Storage Limitation
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Principle that data should not be kept longer than necessary
Overview
19 sources · Jul 23, 2026Legal Framework
Storage limitation is codified in Article 5(1)(e) GDPR, which requires that personal data be:
"kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed"
— GDPR Art. 5(1)(e)
The provision carves out a narrow exception: longer retention is permitted only for archiving in the public interest, scientific or historical research, or statistical purposes under Article 89(1). The principle operates alongside Article 5(1)(c) (data minimisation) and Article 5(1)(d) (accuracy), forming an interlocking lifecycle framework.
The AI Act reinforces this at the system level. Article 17(1)(f) AI Act requires providers of high-risk AI systems to implement documented procedures covering "data retention" as part of their quality management system. Article 10 further requires governance over data preparation operations, implicitly tying retention to the system's intended purpose.
Key Developments
The CJEU's ruling in Digital Rights Ireland established that retention regimes must guarantee not only a defined endpoint but also effective erasure. The Court found that the Data Retention Directive failed because it:
"does not ensure the irreversible destruction of the data at the end of the data retention period."
— Digital Rights Ireland, ¶67
This sets a baseline: a retention period without enforceable destruction is legally deficient.
Dutch courts have grappled with retention in practice. In the Gemeente Weert case, the Raad van State upheld a municipality's preservation of a mayor's deleted emails, balancing storage limitation against obligations under the Archiefwet and the Woo — retention beyond the functional deletion point was justified where archival and transparency duties required it. Conversely, in the Beekdaelen case, a court confronted the opposite problem: log files were destroyed under a supplier's retention policy before an individual could identify who had accessed her data, illustrating how premature erasure can itself undermine data-subject rights.
The EDPB has confirmed that the GDPR deliberately leaves retention periods to controller determination:
"The GDPR does not specify a retention period for such documentation. Where such records contain personal data, it will be incumbent on the controller to determine the appropriate period of retention in accordance with the principles in relation to the processing of personal data"
— EDPB Guidelines 9/2022, §124
Status of the Debate
This topic is actively contested in court. The core principle — that data must not be kept longer than necessary — is settled. What remains disputed is the calibration: how long is "necessary" for a given purpose, and how retention interacts with conflicting legal obligations such as archival law, transparency duties, and evidentiary preservation. The Gemeente Weert and Beekdaelen cases illustrate opposite sides of this tension. No definitive court split is on record yet, but the boundaries are being fought case by case. A CJEU reference clarifying the interplay between GDPR storage limitation and sectoral retention mandates (archival, financial, law enforcement) would resolve the open question.
Practical Guidance
- Define purpose-specific retention periods: Map each processing purpose to a concrete retention timeframe in your records of processing activities under Article 30. Generic "as long as necessary" policies are insufficient.
- Implement automated erasure: Destruction at the end of a retention period must be irreversible — Digital Rights Ireland sets this as a minimum standard. Relying on supplier-managed deletion without verification (as in Beekdaelen) creates compliance gaps.
- Reconcile conflicting obligations: Where sectoral law (e.g., Archiefwet, tax law) mandates longer retention, document the legal basis and ensure the stored data is access-restricted to the archival purpose only.
- For AI systems, integrate retention into the QMS: Under Article 17(1)(f) AI Act, document data retention procedures as part of the quality management system, tied to the system's intended purpose and lifecycle.
- Review retention policies when purposes change: If a processing purpose evolves or ceases, the retention period must be recalculated — the original timeframe does not automatically carry over.
why this is here
the footage is automatically deleted after a certain storage period
Discusses deletion after a storage period, directly relating to storage limitation.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
Wher e data is stored only for a very short period, there must be measures to guarantee that a request for access can be fulfilled without the data being erased
The document mentions storage duration only to ensure access can be provided before erasure.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
general and indiscriminate retention of traffic and location data relating to electronic communication is contrary to Union law
The document directly addresses the principle of storage limitation by discussing the permissible and impermissible retention periods for traffic and location data.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
A retention up to five years (as indicated in Art. 12(1) of the PNR Directive) is only allowed for data on air passenger if objective evidence revealed a possible involvement in terrorist offences or serious crime
The document directly addresses the storage limitation principle by setting constraints on how long PNR data may be kept.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
The company kept data relating to the tests carried out by Internet users for 24 months, then 3 months, from their completion.
The core violation is keeping data longer than necessary, which is the essence of storage limitation.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
retention of the data may be of interest to the man's ex-partner
Justifies retention beyond the data subject's request, implicating storage limitation principle.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
the data retention period had to be limited to what was necessary
The judgment mentions retention limitation, but it is secondary to the lack of factual basis for the data.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
Nothing of this type on this topic.
This is the top of each pile — all 42 Case Law · all 55 Guidance · all 96 Enforcement