How long data may stay
The GDPR names no periods. It names a principle: no longer than necessary. Turning that into a number is the actual work – and the point at which a deletion policy either comes into being or does not.
Storage limitation is one of the six principles in Article 5. It says that personal data may be kept in a form permitting identification only for as long as the purpose requires.
From this follows the key sentence on the subject: the period derives from the purpose, not from convenience. And because different data serves different purposes, there is no single period for "customer data" but one per purpose.
Common periods and where they come from
How a period gets its reasoning
Four questions per kind of data
- What were these data collected for?One purpose per kind of data. Several purposes mean several periods for the same kind.
- When is that purpose fulfilled?The moment the data is no longer needed for its original reason – usually an event, not a date.
- Does a law require longer retention?Tax and commercial law above all. But the duty covers the record itself, not the entire dataset.
- When does the period start running?Commercial and tax periods start at the end of the calendar year – which turns ten years into as many as eleven.
The practical part: the deleting itself
- A policy without execution is worthless. Periods nobody triggers extend silently to infinity.
- Automatic beats manual. A nightly job removing expired records is more reliable than an annual reminder.
- The run belongs in a log – not with the deleted data but with time and count. That is the evidence the policy is alive.
- Secondary stores count too: search indexes, caches, export files, mailboxes. They regularly survive deletion in the database.