A Practical 3-2-1 Backup Plan for Personal Data in 2026

Three copies, two kinds of media, one stored off-site — with a short setup list and a restore test.

A 3-2-1 backup strategy means you keep three copies of data you cannot afford to lose, on at least two different kinds of media, with at least one copy stored somewhere that a fire, theft or ransomware event at home would not reach. It is a resilience rule, not a product. The copies can be a laptop, an external drive and a cloud account — or a phone, a drive in another building, and an encrypted disk you update monthly. What matters is that a single failure, a single account takeover, or a single location cannot erase every copy at once.

Most people already have fragments of this plan: photos in a cloud album, documents in a sync folder, a drive in a drawer that was last plugged in last year. Those fragments fail in predictable ways. Sync is not a backup if deleting a file deletes it everywhere. A drive that never leaves the house fails with the house. A cloud account with no second factor fails when the mailbox fails. This guide turns the rule into an inventory, a 30-minute setup, and a restore test you can finish in one sitting.

What the three numbers are actually counting

Three copies includes the working copy you use every day. If the only other copy is a sync folder that mirrors deletions, you do not have three independent copies. An independent copy is one you can still open after the working copy is encrypted by malware, wiped by a reset, or simply lost.

Two kinds of media means the copies should not all depend on the same failure mode. Two cloud accounts at two companies are better than one, but they still share internet, password-manager and identity risks. Pairing a cloud copy with a local drive (or an offline disk) covers both “the laptop died” and “the account was locked.”

One off-site means at least one copy is not in the same room as the working copy. Off-site can be a reputable cloud region, a drive at another address, or a disk in a bank box. “Off-site” that is still on the same desk during a burglary does not count.

Backup inventory

Write this down before you buy anything. The inventory is the plan. Hardware comes after you know which data would actually hurt to lose.

DataWorking copySecond copyOff-site copyIf this vanished tomorrow
Photos and videoPhoneComputer library or external driveCloud photo library or drive stored elsewhereFamily record is gone
Identity documentsOriginals at homeEncrypted scan on a driveEncrypted scan in cloud or second locationReplacing them is slow and public
Work filesLaptopExternal drive, updated on a scheduleCloud or employer system you do not control aloneDeadlines and invoices disappear
Password vaultPassword managerEmergency kit / printed recovery you store carefullyVendor recovery plus a second factor deviceEvery other backup becomes unreachable
Account recoveryEmail and phoneBackup codes stored offlineRecovery contact or hardware key kept elsewhereYou cannot sign in to the cloud copy

Crypto wallet recovery information does not belong in this ordinary inventory as a screenshot or a cloud note. Treat it as a separate, higher-risk item. The companion guide on crypto wallet recovery backup safety explains why mixing seed material into a normal cloud backup creates a new way to lose the funds.

A 30-minute setup checklist

You will not finish a perfect archive in half an hour. You can finish a minimum plan that already beats “everything is in one phone.”

  1. Pick one laptop or desktop as the working computer for documents and exports. Note its name on the inventory.
  2. Turn on full-disk encryption on that computer and on your phone if it is not already on. A backup of an unencrypted lost laptop is only half the problem; the lost laptop is the other half.
  3. Choose the off-site copy first: either a cloud backup or sync account you already pay for and can still sign in to, or a drive you can physically move this week. Do not open a new account you will forget.
  4. Export or copy the three categories that would hurt most: recent documents, a photo export or camera-roll backup, and scans of a few identity documents. Put them in the off-site copy.
  5. Plug in one external drive and copy the same three categories. Eject it. That drive is the second medium, not a second cloud.
  6. Confirm the password manager has a recovery method you have actually seen: backup codes, a recovery kit, or a second device. Store that method away from the laptop.
  7. Write the date on the inventory. A backup you cannot date is a rumor.

If step 4 stalls because you cannot sign in, stop and fix account recovery before you add more folders. A cloud copy you cannot open is not an off-site copy. The comparison in cloud backup versus an external drive is useful here: each one fails differently, so the checklist uses both on purpose.

Restore test: the step people skip

A backup is proven only when you open a file from the copy, not when the software says “complete.” Once a month, or after any large change, do this smaller test:

  1. Pick one document and one photo that you did not open today.
  2. Disconnect or ignore the working computer’s main folder. Open the file from the external drive.
  3. Sign in to the off-site copy from a browser or a second device and open the same file there.
  4. If either copy is missing, outdated, or encrypted with a password you do not have, the plan failed. Fix that copy before adding new categories.
  5. Record the test date next to the inventory date. If the two dates drift by more than a month, the drive in the drawer is decor.

Do not “test” by deleting the only working copy first. Restore from the spare while the original still exists. The point is to discover a bad copy while you still have a good one.

Threats this plan does and does not cover

The 3-2-1 rule is aimed at loss: disk death, theft of one device, a house fire, accidental deletion, and ransomware that encrypts the machine you are using. It does not by itself stop a thief who also steals the drive you left in the same bag, or malware that has been quietly corrupting files for months if every copy is a faithful mirror of the corruption. That is why versioned cloud backup (keeping older versions) and an offline drive you update on a schedule are more useful than a sync folder alone.

It also does not decide what is legal to copy. Work files may belong to an employer. Other people’s photos may have privacy limits. Back up what you are allowed to keep, and do not upload documents you would be unwilling to see in a breach without encryption.

Key takeaways

  • Three copies, two media, one off-site — count the working copy, and do not count a sync mirror as an independent copy.
  • Write an inventory before you buy a drive. The list is the plan.
  • A 30-minute pass can protect documents, photos and account recovery. Perfection can wait.
  • Open a real file from both the drive and the off-site copy. A green checkmark is not a restore test.
  • Keep wallet recovery information out of ordinary cloud folders.

Related reading

Informational only. Not financial, legal or technical advice for your specific situation. Verify current terms with the provider or primary source before you act.