Skip to content
Topic Contested in court

Retention Period

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

The duration for which personal data may be stored

596 linked items 5 Laws67 Case Law71 Guidance397 Enforcement15 News

Overview

19 sources · Jul 23, 2026

Legal Framework

The primary governing provision for retention periods is Article 5(1)(e) GDPR, which establishes the storage limitation principle. Personal data must be kept in a form permitting identification of data subjects only for as long as necessary for the purposes of processing. This is complemented by Article 5(1)(c) (data minimisation), which requires that data be "adequate, relevant and limited to what is necessary," and by Article 25(2) GDPR, which extends data-protection-by-default to "the period of their storage."

The core requirement is purpose-bound: the retention period must be calibrated to the specific purpose for which data are processed. Once that purpose is exhausted, erasure or anonymisation must follow.

"kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed"
— GDPR Art. 5(1)(e)

Article 5(1)(e) also carves out a narrow exception: longer retention is permitted solely for archiving in the public interest, scientific or historical research, or statistical purposes, provided Article 89(1) safeguards apply. Article 47(2)(d) GDPR reinforces this by requiring that binding corporate rules specify "limited storage periods."

Key Developments

The CJEU's ruling in Digital Rights Ireland established that blanket retention periods — undifferentiated across data categories or user types — fail to meet proportionality requirements. The Court criticised Directive 2006/24 for imposing a minimum six-month retention period without distinguishing between categories based on usefulness.

"Article 6 of Directive 2006/24 requires that those data be retained for a period of at least six months, without any distinction being made between the categories of data"
— Digital Rights Ireland, ¶63

The Court further found that the directive failed to "ensure the irreversible destruction of the data at the end of the data retention period," underscoring that retention limits are meaningless without enforceable erasure obligations.

The Dutch Council of State (Raad van State) addressed retention in the context of government email preservation, holding that a municipality could safeguard a mayor's deleted emails to prevent premature destruction under the Archiefwet — illustrating how sectoral archival legislation interacts with data-protection storage limits.

The EDPB's breach notification guidelines confirm that even documentation of personal data breaches has no fixed retention period under the GDPR; controllers must self-determine an appropriate period "in accordance with the principles in relation to the processing of personal data."

Status of the Debate

Retention period is actively contested in litigation. Courts have diverged on how to calibrate storage limits across contexts — from telecommunications metadata to government emails to breach records. The fundamental principle (purpose-bound, minimised retention) is settled, but its application to specific sectors and data categories remains in flux. No uniform court-driven threshold exists for how long particular categories of data may be kept. What would resolve the open questions is further CJEU guidance on proportionality testing for sector-specific retention mandates, particularly where national archival laws intersect with GDPR storage limitation.

Practical Guidance

  • Define purpose-specific retention schedules. Map each processing purpose to a maximum retention period, grounded in Article 5(1)(e). Avoid blanket periods that fail to distinguish between data categories or user types, as criticised in Digital Rights Ireland.
  • Implement automated erasure or anonymisation. Configure technical measures under Article 25(2) so that default storage periods are enforced systemically, not left to ad hoc human decision-making.
  • Document the rationale for each retention period. Record why a specific duration is necessary for the stated purpose — this is essential for demonstrating compliance and defending against regulatory challenge.
  • Ensure irreversible destruction at end of period. As the CJEU stressed, retention limits require enforceable erasure; partial or reversible deletion is insufficient.
  • Check sectoral archival laws. Where national legislation (e.g., the Archiefwet) mandates longer retention, confirm that the Article 89(1) safeguards — particularly pseudonymisation and data minimisation — are applied to the extended retention.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
Guidelines 3/2019 processing of personal data through video devices Guidelines ·EDPB Guidance EDPB Jan 2020 Storage limitation principle
why this is here
In some cases it might be necessary to use black box solutions where the footage is automatically deleted after a certain storage period

Discusses storage duration and deletion of footage, relating to retention and storage limitation.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 01/2022 data subject rights - Right of access Guidelines ·EDPB Guidance EDPB Apr 2023 Data storage in relation to access
why this is here
Wher e data is stored only for a very short period, there must be measures to guarantee that a request for access can be fulfilled without the data being erased

Mentions storage duration only in the context of ensuring access requests can be fulfilled before erasure.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 5/2019 criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1) Guidelines ·EDPB Guidance EDPB Jul 2020 Retention periods relevant to necessity assessment
why this is here
Consequently, the original retention periods of personal data, when available, should also be considered by Supervisory Authorities when they conduct their analysis of delisting requests pursuant to Article 17.1.a GDPR.

The document mentions retention periods as a factor in assessing whether data are no longer necessary, but does not focus on storage limitation as a principle.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

CJEU: PNR Directive Valid if Limited to the “Strictly Necessary” > In a landmark ruling of 21 June 2022, the CJEU (Grand Chamber), upheld the EU’s regime to collect and use records of travellers, provided that it is strictly interpreted in line… News eucrim Aug 2022 Retention period limits
why this is here
retention of all passengers subject to the PNR system complies with the requirement of "strict necessity" only during the initial six months

The judgment explicitly addresses retention periods for PNR data, distinguishing between six months for all passengers and up to five years for targeted individuals, making this a primary source.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Health data and use of cookies: DOCTISSIMO fined €380,000 Background information Following a complaint by the PRIVACY INTERNATIONAL association, the CNIL carried out four investigations into DOCTISSIMO. The doctissimo.fr website mainly… News CNIL May 2023 retention periods for test data
why this is here
The company kept data relating to the tests carried out by Internet users for 24 months, then 3 months, from their completion.

The core violation is excessive data retention, which is the subject of the storage limitation principle.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

CJEU clarifies GDPR principles of purpose limitation and storage limitation ⇄ The purpose limitation principle does not preclude a controller from capturing and storing in a test database established for testing and error correction purposes personal data… News NL EU Court Expert Oct 2022 storage limitation principle
why this is here
de testdatabank na de uitvoering van de nodige tests en de oplossing van de problemen niet onmiddellijk had gewist, waardoor een groot aantal in deze testdatabank opgeslagen persoonsgegevens bijna anderhalf jaar zonder doel was bewaard

The case involves a retention period issue, but the document focuses on the CJEU's interpretation of storage limitation, not a specific retention policy.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Collection and retention, by the French blood donation service (EFS), of personal data reflecting applicant’s presumed sexual orientation without proven factual basis: violation of Article 8 of the Convention News ECHR Sep 2022 Retention period of personal data
why this is here
the data retention period had to be limited to what was necessary

The document mentions the retention period as a factor, but the core issue is collection and retention of sensitive data, not a general retention period principle.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 67 Case Law · all 71 Guidance · all 397 Enforcement · all 40 Literature