Backup & DR

What Is GFS (Grandfather-Father-Son) and When to Apply It

The most widely used backup rotation scheme in professional environments: how to balance long-term retention, regulatory compliance and storage costs with the Grandfather-Father-Son strategy.

business EasyDataHost calendar_today April 5, 2026 schedule 9 min read

Every organisation that manages critical data faces the same dilemma: how long to keep backups and how much storage to dedicate to them. Retaining too many restore points consumes space and drives up costs. Retaining too few leaves the business exposed during audits, legal requirements or the need to recover data from weeks or months ago.

The solution to this balancing act is not new: the GFS (Grandfather-Father-Son) rotation scheme has been the de facto standard in professional environments for decades. GFS defines a clear hierarchy of daily, weekly, monthly and optionally yearly backups, each with its own retention policy. The result is a strategy that is predictable, storage-efficient and aligned with regulatory compliance requirements.

In this article we explain what GFS is, how the rotation cycle works, how to configure it in Veeam, when to apply it based on regulatory context, and how to combine it with offsite backups and immutability to build comprehensive data protection.

What Is GFS (Grandfather-Father-Son)

GFS is a backup rotation scheme that organises backups into three hierarchical levels, each with a different retention period. The name comes from the generational analogy:

  • today Son - Daily backups: performed every working day and retained for a short period, typically 7 days. They are the first line of recovery for recent incidents.
  • date_range Father - Weekly backups: one of the daily backups (usually Friday or Sunday) is promoted to a weekly backup and retained for 4 weeks. They provide one restore point per week for the last month.
  • calendar_month Grandfather - Monthly backups: one of the weekly backups (usually the last one of the month) is promoted to a monthly backup and retained for 12 months or more. They serve as the reference for audits and regulatory compliance.

Optionally, a fourth level is added: the yearly backup, which keeps a copy of the last monthly backup of each year for 5, 7 or 10 years, depending on regulatory requirements. This level is common in sectors such as finance, healthcare and public administration.

How the Rotation Cycle Works

The GFS cycle works through the automatic promotion of backups between levels. No additional backups are created: the same daily backup is reused as a weekly, monthly or yearly backup as appropriate. This minimises storage consumption.

Let us look at a practical example with the most common configuration:

  • arrow_right Son: daily backup Monday to Friday, 7-day retention. Each day a new backup is created and the oldest one beyond 7 days is deleted.
  • arrow_right Father: the Friday backup is flagged as weekly, 4-week retention. When the fifth Friday arrives, the oldest weekly backup is deleted.
  • arrow_right Grandfather: the last weekly backup of the month is flagged as monthly, 12-month retention. After one year, the oldest monthly backup is deleted.
  • arrow_right Yearly (optional): the December monthly backup is kept for 5-10 years according to the organisation's policy.

Practical example:

With the standard configuration (7 Son + 4 Father + 12 Grandfather), at any point during the year you will have available: the last 7 daily backups, the last 4 weekly backups and the last 12 monthly backups. That is a total of 23 restore points covering a full year, instead of the 365 daily backups you would need with simple retention.

Visual Diagram: A Month-Long Example

Imagine the month of April 2026. A backup runs every working day. Fridays are promoted to Father (weekly) and the last Friday of the month is also promoted to Grandfather (monthly):

Week Mon Tue Wed Thu Fri
Week 1 Son Son Son Son Father
Week 2 Son Son Son Son Father
Week 3 Son Son Son Son Father
Week 4 Son Son Son Son Grandfather

At the end of April, the Son backups from Monday to Thursday of week 4 are still available (7-day retention). The four Father backups (Friday of each week) are kept for 4 weeks. And the Grandfather from the last Friday is kept for 12 months. As time passes, the oldest Son backups are automatically deleted, but the Father and Grandfather backups remain according to their retention policy.

Benefits of GFS

  • gavel Regulatory compliance: GFS makes it possible to meet data retention requirements such as GDPR (5 years), healthcare regulations (10 years) or financial regulations, by keeping monthly and yearly backups without storing every single day of the year.
  • savings Storage efficiency: with just 23 restore points (7+4+12) an entire year is covered, compared to the 365 that a simple daily retention would require. The storage saving exceeds 93%.
  • restore Clear recovery points: the IT team always knows exactly which restore points are available and at what granularity. There is no ambiguity about how far back you can go.
  • trending_up Predictable growth: the number of retained backups is fixed (23 in the standard configuration), making it possible to plan storage capacity precisely and without surprises.

GFS in Veeam Backup & Replication

Veeam Backup & Replication implements GFS natively in its retention policies. The configuration is done in the GFS Retention Policy section of each backup job or backup copy job. The basic steps are:

  • looks_one Define the daily backup job: configure a job that runs incremental backups every day (Monday to Friday or Monday to Sunday) with a short retention (7-14 restore points).
  • looks_two Enable GFS in the backup copy job: in the long-term retention section, check the boxes for Keep weekly full backups, Keep monthly full backups and optionally Keep yearly full backups.
  • looks_3 Set retention periods: specify how many weeks to keep Fathers (4), how many months for Grandfathers (12) and how many years for yearly backups (5-10).
  • looks_4 Select the target repository: point the backup copy job to an offsite or S3-compatible repository to comply with the 3-2-1 rule. EasyDataHost offers Veeam Offsite repositories optimised for this purpose.

If your organisation needs Veeam licences, EasyDataHost offers official licensing with included technical support, simplifying both deployment and GFS policy configuration.

Comparison Table: GFS vs Simple Retention vs Forever Incremental

The following table compares the three most common retention approaches in professional backup environments:

Criterion GFS Simple retention (keep last N) Forever incremental
Long-term retention Excellent (months/years) Limited (days/weeks) Limited without GFS overlay
Storage usage Efficient (23 points/year) High if retention is extended Very efficient (increments only)
Regulatory compliance Ideal (monthly/yearly retention) Inadequate for long term Requires additional GFS
Management complexity Medium (automated in Veeam) Low Low
Restore speed Fast (full backups per level) Fast Variable (incremental chain)
Backup window Requires periodic fulls Requires periodic fulls Incremental only (minimal window)

When to Apply GFS

GFS is not necessary in every scenario, but it becomes essential when long-term retention requirements exist. These are the most common cases:

  • shield GDPR and data protection: although the GDPR does not specify exact retention periods for backups, many legal interpretations and compliance audits require keeping copies for 5 years. GFS with 5-year annual retention covers this requirement at minimal storage cost.
  • local_hospital Healthcare sector: healthcare legislation in many countries requires keeping medical records for 10-15 years. GFS with 10-year annual retention maintains one restore point per year without storing thousands of daily backups.
  • account_balance Financial audits: companies subject to accounting audits need to be able to demonstrate the state of data at any monthly or yearly close. The monthly Grandfather backups provide exactly that reference point.
  • balance Legal holds: when a legal proceeding requires preserving data from a specific period, GFS backups make it possible to locate and retain the copy from the exact month or year without affecting the rest of the rotation cycle.

GFS + Offsite: Meeting the 3-2-1 Rule

GFS defines which backups to keep and for how long, but it does not say where to store them. For comprehensive protection, GFS must be combined with the 3-2-1 rule: three copies of the data, on two different media, with at least one copy offsite.

The ideal combination is to keep Son and Father backups in a local repository (fast for frequent restores) and replicate the Grandfathers to an offsite or cloud repository. EasyDataHost offers two options optimised for this use case:

  • cloud_sync Veeam Offsite: a managed repository in EasyDataHost's data centre, connected directly to Veeam Backup & Replication for backup copy jobs with a GFS policy.
  • inventory_2 S3 Storage: S3-compatible object storage for archiving Grandfather and yearly backups at reduced cost per TB with immutability support (Object Lock).

For full disaster recovery scenarios, EasyDataHost also offers Veeam DRaaS, which combines offsite backup with the ability to boot virtual machines directly in EasyDataHost's data centre if the primary site becomes inoperable.

GFS + Immutability

GFS rotation protects against accidental data loss due to insufficient retention, but it does not protect against ransomware or the malicious modification of backups. To address this threat, GFS backups must be stored in repositories with immutability enabled.

An immutable backup cannot be modified, encrypted or deleted during its retention period, not even by an administrator with root access. When combined with GFS, each backup level (Son, Father, Grandfather) inherits immutability protection for its corresponding retention period. The result is a chain of backups covering from the last 7 days to the last 10 years, fully protected against tampering.

Key concept:

GFS defines how long each backup is retained. Immutability guarantees that no one can alter those backups during that time. Together, they form the foundation of a data protection strategy resilient to both operational errors and ransomware attacks.

Common Mistakes When Implementing GFS

Even with a well-designed GFS policy, these are the mistakes we see most frequently in organisations implementing backup rotation:

  • warning Not testing restores: the most serious mistake. There is no point in keeping 12 monthly backups if you have never verified that they can be restored correctly. We recommend quarterly restore tests at a minimum.
  • warning Insufficient retention for the sector: configuring GFS with 12 months when regulations require 5 or 10 years. It is essential to review legal requirements before defining the retention policy.
  • warning All copies in the same location: keeping GFS backups only in the local repository with no offsite copy. A fire, flood or ransomware attack can destroy both production data and all backups. A local snapshot is not a backup either.
  • warning Not documenting the policy: if the GFS policy is not documented and the only administrator who configured it leaves the company, no one will know which periods are covered or how to restore from a Grandfather backup.

Conclusion

GFS (Grandfather-Father-Son) is the backup rotation scheme that best balances long-term retention, storage efficiency and regulatory compliance. With just 23 restore points an entire year is covered, and adding yearly retention can extend coverage to 5 or 10 years without storage consumption growing out of control.

  • arrow_right Son (daily, 7 retained), Father (weekly, 4 retained), Grandfather (monthly, 12 retained) form the basic hierarchy.
  • arrow_right GFS saves over 93% of storage compared to simple daily retention over a year.
  • arrow_right Veeam implements GFS natively in its backup copy jobs, making configuration straightforward.
  • arrow_right Combining GFS with offsite + immutability provides comprehensive protection against data loss, errors and ransomware.
  • arrow_right Testing restores periodically is just as important as configuring the retention policy.

If you need to design a GFS backup policy tailored to your sector's requirements, contact our team to configure the retention strategy, offsite repository and immutability that best fit your organisation.

GFS Backup Veeam Retention Compliance
account_tree

GFS backup with long-term retention and offsite repository

EasyDataHost: Veeam Offsite + immutable S3, automated GFS policy, data in Spain. Regulatory compliance without complexity.