Retention periods

How long may you keep data? The GDPR gives no figure, only a standard: no longer than necessary. Hard periods do exist, but they come from other statutes.

Legal basis

Article 5(1)(e) GDPR contains the storage limitation principle: personal data may not be kept in a form permitting identification for longer than is necessary for the purposes of the processing. What is necessary is for the controller to determine and to be able to justify. The fixed periods come from elsewhere. Article 52 of the State Taxes Act requires businesses to keep their records for seven years, extended to ten years for data concerning immovable property. Payroll records must be kept for five years after the employment ends. Where a statutory retention duty applies, it takes precedence over a request for erasure.

How it works in practice

This only becomes workable with a retention schedule: a period, a basis and an owner for each category of data, with a periodic clean-up that actually runs. For recruitment data four weeks after the process closes is the usual practice, or a year with the candidate’s consent. For camera footage the Dutch data protection authority works with four weeks, absent a specific incident.

Where it goes wrong

Three points recur. First, backups and archives, which stay outside the schedule and sit there for years. Second, confusion between the tax retention duty and the GDPR, leading to everything being kept for seven years. Third, using old files for new purposes, which requires a legal basis of its own.

Related terms

Retention periods connect to data subject rights, to the personal data breach and to the data processing agreement.

Want your retention policy in order? Our IT lawyers draw up the schedule.