GDPR never tells you how long to keep personal data. It tells you to know.
Ask how long personal data can be kept under GDPR and there is no table to look it up in. The regulation sets a principle instead: storage limitation. Personal data may be kept no longer than necessary for the purpose it was collected for – and the organisation, not the regulator, must decide what that means, write it down, and act on it.
That makes GDPR data retention a policy problem and a systems problem at once. This paper sets out what the regulation actually requires, why legacy systems are where retention policies quietly fail, and how to keep the records the law demands while deleting the data it forbids you to hoard.