractual terms in place.
Who it's relevant to
Inside Restoration of Availability
Common questions
Answers to the questions practitioners most commonly ask about Restoration of Availability.