Laws · GDPR ·art-5-par-1-pnt-e EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (‘storage limitation’);
How it connects
Cited by
- Italian DPA sanctions Municipality of Policoro for CCTV signage, retention and DPO
- Guidelines 05/2020 on consent under Regulation 2016/679
- Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020
- Guidelines 01/2022 on data subject rights - Right of access
- Guidelines 9/2022 on personal data breach notification under GDPR
All 35
- EDPB Annual Report 2024
- SO Warszawa: Controller warned for violating GDPR Arts. 5(1), 6(1), and 15(1)
- Coordinated Enforcement Action,
- Challenges of Cloud Data Privacy in Surveillance: Legal, Technical, and Ethical Implications
- Belgian DPA: Roularta Media Group violated cookie consent rules
- EDPB Annual Report 2025
- Opinion 11/2024 on the use of facial recognition to streamline airport passengers’ flow (compatibility with Articles 5(1)(e) and(f), 25 and 32 GDPR)
- Report of the work undertaken by the ChatGPT Taskforce
- EDPB Annual Report 2023
- Recommendations 1/2022 on the Application for Approval and on the elements and principles to be found in Controller Binding Corporate Rules (Art. 47 GDPR)
- EDPB Annual Report 2022
- EDPB Annual Report 2021
- EDPB-EDPS Joint Opinion 04/2021 on the Proposal for a Regulation of the European Parliament and of the Council on a framework for the issuance, verification and acceptance of interoperable certificates on vaccination, testing and recovery
- EDPB Document on response to the request from the European Commission for clarifications on the consistent application of the GDPR, focusing on health research
- Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak
- Maximilian Schrems v Meta Platforms Ireland Limited
- Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság
- Supreme Court - III CZP 78/19
- HDPA (Greece) - 7/2026
- Garante per la protezione dei dati personali (Italy) - 483/2026
- Garante per la protezione dei dati personali (Italy) - 484/2026
- DSB (Austria) - 2025-1.049.138
- Garante per la protezione dei dati personali (Italy) - 476/2026
- Italian DPA sanctions Top Secret Investigazioni for unjustified email forwarding after
- VG Hannover: Controller appeals DPA reprimand over unlawful workplace video surveillance
- Azienda Speciale per la Gestione degli Impianti Sportivi del Comune di Trento: Insufficient legal basis for data processing
- BVwG reduces DPA fine for undisclosed call recording from €25,500 to €22,000
- Finnish DPA finds 12-year retention of rental applicant data violates minimisation
- Austrian Federal Administrative Court: address publisher's data transfer and Article 15
- Icelandic DPA: City of Reykjavik cannot request bank statements from NPA disabled service
Related across sources
C-77/21 Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság In this preliminary ruling, the CJEU interpreted Articles 5(1)(b) and 5(1)(e) GDPR in proceedings between Digi Távközlési és Szolgáltató Kft. and the Hungarian National Authority… First Chamber Oct 20, 2022 Retention Period Storage Limitation Personal Data
C-175/20 SIA 'SS' v Valsts ieņēmumu dienests In Case C-175/20, the Court of Justice of the EU interpreted GDPR Articles 5 and 6 in response to a preliminary ruling from the Latvian Regional Administrative Court concerning a… Fifth Chamber Feb 24, 2022 Retention Period Personal Data Legitimate Interest
C-60/22 UZ v Bundesrepublik Deutschland In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik… Fifth Chamber May 4, 2023 Right to Restriction Right to be Forgotten Personal Data
C-231/22 État belge v Autorité de protection des données In Case C-231/22, the Court of Justice of the European Union interpreted Article 4(7) and Article 5(2) of the GDPR in response to a preliminary reference from the Brussels Court… Third Chamber Jan 11, 2024 Controllers Personal Data Public Authority
C-136/17 GC and Others v CNIL C-136/17 (GC and Others) Sep 24, 2019 Right to be Forgotten Legitimate Interest Criminal Data
C-638/23 Amt der Tiroler Landesregierung v Datenschutzbehörde In Case C-638/23, the Court of Justice interpreted Article 4(7) GDPR in response to a preliminary reference from the Austrian Verwaltungsgerichtshof in proceedings between the Amt… Eighth Chamber Feb 27, 2025 Public Authority Controllers Personal Data