Storage Limitation
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Principle that data should not be kept longer than necessary
Overview
19 sources · Jul 23, 2026Legal Framework
Storage limitation is codified in Article 5(1)(e) GDPR, which requires that personal data be:
"kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed"
— GDPR Art. 5(1)(e)
The provision carves out a narrow exception: longer retention is permitted only for archiving in the public interest, scientific or historical research, or statistical purposes under Article 89(1). The principle operates alongside Article 5(1)(c) (data minimisation) and Article 5(1)(d) (accuracy), forming an interlocking lifecycle framework.
The AI Act reinforces this at the system level. Article 17(1)(f) AI Act requires providers of high-risk AI systems to implement documented procedures covering "data retention" as part of their quality management system. Article 10 further requires governance over data preparation operations, implicitly tying retention to the system's intended purpose.
Key Developments
The CJEU's ruling in Digital Rights Ireland established that retention regimes must guarantee not only a defined endpoint but also effective erasure. The Court found that the Data Retention Directive failed because it:
"does not ensure the irreversible destruction of the data at the end of the data retention period."
— Digital Rights Ireland, ¶67
This sets a baseline: a retention period without enforceable destruction is legally deficient.
Dutch courts have grappled with retention in practice. In the Gemeente Weert case, the Raad van State upheld a municipality's preservation of a mayor's deleted emails, balancing storage limitation against obligations under the Archiefwet and the Woo — retention beyond the functional deletion point was justified where archival and transparency duties required it. Conversely, in the Beekdaelen case, a court confronted the opposite problem: log files were destroyed under a supplier's retention policy before an individual could identify who had accessed her data, illustrating how premature erasure can itself undermine data-subject rights.
The EDPB has confirmed that the GDPR deliberately leaves retention periods to controller determination:
"The GDPR does not specify a retention period for such documentation. Where such records contain personal data, it will be incumbent on the controller to determine the appropriate period of retention in accordance with the principles in relation to the processing of personal data"
— EDPB Guidelines 9/2022, §124
Status of the Debate
This topic is actively contested in court. The core principle — that data must not be kept longer than necessary — is settled. What remains disputed is the calibration: how long is "necessary" for a given purpose, and how retention interacts with conflicting legal obligations such as archival law, transparency duties, and evidentiary preservation. The Gemeente Weert and Beekdaelen cases illustrate opposite sides of this tension. No definitive court split is on record yet, but the boundaries are being fought case by case. A CJEU reference clarifying the interplay between GDPR storage limitation and sectoral retention mandates (archival, financial, law enforcement) would resolve the open question.
Practical Guidance
- Define purpose-specific retention periods: Map each processing purpose to a concrete retention timeframe in your records of processing activities under Article 30. Generic "as long as necessary" policies are insufficient.
- Implement automated erasure: Destruction at the end of a retention period must be irreversible — Digital Rights Ireland sets this as a minimum standard. Relying on supplier-managed deletion without verification (as in Beekdaelen) creates compliance gaps.
- Reconcile conflicting obligations: Where sectoral law (e.g., Archiefwet, tax law) mandates longer retention, document the legal basis and ensure the stored data is access-restricted to the archival purpose only.
- For AI systems, integrate retention into the QMS: Under Article 17(1)(f) AI Act, document data retention procedures as part of the quality management system, tied to the system's intended purpose and lifecycle.
- Review retention policies when purposes change: If a processing purpose evolves or ceases, the retention period must be recalculated — the original timeframe does not automatically carry over.