How Long Can You Legally Keep Customer Data?

Date: 09/09/2026

GDPR data retention and storage limitation — hexagon illustration with an archive box and clock

“Forever” was never a valid retention period

We’ve circled this question twice already in this series — once when a customer asks you to delete their data, once when they ask to see or correct it. Both times the same question surfaced underneath: how long were you allowed to keep it in the first place? This is the article on that question specifically.

Article 5(1)(e) requires personal data to be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed. That is the storage limitation principle, and it sits in Article 5 next to data minimisation (Article 5(1)(c)) as its natural counterpart: collect less, and keep it for less time. Privacy by design is a different animal — Article 25 is a separate obligation to build those principles into your systems, not a principle in its own right.

There is one carve-out, in the same provision: data may be kept for longer where it will be processed solely for archiving in the public interest, scientific or historical research, or statistical purposes — and only with the safeguards Article 89(1) requires. For most businesses this will not apply.

There’s no single universal number

GDPR does not set a retention period. It sets a test. The lawful period depends on why you hold the data:

  • Tax and accounting records. In Cyprus, books and records generally have to be kept for six years — that comes from the Assessment and Collection of Taxes Law (Law 4/1978, as amended), not from GDPR. Where another law requires you to keep something, GDPR is not asking you to delete it.
  • Contractual records. Usually the life of the contract plus enough time to handle a dispute. In Cyprus the general limitation period for an action concerning a contract is six years from the date the cause of action accrued (Limitation of Actions Law 66(I)/2012).
  • Marketing data. No statutory number at all. An email list is justifiable while the person is still engaged and has not withdrawn consent or objected. An address you have been bouncing emails at for four years has outlived its purpose.
  • CCTV footage. Normally justifiable only for a short window — long enough to notice and review an incident. There is no figure in the legislation. You set one, keep it short, document why, and extend only a specific segment tied to a specific incident.
  • Unsuccessful job applications. Again no statutory number: long enough to deal with a query or challenge about the recruitment decision, and no longer.

The rule of thumb: every period should trace back to a specific legal requirement or an ongoing business purpose. “We’ve always kept it” is not a basis.

You have to write the period down — and publish it

This is the part most businesses miss. Storage limitation is not only about deleting; it comes with paperwork obligations attached.

  • Tell people. Article 13(2)(a) — and Article 14(2)(a) where you did not get the data from the person directly — requires your privacy notice to state how long you will store the data, or, if you cannot give a fixed period, the criteria you use to work it out.
  • Record it. Article 30(1)(f) requires your record of processing activities to include, where possible, the envisaged time limits for erasure of each category of data.
  • Be able to prove it. Article 5(2) makes you responsible for demonstrating compliance with the Article 5(1) principles, this one included. A written retention schedule is what “demonstrating” looks like in practice.

Recital 39 puts it plainly: the controller should establish time limits for erasure or for a periodic review.

Building a simple retention schedule

You do not need a policy document. A table works:

Data typePurposeRetention periodBasis for the period
Invoices and accounting recordsTax compliance6 yearsLegal obligation — Assessment and Collection of Taxes Law
Signed contractsPerforming the contract, defending claimsContract term + 6 yearsContract + limitation period
Marketing listOngoing marketingUntil unsubscribe or sustained inactivityConsent
CCTV footagePremises securityShort, fixed windowLegitimate interest
Unsuccessful applicationsRecruitmentShort, fixed windowLegitimate interest

Two things get much easier once this exists: answering a data subject request accurately, and knowing what to actually delete at clean-up time. Where you are relying on legitimate interest to justify a period, the balancing test is the thing you should be able to point to.

What happens when the period ends

When a period expires, the data should be deleted or genuinely anonymised — not merely left alone. Anonymised data falls outside GDPR entirely (Recital 26), but the bar is higher than people assume: if you can still single someone out, it is still personal data and still in scope. Moving a spreadsheet to a folder nobody opens is not anonymisation.

It cuts the other way too. Article 17(1)(a) gives people the right to erasure precisely where the data is no longer necessary for the purpose it was collected for — so an expired retention period is a request you are going to lose.

A practical habit: a recurring quarterly or annual reminder to check the schedule against what is actually sitting in your systems, and clear out whatever has outlived its purpose.

Quick checklist

  1. List the categories of personal data you hold.
  2. Attach a specific purpose and a specific period to each.
  3. Tie every period to a real basis — a law, a contract, or an ongoing legitimate interest.
  4. Put the periods, or the criteria, in your privacy notice and your record of processing.
  5. Schedule a recurring review, not a one-off exercise.
  6. When a period ends, actually delete — do not just stop looking at it.

Not sure what your retention periods should be, or whether the ones you have would survive scrutiny? Let’s Talk GDPR.

Related reading


References

  1. GDPR Article 5(1)(e) — storage limitation: personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
  2. GDPR Article 5(2) — accountability: the controller is responsible for, and must be able to demonstrate compliance with, the Article 5(1) principles.
  3. GDPR Articles 13(2)(a) and 14(2)(a) — the storage period, or the criteria used to determine it, must be given to the data subject.
  4. GDPR Article 17(1)(a) — right to erasure where the personal data are no longer necessary in relation to the purposes for which they were collected or processed.
  5. GDPR Article 30(1)(f) — records of processing activities, including where possible the envisaged time limits for erasure.
  6. GDPR Article 89(1) — safeguards for archiving in the public interest, scientific or historical research, and statistical purposes.
  7. GDPR Recitals 26 and 39 — anonymous information falls outside the Regulation; time limits should be established for erasure or periodic review.
  8. Assessment and Collection of Taxes Law (Law 4/1978, as amended), Cyprus — obligation to retain books and records for six years.
  9. Limitation of Actions Law 66(I)/2012, Cyprus — six-year general limitation period for actions concerning a contract.
Latest Articles & Insides