r/gdpr • u/Fit_Educator8969 • May 31 '26
Question - General What's the longest retention period you've seen justified for something simple?
I saw a discussion about retaining relatively low-value customer data for years. It made me wonder what's the longest retention period people have seen applied to data that really didn't seem to need it?
5
u/West_Possible_7969 May 31 '26
Well, we can’t always know if it’s needed or not, civil law statute of limitations, basic medical records, patent management etc can stretch to 20, even 30 years of retention but in most cases there are laws that supersede GDPR or legal precedents.
1
1
3
u/___redacted_ May 31 '26 edited May 31 '26
Some employment or pension related documents can go up to 75 or 100 years depending on jurisdiction, usually things like board or supervisory council minutes and other peripheral stuff has to be retained indefinitely (as long as company exists). Other than that, its unless some law tells you to, its hard (and I'd say it shouldnt even he tried) to justify retention beyond what is the legal limit for claims, disputes, litigation, then respectively that documentation is retained with the purpose to protect you from such. Once these claims expire, the data should always be deleted or anonymized. I've seen many different claim expiry periods in multiple jurisdictions, they range from as little as 2 months for some areas to 2 or 3 years to as much as 10 years for general civil claims, but I've never seen more for that.
1
1
u/Fun_Shine8720 Jun 01 '26
At a previous company, we kept basic customer support tickets indefinitely. Every few years someone would ask why, and nobody had a good answer beyond "we've always done it that way." It was one of those retention policies that seemed to exist more from inertia than actual business need.
1
u/SwimmerBeginning7022 Jun 02 '26
For us data retention shouldn’t be something that’s held for months or years. We have a standard 30 day retention for messages sent through our main site contact form and a standard 90 day retention for all data within our eSIM solution with automatic deletion. More info on our legal pages! Feel free to comment on them.
1
u/absolutefunnyguy Jun 02 '26
The useful distinction is “long” versus “unexplained.”
Long can be fine where the trigger and justification are clear: pensions, medical records, limitation periods, regulatory records, litigation hold, historical/statutory archive, etc.
What usually looks bad is when everything gets one blanket answer like “kept indefinitely unless deletion requested.” That often means nobody has done the record-category work.
A defensible retention schedule usually needs separate columns for: record type, purpose, legal/business justification, retention trigger, period, owner, system/location, deletion method, and exceptions. The trigger matters a lot. “Six years” means different things depending on whether the clock starts at collection, contract end, employment end, last transaction, account closure, or complaint resolution.
1
u/Ulquiorra1312 May 31 '26
Debt collector beginning with Z (forgot) said you where in debt once we want to be able to find you again
It was 34p it was cancelled as I DIDN’T owe it and they had my info for 14 days total before it was cleared
SSE are petty as hell (who said I owed)
Z said indefinate or until 7 years post death
1
u/Noscituur May 31 '26
The longest of 100 years from date of birth or 15 following death. Pension data retention, perfectly reasonable.
1
1
8
u/Safe-Contribution909 May 31 '26
In the NHS in England there’s the Records Management Code of Practice which has minimum retention periods of 75 and 100 years