Skip to content
Security calendar_today Updated: 29 September 2026 schedule 5 min read

Data Retention: How Long May You Keep Personal Data?

verified Last reviewed 29 September 2026 · GDPRWise legal team

Set justified retention periods for personal data, distinguish active use from archiving, and put deletion into practice with a clear data retention policy.

summarize Key Takeaways
  • check_circle Set retention periods by data category and purpose, taking account of applicable legal requirements.
  • check_circle Record when each period starts, who is responsible and what happens at expiry.
  • check_circle Separate active use from justified, restricted archiving and implement deletion across systems.
  • check_circle Consent and a written policy do not justify indefinite retention; review necessity and put the policy into practice.

Why is this important?

The GDPR requires you to keep identifiable personal data no longer than necessary for the purposes for which you process it (Article 5(1)(e)). It does not provide a universal retention timetable for businesses.

You must be able to explain why you still hold particular data. A documented policy helps demonstrate compliance only if you apply it in practice. Keeping information because storage is cheap, or because it might be useful one day, is not enough.

How to determine retention periods

Use the table below as a decision guide, not a list of standard legal periods. Check the local legislation and supervisory guidance applicable to your activities.

Data typeWhat determines the period?Practical action
Accounting documentsApplicable statutory requirements for particular documentsCheck the required period and its starting point; do not apply it to the entire customer file.
Personnel dataThe purpose and legal requirements for each categorySet separate periods for payroll, administration, assessments and other records.
Unsuccessful applicants’ dataRecruitment, justified evidence retention or a separate talent-pool purposeDistinguish these purposes and establish the appropriate legal basis and period for each.
Customer data during the relationshipWhat remains necessary to deliver the service and meet relevant obligationsReview outdated or unnecessary information even while the customer remains active.
Customer data after the relationshipSpecific legal obligations or another justified purpose, such as legal claimsRetain only what that purpose requires, with restricted access where appropriate.
CCTV footageThe security purpose and applicable local rulesChoose a short, justified period; isolate relevant incident footage only where further retention is justified.
Website analyticsThe measurement purpose, data collected and applicable cookie and tracker rulesMinimise identifiable data and review retention settings; a vendor default is not a legal justification.
Contact form submissionsThe request and any necessary follow-upDistinguish an enquiry, a contract request and a complaint; delete what is no longer needed.
Newsletter subscribersA valid basis for sending and continued necessityReview inactive records; consent does not justify indefinite retention.

Do not assign a legal basis solely by data type. A contact form may involve steps towards a contract at the person’s request, for example. Legitimate interests requires necessity and a favourable balancing assessment; it is not a default permission to keep data.

For recruitment, see how long you can keep a candidate’s CV and whether you need consent to keep it.

When someone unsubscribes, stop the newsletter. You may still need limited evidence of consent or a minimal suppression record to demonstrate past consent or respect the opt-out. Document the separate purpose, legal basis and necessary period; do not keep using those records for marketing.

How to create a retention policy

Step 1: Inventory your processing activities

Start with your processing register, then identify the data categories and systems used for each activity. Include shared folders, mailboxes, paper files, service providers and backups. One activity may need several retention rules.

Step 2: Determine the period per category and purpose

Ask yourself:

  • Does a legal retention requirement apply, to which records and from which starting date?
  • How long are these data actually necessary for the stated purpose?
  • Is limited archiving needed for a legal obligation or legal claims?
  • Does supervisory or sector guidance help justify the period in this situation?

A sector practice is a reference point, not automatic permission. Separate active use from restricted archiving. A possible dispute does not justify keeping the entire file indefinitely. If one record serves several purposes, ending one does not automatically require deletion of the information still lawfully needed for another, but it does end the use that is no longer justified.

Step 3: Document your choices

Record:

  • Data category, purpose and legal basis
  • Retention period and the event that starts it, such as closure of a request
  • Applicable requirement or reason for the chosen period
  • Responsible person, systems and service providers concerned
  • Action at expiry, including deletion or effective anonymisation
  • Any justified exception, its scope, restricted access and review date

Explain the periods, or criteria where a period cannot be specified, in the relevant privacy information (Articles 13 and 14). Align this with your register and arrangements with service providers.

Step 4: Implement and monitor

Use reminders or automatic deletion where appropriate, and check that deletion actually works across relevant systems. Review the policy periodically, for example annually, and when purposes, systems or applicable requirements change. A yearly review is a practical recommendation, not a universal GDPR deadline.

Include a documented deletion or overwrite schedule for backups. If immediate selective deletion is not feasible, assess and document a limited, protected backup cycle and prevent ordinary use of data awaiting deletion. Ensure a restore does not put previously deleted data back into active use. UK ICO guidance describes this practical approach; it is not a blanket exemption under EU law.

Common mistakes

  • Treating a chosen period as permission to keep everything: review necessity throughout the period and assess erasure requests on their merits.
  • Confusing active files with archives: restrict archived evidence to its justified purpose and authorised users.
  • Calling coded data anonymous: replacing names with identifiers is usually pseudonymisation. The GDPR still applies if people remain identifiable. Effective anonymisation must prevent identification in practice, including through reasonably available additional information.
  • Relying on a policy without implementing it: keep proportionate evidence of reviews and deletion without retaining the deleted content itself.
  • Letting exceptions become permanent: record why deletion is suspended, limit the affected records and review when the reason ends.
auto_awesome Track retention periods automatically?

GDPRWise helps you set the right retention period for each processing activity and reminds you when data needs to be deleted.

Share share LinkedIn mail Email
GW
GDPRWise Editorial

This article was written by the GDPRWise team and reviewed by our privacy experts. We regularly review our content for accuracy and legal correctness.