NetApp Cloud Backup DataLock protects backup data from ransomware and unauthorized modifications by leveraging Write Once Read Many (WORM) immutability capabilities in object storage. It integrates with cloud providers' native object-lock technologies and on-premises NetApp StorageGRID to prevent deletion or alteration of backup copies during configurable retention periods. The solution offers multiple retention modes including Governance, Compliance/Azure Locked, and Unlocked options to meet various regulatory and operational requirements. It works with NetApp SnapLock to maintain immutability from ONTAP source volumes through object-storage backups, and includes automated ransomware scanning to detect compromised backups. The lock duration combines backup policy schedules with a 31-day buffer and supports AWS S3, Azure Blob, and StorageGRID destinations. While the system requires ONTAP 9.11.1+ for basic functionality and 9.13.1+ for FlexGroup volumes, it does have some limitations including incompatibility with archival-tiered backups and requires uniform DataLock mode application across all cluster policies.