The GDPR auditor asks: “What is your data retention period for customer email addresses?” The founder says: “We keep them forever. They might want to buy again.”
This is the wrong answer. GDPR Article 5(1)(e) says personal data must be kept “for no longer than is necessary for the purposes for which the personal data are processed.” Indefinite retention is a violation.
At Metaluxo we help SMEs define retention schedules that satisfy GDPR without breaking business operations. This post covers how to set periods, document them, and enforce them.
The legal baseline
Before GDPR, you must consider other legal obligations:
| Data type | Legal retention requirement | Source |
|---|---|---|
| Financial records | 6 years | UK Companies Act, HMRC |
| Employment records | 6 years after employment ends | UK employment law |
| Health records | 8–25 years (varies by record type) | NHS guidance |
| Tax records | 6 years | HMRC |
| Contractual correspondence | 6 years (limitation period) | Limitation Act 1980 |
| CCTV footage | 30–90 days | ICO guidance |
| Marketing consent | Until withdrawn | GDPR |
Your GDPR retention period cannot be shorter than these legal requirements. But it should not be longer either.
How to set GDPR-compliant retention periods
Step 1: Inventory your data
List every category of personal data you process: customer names, emails, phone numbers, addresses, payment details, support tickets, etc.
Step 2: Define the purpose
For each category, ask: why do we have this? The purpose determines the necessary period.
- Customer contact details for order fulfilment → duration of contract + 6 years
- Marketing email addresses → until consent is withdrawn
- Job applicant CVs → 6 months after rejection (unless consent given for longer)
- Employee records → 6 years after employment ends
Step 3: Document the justification
Write one sentence per data type: “We retain customer email addresses for 6 years after the last order to comply with UK tax record requirements and support potential warranty claims.”
Step 4: Implement deletion
Automate where possible. Most CRMs and databases support scheduled deletion or anonymisation. Manual deletion processes fail — staff forget, leave, or prioritise other work.
Step 5: Review annually
Retention periods are not static. Business needs change, laws change, and purposes evolve. Review your schedule annually and update it.
Common mistakes
- One-size-fits-all periods. “We keep everything for 7 years” is not a retention policy. It is a default that probably violates GDPR for some data types.
- No deletion process. Defining a period without a way to enforce it is meaningless.
- Confusing backup retention with production retention. Backups may need longer retention for disaster recovery, but personal data in backups must still be deleted when the retention period expires.
- Forgetting about shared drives and exports. A retention policy that covers the database but not the CSV export on the finance manager’s laptop is incomplete.
At Metaluxo we define data retention schedules for SMEs as part of our GDPR compliance programmes. If you are preparing for an audit and do not have documented retention periods, book a free 30-minute consultation and we will build a schedule that satisfies GDPR without breaking your operations.
Common questions
Is there a maximum data retention period under GDPR?
No universal maximum. The standard is 'no longer than necessary.' For most business data, 6 years aligns with UK tax and contract limitation periods. For health data, 8–25 years may apply.
Can we keep anonymised data forever?
Yes, if the data is truly anonymised and cannot be re-identified. Pseudonymised data is still personal data and subject to GDPR retention limits.
What happens if we delete data too early?
You may violate tax, employment, or contractual obligations. Retention periods should balance GDPR minimisation against legal and business requirements.