EU Privacy Law EU/EEA

GDPR Data Retention Policies: Building Defensible Schedules by Data Category

How GDPR storage limitation works in practice: setting retention periods per data category, legal holds, deletion mechanics, and documenting the schedule.

Regulation

GDPR, Article 5(1)(e)

Max Penalty

EUR 20 million or 4% of global annual turnover, whichever is higher

Enforcing Authority

National supervisory authorities, coordinated by the EDPB

Official Source

eur-lex.europa.eu

Executive Summary

  • The storage limitation principle (Article 5(1)(e)) forbids keeping personal data in identifiable form longer than the purposes require.
  • GDPR sets almost no fixed retention periods itself; you derive them from purposes, national statutes, and limitation periods, and you must be able to defend each one.
  • Privacy notices must state retention periods or the criteria used to determine them (Articles 13(2)(a) and 14(2)(a)).
  • Retention failures are fined as principle violations, in the top tier: Deutsche Wohnen was fined EUR 14.5 million in 2019 for an archive that could not delete tenant data.
  • A schedule nobody executes is worse than none: regulators check whether deletion actually runs, not whether the policy document exists.

Storage limitation is the GDPR principle that data must go away when its job is done. Article 5(1)(e) permits keeping personal data in identifiable form only as long as necessary for the purposes, and Articles 13 and 14 force you to tell people the period, or at least the criteria, up front. The regulation gives almost no fixed numbers, which is precisely what makes retention hard: every period in your schedule needs a reason you can state out loud.

RegulationGDPR, Article 5(1)(e)
Max penaltyEUR 20M or 4% of global annual turnover
Enforcing authorityNational supervisory authorities, coordinated by the EDPB
Official textEUR-Lex CELEX 32016R0679

Deriving periods that hold up

Work each data category through three questions:

  1. What does the purpose require? Order data is needed while the order can be disputed or returned; a job application is needed until the role is filled plus a discrimination-claim window.
  2. What does law require you to keep? National tax and commercial codes set mandatory minimums, commonly 6 to 10 years for financial records. These are lawful-obligation retention, and they beat deletion requests for the covered records.
  3. What do limitation periods justify? Keeping contract data through the limitation period for claims is a recognized legitimate interest, but only for the data actually needed to defend a claim.

The output is a schedule per data category: the period, the justification, the trigger event (order completion, contract end, last activity), and the deletion mechanism.

Why enforcement happens

The instructive case is Deutsche Wohnen: Berlin’s authority fined the housing company EUR 14.5 million in 2019 because its archive system had no technical capability to delete tenant data, some of it years past any purpose. The lesson is that retention violations are usually architecture problems. Systems that only ever add records, CRM databases with no last-activity purge, and marketing lists that never decay all fail the principle regardless of what the policy document says.

Making deletion actually run

Assign each system an owner and a deletion mechanism: automated purges where the platform supports them, scheduled manual reviews where it does not, and a documented approach for backups. Test the mechanism the way you would test a backup restore, by verifying a record actually disappears end to end, including from search indexes and analytics exports. Log executions; the log is your evidence.

Two adjacent obligations complete the picture. Your privacy notice must disclose the periods or criteria, which is easy to check: run a free scan to see what your public policy currently says. And your records of processing must carry the envisaged periods per activity, so keep the ROPA and the retention schedule synchronized rather than maintaining two diverging documents.

Frequently Asked Questions

How long can I keep personal data under GDPR?

As long as necessary for the purposes it was collected for, and no longer (Article 5(1)(e)). GDPR rarely sets specific periods; you justify each one from the purpose, applicable statutes such as tax law, and limitation periods for legal claims.

Does GDPR require deleting data after a specific number of years?

No single number exists. Common anchors: tax records 6 to 10 years depending on the country, recruitment data for unsuccessful candidates around 6 months to 2 years, CCTV days to weeks, marketing data for the life of the consent plus a proof period.

Can I keep data forever if I anonymize it?

Yes, if the anonymization is real. Truly anonymous data is outside GDPR (recital 26). Pseudonymized data, where you or anyone else can re-link identities, remains personal data and stays subject to retention limits.

What about backups?

Deletion obligations extend to backups, but regulators accept practical approaches: exclude expired data on restore, let backup rotation age data out on a defined cycle, and document the mechanism. Indefinite backup retention with no deletion path is not defensible.

What is a legal hold and how does it interact with retention?

A documented suspension of deletion for data relevant to litigation or an investigation. It overrides the schedule for the affected records only, and it should be lifted, and deletion resumed, when the matter ends.

Regulatory Crosswalk

UK GDPRLGPDISO/IEC 27701

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.