A Question Worth Asking Now

When an Employee Leaves,
Where Do the Files Go?

A file that lives only on one person's laptop, only in one person's personal Dropbox or Google Drive or OneDrive account, or only as an attachment in one person's personal inbox, is not a company file in any recoverable sense. It is a company file that happens to be sitting on someone else's property, held together by that person's continued goodwill and continued access. Most of the time that is fine, because most of the time nobody leaves. But someone eventually does, on a date that is usually known well in advance, and the files that mattered on their last Friday do not automatically move anywhere. They stay exactly where they were, on a machine or in an account the business may not control for very much longer. This page is about a very ordinary problem: not distrust, not theft, just files that were saved where it was fastest, by someone who is now gone.

Everyday Backups provides managed, encrypted cloud backup for Windows computers, with monitoring, restore support, and regular backup health reporting. Paid plans from $5.99/mo.

Where business files actually end up

Ask any small business where its files live and the honest answer is usually a mix of a few good locations and several improvised ones. None of the improvised ones were a decision anyone made on purpose. They are just where a file landed the first time someone needed to save it quickly.

Only the first of these is actually recoverable by the business on its own timeline. Every other item on that list depends on a person, a device, or an account that the business does not fully control, and most of the time nobody notices which category a given file fell into until the person who saved it is no longer around to ask. A useful exercise for any small business is a plain, honest inventory: for each person on the team, where does their day-to-day work actually get saved, not where a handbook says it should be saved. The answer is usually a little different for every person, built out of individual habits that developed over months or years without anyone deciding on them.

This inventory is worth doing while everyone is still around, because it is a question with a clear answer today and a much murkier one later. Right now, someone can simply be asked, and the answer takes thirty seconds. After they leave, the same question can turn into a search through an unfamiliar laptop, a request to a cloud provider that may or may not be answerable, or an admission that nobody actually knows and the file may just be gone.

Why turnover is different from every other kind of data loss

A drive failure is sudden and unplanned. Ransomware is sudden and unplanned. An employee leaving is neither. Someone gives two weeks' notice, or retires on a date set months earlier, or a seasonal role simply ends on schedule, and the business usually knows the date is coming. It is the one common data loss event that is scheduled in advance, and it is still, routinely, the one nobody prepares for.

Part of the reason is that turnover does not look like a data loss event while it is happening. Nothing crashes. Nothing gets encrypted. A person just packs up, hands back a badge, and their account gets closed a few days or a few weeks later, on a schedule set by IT policy or by whatever the cloud provider's own account-closure process happens to be, not by the business. The files that only existed in that person's world do not announce that they are about to become unreachable. They simply stop being reachable, quietly, on somebody else's timeline.

That is the core difference worth sitting with. The question "where does this file live?" is cheap and easy to answer while the person is still there to answer it. It is close to impossible to answer well after they are gone, an account is closed, and nobody who remembers the details is still reachable to ask. A drive failure gives a business no warning, but at least the loss is obvious the moment it happens, and everyone knows to start recovery immediately. A turnover-related gap is quieter. The file might still technically exist for days or weeks after someone's last day, sitting in an account nobody has opened yet, and the business often does not find out it is gone until someone specifically goes looking for it, by which point the window for an easy fix, simply asking the person who saved it, has already closed.

Ordinary convenience, not malice

It is worth saying plainly, because it is easy to read a page like this the wrong way: none of this is about distrusting anyone, and it is not a case for watching what people do with company files while they still work there.

People save files where it is fastest. A shared drive might require a few extra clicks, a login prompt, or a folder structure nobody fully remembers, while the desktop or an already-open personal cloud app is right there. Almost nobody makes that choice thinking about what happens if they leave the company someday. They are just finishing a task and moving on to the next one. The gap this creates is not a character flaw, it is what happens by default when the fast path and the recoverable path are not the same path, and nobody has made them the same path on purpose.

That is also why this is not a problem that gets solved by asking people to be more careful, or by monitoring where they save things. It gets solved by making the recoverable path the fast path, a shared location that is easy to reach, plus a backup of the machines people actually use, so that ordinary, well-intentioned convenience does not quietly turn into a gap nobody notices until someone is already gone.

The six places files go missing when someone leaves

These are not exotic edge cases. They are the ordinary, unremarkable ways a file ends up somewhere the business cannot easily get to once its owner is gone. None of them involve anyone doing anything wrong.

Desktop or local folder instead of a shared location

Saving to the desktop or a local "My Documents" folder is the path of least resistance, and it is often the default the operating system offers first. A spreadsheet, a client file, or a set of notes built up there over months can be the only copy that exists, sitting on one specific laptop, with no second copy anywhere else in the business.

A personal cloud account used for work

A personal Dropbox, Google Drive, or OneDrive account is convenient because it is already set up and already syncing across a phone and a laptop. Whatever gets saved there stays tied to that person's login, not the company's, even if the files themselves are clearly business records.

An account closed, suspended, or password-reset

Once someone leaves, their accounts typically get closed or the password gets reset as a routine offboarding step. Whatever lived only inside that account, including a personal cloud folder the business never had its own login for, generally goes with it, whether or not anyone realized it was there.

Files that exist only in a personal inbox

An attachment sent once, in a reply that was never forwarded or filed anywhere else, can be the only surviving copy of a signed form, a vendor quote, or a scanned document. If that inbox is personal rather than a company account, it leaves with the person, and nobody may notice until someone specifically needs that attachment again.

A company laptop wiped and reissued

A departing employee's laptop is often wiped and handed to the next hire as quickly as possible, sometimes before anyone has confirmed exactly what was on it or whether it had been backed up on any regular schedule. The reissue is routine; the question of what was lost in the process usually is not.

A contractor or part-timer on their own computer

Work done on a personal machine that was never a company asset was never covered by any backup plan the business had, because the business never had a plan for hardware it did not own. The deliverable the business cares about may exist in only one place, on someone else's hard drive.

What "the account closes" actually means for your files

"The account closes" sounds like one event. In practice it is a handful of different processes, run by different providers, on different timelines, none of which the business directly controls.

If the account belongs to an IT provider or an internal admin, the account may be disabled immediately or kept open briefly for a handoff, depending on that provider's own offboarding process. If the account is a personal cloud storage login, whatever retention window applies to a closed, suspended, or abandoned account is set by that provider, varies by plan and by provider, and changes over time as providers update their own policies. This page will not state a specific number of days any account or file stays recoverable, because that number is not fixed and not something we control or can promise. The practical takeaway is simpler than any specific policy: if a file only exists inside an account that is not the business's own, the safest assumption is that its recoverability ends whenever that account closes, on whatever schedule the provider that owns it decides, and the only way to check a provider's current policy is to read that provider's own current documentation before relying on it.

A company laptop is a more direct case. Once it is wiped, whatever was on it and not already copied somewhere else is generally gone as soon as the reimage finishes, and reimaging is often one of the first steps in getting a machine ready for the next person. In a small business without a dedicated IT team, that step frequently happens quickly, sometimes the same week someone leaves, because an empty desk with an idle laptop is not useful to anyone and the next hire needs a working machine. Nobody involved in that process is usually thinking about whether the outgoing employee's files were ever copied off the drive; they are thinking about getting a computer ready for whoever is starting next. That is exactly the kind of ordinary, well-intentioned handoff where a file that only ever lived on that one machine quietly stops existing.

None of this means a business needs to chase down every provider's retention policy before every departure. It means the safer default is not depending on any provider's retention policy at all for a file that matters. A file that is already copied onto the business's own backed-up machine, or into a shared company location covered by that backup, does not need anyone to check a retention window, because its recoverability was never tied to the account in the first place.

Understanding the 3-2-1 backup rule, applied to staff turnover

The 3-2-1 rule is a straightforward framework promoted by CISA and widely used in small-business backup guidance. Applied to staff turnover, it reframes the question from "did this person back up their own files" to "does the business have its own copy that does not depend on any one person."

3 copies of your data

The working copy on someone's laptop is one. A copy on a shared company drive is a second. A third, off-site, encrypted backup copy is the one that still exists regardless of whose desk the laptop sat on or whose account it was tied to.

2 different media types

Two copies on the same kind of local storage do not provide meaningful redundancy. CISA guidance calls for at least two different storage types, for example a local shared drive and a separate off-site backup destination, as independent layers of protection.

1 copy stored off-site

Off-site means physically and organizationally separate from any one person's device or personal account. A copy that lives only in a departing employee's personal cloud login is, by definition, not an off-site company copy at all.

Offline or air-gapped copies

CISA specifically recommends maintaining at least one backup copy that is not continuously connected to the network or tied to a single login. A copy like that survives a laptop reimage, a password reset, or an account closure without depending on any of them going smoothly.

The same offline, off-site copy that protects against a departing employee's account closing is also the copy that tends to survive a ransomware attack, since a connected sync folder or an actively mounted network drive can be encrypted along with everything else. For a closer look at that specific scenario, see ransomware restore readiness.

What a backup solves here, and what it does not

It is worth being direct about the boundaries of what a backup can do in a turnover situation, because the two halves of this problem are not the same and only one of them is a backup problem.

What it solves

A backup covering the Windows machine a person used means that whatever they saved to that computer, the desktop, the local user folder, a project folder, remains recoverable from the business's own copy after they leave, independent of whether their account is closed, their password is reset, or the laptop is later wiped and reissued. The business's own copy exists on its own timeline, not on the timeline of any account-closure process outside its control. That is the machine half of the problem, and it is the half a backup is actually built to handle.

What it does not solve

A backup is a data recovery tool, not a security product. It does not prevent anyone from taking, copying, or exposing data, and it is not a monitoring or surveillance tool of any kind, nor is it meant to be. It also does not reach into a personal email inbox, a personal cloud storage account, or a personal computer that was never the company's to back up. If a file only ever lived in one of those places, closing that account closes the door on it regardless of what backup product the business uses.

That half of the problem, the account half, is not solved by any backup product, ours included. It is solved by a habit: keeping company files off personal accounts in the first place, so there is nothing important left behind in an account the business never had access to when that account eventually closes.

Questions worth answering before the next departure

None of these require a policy document or a lawyer. They are just questions that are cheap to answer now and expensive to answer later.

None of these questions require confronting anyone or changing how the team works day to day. They are simply easier to answer, and easier to fix, on a Tuesday afternoon while everyone is still around than they are during someone's last week, when attention is elsewhere and the clock is already running.

Frequently Asked Questions

Is this page about catching an employee who might steal data?

No. This page assumes an ordinary, amicable departure, someone giving notice, retiring, or moving on, not a malicious one. It is not about monitoring staff, tracking activity, or distrusting anyone. The problem it addresses is much more mundane: people save files where it is fastest and most convenient, nobody reviews where those files ended up while the person is still there, and then the person leaves and the location of a file becomes a question instead of a known fact. A backup does not watch what anyone does. It keeps a separate copy of what is on the company's own machines so that a normal, expected departure does not also become a data loss event.

What actually happens to files when a departing employee's account is closed?

It depends on the account and the provider, and the exact timing is set by policies the business does not control. An email account may be suspended immediately or kept open briefly for handoff, depending on internal practice. A personal cloud storage account tied to that person's own login is generally not something the business can open at all once it is closed, reset, or the person simply stops responding. Retention windows for deleted or suspended accounts vary by plan and by provider, and they change over time, so the safest assumption is that anything living only in that account may not be recoverable once it closes, and the safest habit is checking each provider's current documentation rather than relying on what used to be true.

Does OneDrive, Google Drive, or Dropbox count as a backup for files an employee stored there?

Not when the account belongs to the person rather than the business, and not as a backup even when it is a company account. If a file exists only inside someone's personal OneDrive, Google Drive, or Dropbox login, the business generally has no direct way to reach that file once the person is gone and the account is closed or inaccessible. Separately, sync tools mirror the current state of a folder rather than keeping independent version history, so even a company-owned sync account is not the same thing as a backup. See cloud sync vs. backup, onedrive is not a backup, google drive is not a backup, and dropbox is not a backup for more detail on each.

What about a contractor or part-timer who works on their own computer?

A contractor or part-timer working on a personal computer is often the clearest version of this problem, because the machine itself was never the business's to back up in the first place. Whatever that person produces, a design file, a draft contract, a spreadsheet, exists only on hardware the business does not control and cannot access once the engagement ends. The practical fix is not a backup product, it is a habit: routing that person's deliverables into a shared, company-owned location while the work is happening, rather than treating the final handoff at the end of the engagement as the first time anyone checks where the files actually are.

Does Everyday Backups back up a former employee's email or cloud account?

No. Everyday Backups backs up files on Windows computers, the machine itself, not personal email inboxes, personal cloud storage accounts, or any account that is not the business's own Windows device. If a file exists only in a personal inbox or a personal cloud account and never touched a company machine, no backup product, ours included, can recover it after that account is closed. The account half of this problem is addressed by keeping company files off personal accounts in the first place, not by a backup running after the fact.

What is the 3-2-1 rule and how does it apply to staff turnover?

The 3-2-1 rule, promoted by CISA, calls for three copies of your data, on two different types of media, with one copy off-site, plus at least one copy that is not continuously connected to the network. Applied to staff turnover, the practical reading is that a file's only copy should never be the working copy on one person's laptop or inside one person's personal account. A second copy on a shared company location and a third, off-site, encrypted backup copy mean the file is still there, in its own right, regardless of whose desk the laptop used to sit on.

What does Everyday Backups actually provide, and what should we do before someone leaves?

Everyday Backups installs on Windows machines, backs up chosen files automatically on a schedule, encrypts data in transit and at rest, keeps version history, monitors for failed or missed jobs, and stores backups off-site rather than only on the machine itself. Paid plans start at $5.99/mo. Before someone leaves, the most useful step is simply asking where their working files actually live, the desktop, a shared drive, a personal cloud account, or an inbox, and moving anything that matters into a shared, backed-up location while they are still there to answer the question. Take the free 2-minute self-check to see where your current setup stands, review the small-business backup checklist for a broader assessment, or schedule a free 15-minute Backup Risk Check with our team.

Two ways to get started

Whether you want to check your current situation on your own first or talk it through with someone who can give you a second set of eyes, there is a starting point that fits. Neither option requires you to already know the answer to where every file on your team lives; that is exactly the kind of thing a quick review is meant to surface.

2-minute self-check (free)

The 2-minute self-check at everydaybackups.com/a/backup-risk-check.html asks a short set of questions about your current setup and tells you where the gaps are. No signup required. It takes about two minutes and gives you a clear picture of where you stand right now.

Free 15-minute Backup Risk Check (with our team)

If you would rather talk through your specific setup, our team offers a free 15-minute Backup Risk Check. We look at what you have, identify the gaps, including where files might be tied to personal accounts or personal devices, and give you honest guidance on what to fix first, whether or not you use Everyday Backups to do it. Schedule at app.everydaybackups.com/contact or call us at 850-980-3691.

Everyday Backups is a general file and device backup service for Windows computers, not employment-law, human resources, termination, offboarding-policy, non-compete, or data-ownership legal advice, and this page is not a substitute for any of it. A backup is a data recovery tool; it is not a security product, and it does not prevent anyone from taking, copying, retaining, or exposing data, nor is it a monitoring, surveillance, or insider-threat tool of any kind. It does not by itself satisfy any record-retention or other legal or regulatory obligation applicable to a business or its personnel records. References to OneDrive, Google Drive, and Dropbox are illustrative examples of common cloud storage platforms only, named for accuracy and not as an endorsement, disparagement, or compatibility claim, and any statements about account retention are general and vary by provider and by plan and change over time; consult each provider's own current documentation for specifics. References to CISA guidance are for informational context only and do not constitute endorsement by that organization. Consult your own legal counsel and human resources advisors for requirements specific to hiring, termination, offboarding, non-compete, and data-ownership matters at your business.

Protect every device, start in minutes

Everyday Backups runs on Windows, iPhone, iPad, and Android. Set it once; it backs up automatically, encrypted, off-site. Paid plans from $5.99/mo.

Prefer to talk to a person? Call 850-980-3691

Want a second set of eyes? Schedule your free 15-minute Backup Risk Check with our team