Why is this important?
The GDPR requires you to keep identifiable personal data no longer than necessary for the purposes for which you process it (Article 5(1)(e)). It does not provide a universal retention timetable for businesses.
You must be able to explain why you still hold particular data. A documented policy helps demonstrate compliance only if you apply it in practice. Keeping information because storage is cheap, or because it might be useful one day, is not enough.
How to determine retention periods
Use the table below as a decision guide, not a list of standard legal periods. Check the local legislation and supervisory guidance applicable to your activities.
| Data type | What determines the period? | Practical action |
|---|---|---|
| Accounting documents | Applicable statutory requirements for particular documents | Check the required period and its starting point; do not apply it to the entire customer file. |
| Personnel data | The purpose and legal requirements for each category | Set separate periods for payroll, administration, assessments and other records. |
| Unsuccessful applicants’ data | Recruitment, justified evidence retention or a separate talent-pool purpose | Distinguish these purposes and establish the appropriate legal basis and period for each. |
| Customer data during the relationship | What remains necessary to deliver the service and meet relevant obligations | Review outdated or unnecessary information even while the customer remains active. |
| Customer data after the relationship | Specific legal obligations or another justified purpose, such as legal claims | Retain only what that purpose requires, with restricted access where appropriate. |
| CCTV footage | The security purpose and applicable local rules | Choose a short, justified period; isolate relevant incident footage only where further retention is justified. |
| Website analytics | The measurement purpose, data collected and applicable cookie and tracker rules | Minimise identifiable data and review retention settings; a vendor default is not a legal justification. |
| Contact form submissions | The request and any necessary follow-up | Distinguish an enquiry, a contract request and a complaint; delete what is no longer needed. |
| Newsletter subscribers | A valid basis for sending and continued necessity | Review inactive records; consent does not justify indefinite retention. |
Do not assign a legal basis solely by data type. A contact form may involve steps towards a contract at the person’s request, for example. Legitimate interests requires necessity and a favourable balancing assessment; it is not a default permission to keep data.
For recruitment, see how long you can keep a candidate’s CV and whether you need consent to keep it.
When someone unsubscribes, stop the newsletter. You may still need limited evidence of consent or a minimal suppression record to demonstrate past consent or respect the opt-out. Document the separate purpose, legal basis and necessary period; do not keep using those records for marketing.
How to create a retention policy
Step 1: Inventory your processing activities
Start with your processing register, then identify the data categories and systems used for each activity. Include shared folders, mailboxes, paper files, service providers and backups. One activity may need several retention rules.
Step 2: Determine the period per category and purpose
Ask yourself:
- Does a legal retention requirement apply, to which records and from which starting date?
- How long are these data actually necessary for the stated purpose?
- Is limited archiving needed for a legal obligation or legal claims?
- Does supervisory or sector guidance help justify the period in this situation?
A sector practice is a reference point, not automatic permission. Separate active use from restricted archiving. A possible dispute does not justify keeping the entire file indefinitely. If one record serves several purposes, ending one does not automatically require deletion of the information still lawfully needed for another, but it does end the use that is no longer justified.
Step 3: Document your choices
Record:
- Data category, purpose and legal basis
- Retention period and the event that starts it, such as closure of a request
- Applicable requirement or reason for the chosen period
- Responsible person, systems and service providers concerned
- Action at expiry, including deletion or effective anonymisation
- Any justified exception, its scope, restricted access and review date
Explain the periods, or criteria where a period cannot be specified, in the relevant privacy information (Articles 13 and 14). Align this with your register and arrangements with service providers.
Step 4: Implement and monitor
Use reminders or automatic deletion where appropriate, and check that deletion actually works across relevant systems. Review the policy periodically, for example annually, and when purposes, systems or applicable requirements change. A yearly review is a practical recommendation, not a universal GDPR deadline.
Include a documented deletion or overwrite schedule for backups. If immediate selective deletion is not feasible, assess and document a limited, protected backup cycle and prevent ordinary use of data awaiting deletion. Ensure a restore does not put previously deleted data back into active use. UK ICO guidance describes this practical approach; it is not a blanket exemption under EU law.
Common mistakes
- Treating a chosen period as permission to keep everything: review necessity throughout the period and assess erasure requests on their merits.
- Confusing active files with archives: restrict archived evidence to its justified purpose and authorised users.
- Calling coded data anonymous: replacing names with identifiers is usually pseudonymisation. The GDPR still applies if people remain identifiable. Effective anonymisation must prevent identification in practice, including through reasonably available additional information.
- Relying on a policy without implementing it: keep proportionate evidence of reviews and deletion without retaining the deleted content itself.
- Letting exceptions become permanent: record why deletion is suspended, limit the affected records and review when the reason ends.
GDPRWise helps you set the right retention period for each processing activity and reminds you when data needs to be deleted.