LinkedInInstagramXTikTok

Data retention and secure deletion under the GDPR: how long can you keep personal data?

Why retention is a compliance risk

Many companies treat data as something you simply accumulate. Under the GDPR, that instinct is a liability. Every record you hold is data you must protect, could be asked to disclose, and might expose in a breach. The storage-limitation principle in Article 5(1)(e) requires you to keep personal data in identifiable form no longer than necessary for the purpose you collected it for. In other words, deletion is not optional housekeeping – it is a legal obligation.

How long is “no longer than necessary”?

The GDPR deliberately sets no universal retention period, because necessity depends on purpose. The workable approach is to define retention per category of data and per purpose, anchored to a justification. Some periods are set by other laws: in Sweden, the Bookkeeping Act requires accounting records to be kept for seven years, and employment and tax rules impose their own minimums. Where no statute applies, you set a reasonable period based on how long the data genuinely serves its purpose – and you document why.

Building a retention schedule

A retention schedule is the backbone of compliant retention. It lists each category of personal data, the purpose, the lawful basis, the retention period and the trigger for deletion or anonymisation. The trigger matters: “three years after the end of the customer relationship” is auditable, whereas “a few years” is not. The schedule should cover every system, including backups, email archives and spreadsheets that quietly hold personal data outside the main database.

Secure deletion and anonymisation

Deletion must be effective. Moving a file to a recycle bin or flagging a record as inactive is not erasure if the data remains recoverable and usable. Depending on the medium, secure deletion may mean overwriting, cryptographic erasure or physical destruction. Backups deserve special thought: you are not always required to hunt through every backup immediately, but you must have a defensible policy for how deleted data ages out of backup cycles.

Anonymisation is a powerful alternative. If data is irreversibly anonymised so that no individual can be re-identified, it falls outside the GDPR and can be retained for analytics. The bar is high, though – pseudonymised data that can be linked back with a key is still personal data.

Practical example

A Swedish online retailer keeps every customer account indefinitely. After a review it builds a schedule: order and invoice data is retained seven years for accounting law, then deleted; marketing profiles are deleted three years after the last interaction unless the customer re-engages; abandoned sign-ups with no purchase are removed after twelve months. Automated jobs enforce each rule, and the retailer documents the reasoning. When a customer later exercises the right to erasure, the retailer can explain exactly what it holds and why.

Common mistakes companies make

The biggest is keeping everything “just in case”, with no schedule at all. Others confuse the seven-year accounting rule with a licence to keep all data for seven years, when it only covers accounting records. Companies forget backups, shadow copies and old email when they delete, so data they believe is gone resurfaces in a breach or an access request. And many rely on manual deletion that never actually happens.

Recommended actions

Map where personal data lives, including secondary stores. Draft a retention schedule tied to purposes and legal minimums, and have it reviewed so the periods are defensible. Automate deletion and anonymisation wherever possible, and set a backup-ageing policy. Communicate retention periods in your privacy notice, and review the schedule annually. Treat a data subject’s erasure request as a test of whether your retention framework actually works.

Frequently asked questions

Can we keep data forever if we got consent?

No. Consent does not override storage limitation. You still need to delete once the purpose has ended, and consent can be withdrawn at any time.

Does the seven-year rule apply to all our data?

No. It applies to accounting records under the Bookkeeping Act. Other data has its own necessity-based period, which is often much shorter.

Is anonymised data still subject to the GDPR?

Only if it can be re-identified. Truly irreversible anonymisation takes data outside the GDPR; pseudonymisation does not.

Conclusion

Under the GDPR, holding data you no longer need is not a convenience – it is exposure. A clear retention schedule and reliable secure-deletion process reduce your breach surface, cut storage cost and make access and erasure requests straightforward to answer. Lawgent helps businesses build retention schedules and deletion policies that satisfy the storage-limitation principle while respecting Swedish accounting and employment law – so you keep what you must and delete what you should.

0Cart0,00 

No products in the cart.

Return to shop