Earlier quoted context omitted.
Under GDPR "right to be forgotten", you have to delete backups, can't keep them forever - see https://ico.org.uk/for-organisations/guide-to-data-protectio... There are alternatives (one of which is to encrypt the backed up data & just throw away the encryption keys instead) but of course those incur additional costs > Cheaper than loose your customer's data wich they trust you with. This is just opinion. And also it'…
>you have to delete backups, can't keep them forever >>The key issue is to put the backup data ‘beyond use’, even if it cannot be immediately overwritten. It's clear that you cannot delete WORM-tapen with many other data on it. >This is just opinion. Not for a file hosting service, the customer trusts you to do your job. >If it gets destroyed, is it a backup? Destroyed means physikal interaction, since it is not poss…
> ie that the backup is simply held on your systems until it is replaced in line with an established schedule
Again, you can't keep backups forever, you are _required_ to delete them.
Also, not sure why you keep you backups in the bank (do you, really?) but even banks can suffer from fire/arson, explosion (accidental or not), or a number of other natural disasters (earthquake, flooding, etc).
[later edit] Also, sort of by definition, in all businesses customers trust you to do your job. Can you give an example of a business where customers don't typically trust you to do your job?