“We’ll keep it for X years”…How to actually justify that under GDPR
A lot of retention policies start life as a guess. Someone in the business decides personal data should be kept for five years, or seven, or “indefinitely, just in case,” and that number ends up in a policy document with no paper trail behind it. Under GDPR, that’s a problem waiting to surface, usually at the worst possible moment, when a regulator or a data subject asks why.
Article 5(1)(e) of GDPR, the storage limitation principle, requires that personal data be kept “for no longer than is necessary” for the purposes it was collected for. It doesn’t hand you a number. It hands you a test. And Article 5(2) (the accountability principle) means you have to be able to demonstrate you’ve met that test, not just assert it.
So, if a client has settled on a specific retention period, the question isn’t whether the number is right, it’s whether they can show their decision making that arrived at the number.
Here’s the process for doing that.
1. Tie the period to a purpose, not a preference
Every retention period should trace back to why the data was collected in the first place: a contract, a legal obligation, a legitimate interest, consent. The period should run until that purpose is genuinely spent, not until someone feels comfortable letting go of it. “We might need it later” is not a purpose.
2. Check whether a law has already decided it for you
Plenty of retention periods in Ireland aren’t discretionary at all, they’re set by statute, and that statute is the justification:
• Tax and accounting records: six years, (unless there is an ongoing investigation)
• Anti-money laundering records: five years, covering customer due diligence and transaction history for designated persons.
• Employment and company records: various statutory minimums depending on the record type, under the Companies Act and employment legislation.
Where a legal minimum exists, it overrides any GDPR minimalism instinct, you’re not “over retaining,” you’re complying with another law. The Data Protection Commission’s (DPC) own guidance is explicit that GDPR doesn’t prescribe fixed periods for this reason, it expects controllers to look at their other statutory obligations first.
3. Write it down in a retention schedule
This is the actual artefact a regulator will ask to see. Not a one-line policy statement, but a table: data category, purpose, legal basis, retention period, and the specific trigger that starts the clock (end of tax year, contract termination, last customer contact). If the reasoning only exists in someone’s head, it doesn’t exist for accountability purposes.
4. Apply the necessity test to anything left undefined
For data that isn’t governed by a statutory minimum, the client needs to be able to answer one question honestly: is this the shortest period that still serves the purpose? In our experience “Just in case” is the answer that gets flagged in DPC audits more than almost anything else, because it has no defined endpoint and no defined trigger for deletion.
5. Fold it into the DPIA where relevant
If the processing involves special category data or is large-scale enough to require a Data Protection Impact Assessment, the retention rationale belongs there too, including why a shorter period wasn’t chosen, if the risk profile of the data would suggest one.
6. Review it periodically
A retention period fixed once and never revisited is hard to defend years later, especially if the underlying purpose or legal requirement has since changed. A periodic annual or bi-annual review is reasonable for most organisations, and a record of that review is itself evidence that the period is actively maintained, not just inherited.
7. Keep evidence of the decision
Minutes, a DPO sign-off, or a short internal memo recording who set the period and on what basis. This is what actually gets produced if the DPC or a data subject queries a specific timeframe, not the policy document itself, but the trail behind it.
The short version: a specific retention period is justified by a documented, purpose linked, legally grounded retention schedule, reviewed periodically and backed by a record of the decision. That combination is what accountability under GDPR actually looks like in practice, and it’s the difference between a number a client can defend and one they’re just hoping nobody asks about.
Need a retention policy and process that would hold up under the DPC's spotlight? Privacy Path helps Irish and UK businesses build practical, plain-English GDPR procedures. Get in touch at privacypath.ie.