Metaluxo
← Insights

GRC

Data Retention Under GDPR: How Long Can You Actually Keep Data?

The maximum most SMEs should retain personal data.

The GDPR auditor asks: “What is your data retention period for customer email addresses?” The founder says: “We keep them forever. They might want to buy again.”

This is the wrong answer. GDPR Article 5(1)(e) says personal data must be kept “for no longer than is necessary for the purposes for which the personal data are processed.” Indefinite retention is a violation.

At Metaluxo we help SMEs define retention schedules that satisfy GDPR without breaking business operations. This post covers how to set periods, document them, and enforce them.


Before GDPR, you must consider other legal obligations:

Data typeLegal retention requirementSource
Financial records6 yearsUK Companies Act, HMRC
Employment records6 years after employment endsUK employment law
Health records8–25 years (varies by record type)NHS guidance
Tax records6 yearsHMRC
Contractual correspondence6 years (limitation period)Limitation Act 1980
CCTV footage30–90 daysICO guidance
Marketing consentUntil withdrawnGDPR

Your GDPR retention period cannot be shorter than these legal requirements. But it should not be longer either.


How to set GDPR-compliant retention periods

Step 1: Inventory your data

List every category of personal data you process: customer names, emails, phone numbers, addresses, payment details, support tickets, etc.

Step 2: Define the purpose

For each category, ask: why do we have this? The purpose determines the necessary period.

  • Customer contact details for order fulfilment → duration of contract + 6 years
  • Marketing email addresses → until consent is withdrawn
  • Job applicant CVs → 6 months after rejection (unless consent given for longer)
  • Employee records → 6 years after employment ends

Step 3: Document the justification

Write one sentence per data type: “We retain customer email addresses for 6 years after the last order to comply with UK tax record requirements and support potential warranty claims.”

Step 4: Implement deletion

Automate where possible. Most CRMs and databases support scheduled deletion or anonymisation. Manual deletion processes fail — staff forget, leave, or prioritise other work.

Step 5: Review annually

Retention periods are not static. Business needs change, laws change, and purposes evolve. Review your schedule annually and update it.


Common mistakes

  • One-size-fits-all periods. “We keep everything for 7 years” is not a retention policy. It is a default that probably violates GDPR for some data types.
  • No deletion process. Defining a period without a way to enforce it is meaningless.
  • Confusing backup retention with production retention. Backups may need longer retention for disaster recovery, but personal data in backups must still be deleted when the retention period expires.
  • Forgetting about shared drives and exports. A retention policy that covers the database but not the CSV export on the finance manager’s laptop is incomplete.

At Metaluxo we define data retention schedules for SMEs as part of our GDPR compliance programmes. If you are preparing for an audit and do not have documented retention periods, book a free 30-minute consultation and we will build a schedule that satisfies GDPR without breaking your operations.

Common questions

Is there a maximum data retention period under GDPR?

No universal maximum. The standard is 'no longer than necessary.' For most business data, 6 years aligns with UK tax and contract limitation periods. For health data, 8–25 years may apply.

Can we keep anonymised data forever?

Yes, if the data is truly anonymised and cannot be re-identified. Pseudonymised data is still personal data and subject to GDPR retention limits.

What happens if we delete data too early?

You may violate tax, employment, or contractual obligations. Retention periods should balance GDPR minimisation against legal and business requirements.

Related reading

Send us a message
Message us Book now