Skip to content
Topic Contested in court

Storage Limitation

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Principle that data should not be kept longer than necessary

228 linked items 1 Laws42 Case Law55 Guidance96 Enforcement17 News

Overview

19 sources · Jul 23, 2026

Legal Framework

Storage limitation is codified in Article 5(1)(e) GDPR, which requires that personal data be:

"kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed"
— GDPR Art. 5(1)(e)

The provision carves out a narrow exception: longer retention is permitted only for archiving in the public interest, scientific or historical research, or statistical purposes under Article 89(1). The principle operates alongside Article 5(1)(c) (data minimisation) and Article 5(1)(d) (accuracy), forming an interlocking lifecycle framework.

The AI Act reinforces this at the system level. Article 17(1)(f) AI Act requires providers of high-risk AI systems to implement documented procedures covering "data retention" as part of their quality management system. Article 10 further requires governance over data preparation operations, implicitly tying retention to the system's intended purpose.

Key Developments

The CJEU's ruling in Digital Rights Ireland established that retention regimes must guarantee not only a defined endpoint but also effective erasure. The Court found that the Data Retention Directive failed because it:

"does not ensure the irreversible destruction of the data at the end of the data retention period."
— Digital Rights Ireland, ¶67

This sets a baseline: a retention period without enforceable destruction is legally deficient.

Dutch courts have grappled with retention in practice. In the Gemeente Weert case, the Raad van State upheld a municipality's preservation of a mayor's deleted emails, balancing storage limitation against obligations under the Archiefwet and the Woo — retention beyond the functional deletion point was justified where archival and transparency duties required it. Conversely, in the Beekdaelen case, a court confronted the opposite problem: log files were destroyed under a supplier's retention policy before an individual could identify who had accessed her data, illustrating how premature erasure can itself undermine data-subject rights.

The EDPB has confirmed that the GDPR deliberately leaves retention periods to controller determination:

"The GDPR does not specify a retention period for such documentation. Where such records contain personal data, it will be incumbent on the controller to determine the appropriate period of retention in accordance with the principles in relation to the processing of personal data"
— EDPB Guidelines 9/2022, §124

Status of the Debate

This topic is actively contested in court. The core principle — that data must not be kept longer than necessary — is settled. What remains disputed is the calibration: how long is "necessary" for a given purpose, and how retention interacts with conflicting legal obligations such as archival law, transparency duties, and evidentiary preservation. The Gemeente Weert and Beekdaelen cases illustrate opposite sides of this tension. No definitive court split is on record yet, but the boundaries are being fought case by case. A CJEU reference clarifying the interplay between GDPR storage limitation and sectoral retention mandates (archival, financial, law enforcement) would resolve the open question.

Practical Guidance

  • Define purpose-specific retention periods: Map each processing purpose to a concrete retention timeframe in your records of processing activities under Article 30. Generic "as long as necessary" policies are insufficient.
  • Implement automated erasure: Destruction at the end of a retention period must be irreversible — Digital Rights Ireland sets this as a minimum standard. Relying on supplier-managed deletion without verification (as in Beekdaelen) creates compliance gaps.
  • Reconcile conflicting obligations: Where sectoral law (e.g., Archiefwet, tax law) mandates longer retention, document the legal basis and ensure the stored data is access-restricted to the archival purpose only.
  • For AI systems, integrate retention into the QMS: Under Article 17(1)(f) AI Act, document data retention procedures as part of the quality management system, tied to the system's intended purpose and lifecycle.
  • Review retention policies when purposes change: If a processing purpose evolves or ceases, the retention period must be recalculated — the original timeframe does not automatically carry over.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
Guidelines 3/2019 processing of personal data through video devices Guidelines ·EDPB Guidance EDPB Jan 2020 Storage limitation principle
why this is here
the footage is automatically deleted after a certain storage period

Discusses deletion after a storage period, directly relating to storage limitation.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 01/2022 data subject rights - Right of access Guidelines ·EDPB Guidance EDPB Apr 2023 Data storage duration in access context
why this is here
Wher e data is stored only for a very short period, there must be measures to guarantee that a request for access can be fulfilled without the data being erased

The document mentions storage duration only to ensure access can be provided before erasure.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

CJEU Clarifies Exceptions to Data Retention in Irish Case > On 5 April 2022, the CJEU added another chapter to the long history of the admissibility of data retention in the EU. In a case concerning the data retention law in Ireland, the… News eucrim Aug 2022 data retention limits
why this is here
general and indiscriminate retention of traffic and location data relating to electronic communication is contrary to Union law

The document directly addresses the principle of storage limitation by discussing the permissible and impermissible retention periods for traffic and location data.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

CJEU: PNR Directive Valid if Limited to the “Strictly Necessary” > In a landmark ruling of 21 June 2022, the CJEU (Grand Chamber), upheld the EU’s regime to collect and use records of travellers, provided that it is strictly interpreted in line… News eucrim Aug 2022 Retention of PNR data
why this is here
A retention up to five years (as indicated in Art. 12(1) of the PNR Directive) is only allowed for data on air passenger if objective evidence revealed a possible involvement in terrorist offences or serious crime

The document directly addresses the storage limitation principle by setting constraints on how long PNR data may be kept.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Health data and use of cookies: DOCTISSIMO fined €380,000 Background information Following a complaint by the PRIVACY INTERNATIONAL association, the CNIL carried out four investigations into DOCTISSIMO. The doctissimo.fr website mainly… News CNIL May 2023 excessive retention of test data
why this is here
The company kept data relating to the tests carried out by Internet users for 24 months, then 3 months, from their completion.

The core violation is keeping data longer than necessary, which is the essence of storage limitation.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Respondent has no right to erasure of personal data Hague Court of Appeal February 3, 2023, IT 4226; ECLI:NL:GHDHA:2023:306 (Veilig Thuis v. the respondent) In this case, a man requested the deletion of his personal data processed… News IT en Recht Mar 2023 retention for ex-partner's interest
why this is here
retention of the data may be of interest to the man's ex-partner

Justifies retention beyond the data subject's request, implicating storage limitation principle.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Collection and retention, by the French blood donation service (EFS), of personal data reflecting applicant’s presumed sexual orientation without proven factual basis: violation of Article 8 of the Convention News ECHR Sep 2022 Data retention period criticism
why this is here
the data retention period had to be limited to what was necessary

The judgment mentions retention limitation, but it is secondary to the lack of factual basis for the data.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 42 Case Law · all 55 Guidance · all 96 Enforcement