forumNew topic

I'm uploading database backups to the cloud without encryption — could customer data leak?

MMehmet A***Member
Job title
Sales Manager
Sector
Insurance
Organization type
two-branch business
Joined
Mar 2026
Message
251
#1

I take a daily backup with mysqldump and upload it to AWS S3. But I'm not doing any encryption, the SQL file sits on S3 in plain text. The backup file contains all customer data: first name, last name, phone, email, address, even some credit card numbers. If someone has my AWS access key, can they see everything?

How do I do encryption? Should I encrypt the mysqldump output with OpenSSL, or is there another way? Can I automatically encrypt files uploaded to S3?

If our backups are compromised, what do I need to do? Is it mandatory to notify my customers? Within how many hours do I need to tell them?

DDilara A***Member
Job title
Data entry clerk
Sector
Insurance
Organization type
a company within a holding
Joined
Oct 2024
Message
99
Most Helpful#2

Encrypting backups is a legal and technical necessity. Steps: 1) mysqldump encryption: mysqldump database | openssl enc -aes-256-cbc -salt -out backup.sql.enc (client-side encryption), 2) AWS S3 encryption: Server-side encryption (SSE-S3 or SSE-KMS), check encryption state in object metadata, 3) Also: access control (bucket policy, IAM roles), versioning enabled, lifecycle policies (delete old backups). In case of data breach: GDPR, KVKK and Turkish laws prescribe a 72-hour notification period. Customers, authorities, and if media coverage is assumed in risky situations, rapid notification is mandatory. Backup access logs: enable S3 server access logging, enable AWS CloudTrail (so I know who downloaded what and when). Restore and key management: store backing keys in a separate environment, apply key rotation.

NNuri U***VeteranCommunity member
Joined
Feb 2024
Message
325
#3

you need to do encryption on S3, man, store the decryption key somewhere else. tbh encrypt with openssl and upload to S3. if your access key leaks people can download the data so encryption is critical and but if there's a breach, you're obligated to report to KVKK definitely...

OOrhanMember
Job title
IT company
Joined
Oct 2023
Message
132

Doki · Vulnerability scanning · 2026

#4

Encryption approaches: 1) Client-side (before upload): openssl, GPG, encrypted 7zip, 2) Server-side (S3): SSE-S3 (default key), SSE-KMS (customer key), SSE-C (customer-provided key). Recommended: Client-side AES-256 + server-side KMS. Key management: AWS KMS key rotation annually, separate key for backups. GDPR/KVKK compliance: Encryption mandatory, breach notification within 72 hours (the 72-hour reporting window is correct), but sooner if media is mixed up. Restoring from encrypted backup: Need the decryption key, lost key = risk of permanent data loss.

OOzan M***New member
Job title
Music Instructor
Joined
Aug 2024
Message
34
#5

leaving customer data unencrypted is the worst thing ever. encrypt it with OpenSSL, store the key somewhere else, upload to S3 done. if data leaks KVKK slaps you with huge fines the company can even get shut down. encrypt immediately and if you have old backups delete them...

EEmre G***MemberCommunity member
Joined
Dec 2022
Message
198
#6

Backup encryption strategy: 1) Data classification (which ones are sensitive), 2) Encryption algorithm (AES-256 is ideal), 3) Key management (separate storage, rotation), 4) Transport security (HTTPS), 5) Access control (IAM, SSM). Automation: bash script with mysqldump | openssl | aws s3 cp --sse-aws:kms. Audit: S3 access logs, CloudTrail, anomalous access alerts. Breach response: containment, investigation, notification (KVKK/GDPR timeline).

ZZübeyde K***Member
Job title
Purchasing manager
Sector
Sports and fitness
Organization type
family business
Joined
Feb 2025
Message
165

Doki · Corporate website · 2026

#7

encryption = shield within a shield 😂 Leaaving backups open = giving away your data but anyway do both OpenSSL and S3 encryption sleep easy.

SSinan B***VeteranCommunity member
Joined
Apr 2022
Message
48
#8

I'm curious too.

ZZafer Y***Expert
Job title
Software team lead
Sector
Jewelry
Organization type
8-person team
Joined
Jun 2023
Message
214
#9

The answer above hits the nail on the head. Mistakes made on the database backup encryption side are usually reversible but expensive.

This is my opinion, I'm not claiming it's absolute truth.

TTarık D***Expert
Job title
Exporter
Joined
Sep 2023
Message
156
#10

Let me summarize what's been said so far. Having backups accessible on the same network and with the same identity makes them part of the target.

Security isn't absolute; it's about making attacks not worth the effort. That's all, sorry if I went on too long.

CCaner T***Member
Job title
General Manager
Sector
Leather
Organization type
sole proprietorship
Joined
Jul 2024
Message
1
#11

Thanks for posting.

PPınar K***MemberCommunity member
Joined
Feb 2026
Message
17
#12

My questions are cleared up, thanks. Taking notes for two weeks yields better results than a six-month estimate.

Good luck with that.

MMetin A***Expert
Job title
Business consultant
Organization type
sole proprietorship
Joined
Aug 2023
Message
186
#13

Following.

MMustafa C***MemberCommunity member
Joined
Jan 2026
Message
96
#14

Exactly like that. Processes without records never improve, because you don't know what to fix.

Just leaving this note, it might be useful.

HHande Ş***Member
Job title
Secretary
Sector
Cleaning services
Organization type
early-stage startup
Joined
Dec 2024
Message
163
#15

Let me speak from the other side; I'm on the supplier side. Having backups accessible on the same network and with the same identity makes them part of the target.

İİbrahim A***ExpertCommunity member
Joined
May 2024
Message
1
#16

Thanks for writing this, that's the right way. Taking measures without an inventory leaves doors you haven't seen open.

If I were you, I'd go this route.

YYasemin Ç***Expert
Job title
Quality Assurance Manager
Sector
Cleaning services
Organization type
chain store
Joined
Feb 2024
Message
3

Doki · Infrastructure migration · 2026

#17

Thanks, this was very helpful. like the biggest time-waster for us was not knowing who had the final say.

If you have questions, write them; I'll answer as best I can.

BBerkMember
Job title
Real Estate Agent
Joined
Apr 2024
Message
102

Doki · Incident response support · 2026

#18

Quick summary for newcomers: Don't rely on a single measure; go layer by layer.

An untested backup is not a backup. Hope this helps.

MMustafa E***MemberCommunity member
Joined
Feb 2024
Message
83
#19

Let me clarify the technical side. Start with a small trial; don't commit to everything at once.

If I were you, I'd go this route.

KKader G***Member
Job title
Clinic manager
Sector
Retail
Organization type
chain store
Joined
Mar 2024
Message
93

Doki · Backup setup · 2023

#20

Let me summarize what's been said so far. Everyone rushing into database backup encryption gets stuck at the same point.

Hope this helps.

Reply