GDPR data retention: how long can you keep personal data?

EXECUTIVE SUMMARY

The regulation with no numbers

GDPR never tells you how long to keep personal data. It tells you to know.

Ask how long personal data can be kept under GDPR and there is no table to look it up in. The regulation sets a principle instead: storage limitation. Personal data may be kept no longer than necessary for the purpose it was collected for – and the organisation, not the regulator, must decide what that means, write it down, and act on it.

That makes GDPR data retention a policy problem and a systems problem at once. This paper sets out what the regulation actually requires, why legacy systems are where retention policies quietly fail, and how to keep the records the law demands while deleting the data it forbids you to hoard.

THE PROBLEM

What GDPR actually requires

Storage limitation is one of GDPR’s core principles: personal data must be kept in a form that identifies people for no longer than the purpose requires. The ICO’s guidance is blunt about what that means in practice – set retention periods, justify them, review what you hold, and erase or anonymise what is no longer needed. Keeping data indefinitely “just in case” is not an acceptable answer.

Alongside the principle sits the right to erasure: individuals can require their personal data to be deleted when there is no overriding reason to keep it. And the enforcement ceiling is serious – breaches of the principles carry the upper tier of GDPR fines, up to €20 million or 4% of worldwide annual turnover, whichever is higher.

None of this abolishes retention duties. Finance records still sit on their six-year tax clock in the UK and longer in some jurisdictions, batch records on theirs – GDPR simply insists those clocks are real: defined by category, documented, and followed by actual deletion when they run out.

The numbers

What the rulebook gives you

0   fixed retention periods are written into GDPR – every period is yours to define and justify

€20m / 4%   the upper tier of GDPR fines: €20 million or 4% of worldwide turnover, whichever is higher

6 years   a typical tax-law floor that personal data inside finance records must still respect

The result is a two-sided obligation. Retention schedules must be long enough for the records the law makes you keep – and no longer than that for the personal data inside them.

The trap

Legacy systems: where retention policies go to die

 

Most organisations have a retention policy. Far fewer can execute it, because the data the policy governs lives in systems that predate it. A subject access request must be answered from every system that holds the person’s data – including the ERP retired from active use many years ago. An erasure request must be honoured in applications that were never designed to delete anything. And a regulator can ask why personal data with no remaining purpose is still on a server at all.

“The policy says delete after seven years. The system says: delete what, exactly?”

Targeted disposal in a legacy system is close to impossible: one person’s data is scattered across undocumented tables with poor reporting, with no approval workflow and no audit trail to evidence the deletion afterwards. So nothing is deleted, the estate keeps running, and the exposure compounds – on infrastructure the business is also paying for.

THE SOLUTION

Retention you can actually execute

The way out is to move the records into a store where the policy is enforceable – such as Cella – and switch the legacy systems off. Extracted into a governed platform, the data an organisation must keep stays accessible and reportable; the personal data it must not hoard becomes deletable, provably, for the first time.

  • Retention rules per category. Each record class keeps to its own clock – defined once, applied automatically, documented for the regulator.
  • Right-to-erasure requests. Personal data can be located and disposed of, with the outcome evidenced.
  • Governed deletion. Disposal runs through an approval workflow with dual 4-eye verification and a full audit trail – deletion as a controlled event, not a hope.
  • Legal hold. Records under litigation or investigation are held past their scheduled disposal until the hold is lifted – the exception managed, not improvised.

This is the disposal half of information lifecycle management – the same discipline that keeps records for their statutory floors, covered in our companion paper on data retention in regulated industries, applied to the data you are required to let go.

Getting started

From policy on paper to policy in practice

Getting started

Start by mapping the retention schedule against the systems that actually hold personal data. The gap list creates risk: categories with no enforceable period, systems that cannot delete, personal data whose purpose expired years ago. Those systems are usually also expensive to run – which makes the compliance fix and the cost case a strong business case for the same project.

Talk to our team about disposing of legacy data compliantly – retention rules, legal hold and audited deletion – while cutting the systems that made it impossible.

Written by Cella Software