This bugged me too last year. So I built a hosting service for Borg backups that can have append-only access keys.
So the client machine can't change old backups. Ever. In addition you can lock your settings down with 2FA.
So the client machine can't change old backups. Ever. In addition you can lock your settings down with 2FA.
How do you store the data on your end?
The actual data lies on a plain vanilla RAID array.
Also: you still need to keep some data even under GDPR. Like billing data.