How Long Can I Keep Personal Data Under GDPR?
GDPR doesn't set a fixed retention period, it requires you to justify one. Here's how the storage limitation principle actually works and how to set defensible retention periods.
There’s no single number in GDPR that answers “how long can I keep personal data,” no universal 90-day or 2-year rule that applies across the board. Instead, GDPR’s storage limitation principle (Article 5(1)(e)) requires that personal data be kept “no longer than is necessary for the purposes for which it is processed.” That’s a standard you have to apply and justify per category of data, not a number you look up once.
What “necessary for the purpose” actually means
The retention period has to be tied to why you collected the data in the first place, one of the seven core GDPR principles covered in our GDPR principles guide. Once the purpose is fulfilled and no other lawful basis (like a legal retention obligation) applies, you’re required to delete or anonymize the data, not keep it indefinitely “just in case.”
Some categories have retention periods effectively set by other laws, not GDPR directly:
- Tax and accounting records: most EU countries require 6-10 years by tax law, this legal obligation basis overrides GDPR’s general “delete when done” default for that specific data.
- Employment records: often subject to country-specific labor law minimums.
- Signed contracts: typically retained for the statute of limitations period on contract disputes in the relevant jurisdiction.
Where no other law sets a floor, you set the period yourself, and you need to be able to justify it.
Data with no clear legal retention requirement
This is where most businesses actually struggle, marketing lists, website analytics data, customer support tickets, abandoned account data. Common defensible approaches:
- Marketing contacts: retain until consent is withdrawn or a defined period of inactivity (e.g., 2-3 years with no engagement) passes, at which point re-obtain consent or delete.
- Analytics data: GA4 itself lets you configure retention (2 or 14 months for user-level data); shorter periods are generally easier to defend as “necessary” than the maximum setting, especially for identifiers tied to individuals.
- Support tickets: often retained for a defined period tied to warranty/support obligations, then deleted or anonymized.
- Inactive accounts: a defined dormancy period (varies by business) after which accounts and associated data are deleted or anonymized if there’s no ongoing relationship or legal reason to keep them.
The mistake that shows up most in enforcement actions
Regulators have specifically flagged businesses that keep personal data indefinitely by default, “we might need it someday” is not a valid justification under the storage limitation principle. If you can’t articulate why a specific retention period is necessary for a specific purpose, that’s a sign the period (or the absence of one) won’t hold up to scrutiny.
Enzuzo
Tracking a defensible, documented retention period for every category of data you hold, and actually enforcing deletion when it expires, is exactly the kind of ongoing governance work that's easy to let slide without a dedicated tool. Enzuzo bundles policy documentation with consent management in one dashboard, making it easier to keep retention schedules from quietly becoming 'forever' by default.
How this connects to your documentation obligations
Your retention periods (or the criteria used to determine them) are one of the required fields in your Records of Processing Activities. See our ROPA guide for the full documentation requirement, retention policy isn’t just an internal practice, it’s something you need to be able to produce if asked.
A practical starting checklist
- List every category of personal data you hold and the purpose it was collected for.
- Check whether another law sets a mandatory retention floor (tax, employment, contract law) for that category.
- Where no floor applies, set a specific period tied to the purpose, not “indefinitely” or “as long as useful.”
- Build actual deletion into your systems, a documented policy that isn’t technically enforced doesn’t protect you if an audit finds five-year-old data sitting past its stated retention period.
This guide is educational and not legal advice. Appropriate retention periods vary by data category, jurisdiction, and applicable sector-specific laws; consult a privacy attorney for your specific retention schedule.