Skip to main content
Category: Data Lifecycle and Disposal

Retention Period

Also known as: Data Retention Period, Data Life Cycle
Simply put

A retention period is the length of time an organization keeps a record or piece of data before it is archived or deleted. How long data is kept generally depends on the type of data and the purpose it serves, such as legal, tax, financial, administrative, or historical needs. Different categories of records typically have different retention periods.

Formal definition

A retention period is the defined duration for which a specific record series or data type is maintained by an organization before disposition (archiving or deletion). Retention periods vary by the purpose of the data and are commonly documented across a set of record types in a retention schedule, which enumerates the record series an organization creates and receives. In some records-management contexts, the retention period is measured from the point at which a record becomes inactive. This entry defines the concept only; it does not address the specific statutory or regulatory retention durations that apply under any particular regime, nor does it address related obligations such as storage limitation principles, lawful basis for continued processing, or deletion and erasure mechanics, which depend on jurisdiction, data category, and implementation.

Why it matters

Retention periods sit at the intersection of information governance and data protection, because keeping data longer than necessary generally increases both legal exposure and security risk. The amount of time an organization keeps records and documents is typically driven by legal, tax, financial, administrative, or historical purposes, and each of these purposes can pull a given record toward a different disposition date. Without defined and documented retention periods, organizations tend to accumulate data indefinitely, which enlarges the volume of information that could be exposed in a breach and complicates the ability to respond to data subject requests or legal discovery.

Retention decisions are also a governance accountability matter, not merely an operational preference. Under accountability-oriented governance frameworks, an organization is generally expected to be able to demonstrate why data is kept for a particular duration, rather than simply asserting that a period is appropriate. Documenting retention periods across record types, commonly in a retention schedule, provides the evidentiary basis for that accountability. It is worth noting that this entry defines the concept of a retention period only; it does not establish any specific statutory duration, nor does it resolve related questions such as the storage limitation principle, the lawful basis for continued processing, or the mechanics of deletion and erasure, all of which depend on jurisdiction, data category, and implementation.

Who it's relevant to

Information governance and records managers
These professionals own the retention schedule that enumerates record series and assigns a retention period to each. They are responsible for ensuring that periods are documented, applied consistently across record types, and supported by a defensible rationale rather than stated intent alone.
Data protection and privacy officers
Retention periods intersect with storage limitation expectations and the question of whether there remains a purpose and lawful basis for continued processing. Privacy officers generally rely on documented retention periods as evidence of accountability, while recognizing that this concept alone does not resolve deletion or erasure obligations, which depend on jurisdiction and data category.
Legal and compliance teams
Because retention periods are driven by legal, tax, financial, administrative, or historical purposes, legal and compliance functions help determine appropriate durations for each record type and reconcile competing needs. Note that specific statutory or regulatory durations fall outside this concept and must be determined against the applicable regime.
Security and IT operations
Retention periods define how long data persists in systems before archiving or deletion, which directly affects the volume of data at risk and the design of storage and disposition processes. These teams implement the schedule technically, coordinating with governance owners rather than setting periods independently.

Inside Retention Period

Defined Duration
The specific length of time, or the criteria used to determine that length, for which personal data is kept before deletion, anonymization, or review. In many regimes such as the EU GDPR and UK GDPR, data should generally not be retained for longer than necessary for the purposes for which it was processed.
Purpose Linkage
The connection between the retention duration and the original, specified processing purpose. Once the purpose is fulfilled, continued retention typically requires a separate justification, such as a legal obligation or ongoing legitimate need.
Triggering Event
The point from which the retention clock runs, for example the end of a contractual relationship, the last customer interaction, or the closure of an account. Retention criteria are often expressed relative to such events rather than as fixed calendar dates.
Disposition Action
What happens at the end of the period, which may be secure deletion, anonymization, or a documented review to decide whether further retention is justified. Note that anonymization is generally treated as irreversible and may take data out of scope of most data protection regimes, whereas merely restricting access does not.
Legal and Regulatory Basis
Statutory, contractual, or sector-specific requirements that mandate minimum or maximum retention, which vary by jurisdiction and data category. Requirements applicable to, for example, health records or financial records differ from general personal data and are not universal.
Governance Documentation
The policies, schedules, and records that evidence retention decisions. Under an accountability model, demonstrable evidence of retention rules and their application is generally expected, not merely a stated intention to limit retention.

Common questions

Answers to the questions practitioners most commonly ask about Retention Period.

Does keeping a fixed retention period, such as a set number of years, automatically make our retention practices compliant?
No. A single fixed period applied across all data does not by itself demonstrate compliance. In most jurisdictions, retention is expected to be tied to the purpose for which the data was collected and the lawful basis or legal obligation that justifies keeping it. Different categories of data, and different processing purposes, may warrant different periods. Compliance generally depends on being able to justify each period against a defined purpose, and on being able to demonstrate that justification with evidence rather than merely stating a duration. This entry does not cover the specific retention durations mandated by any particular regime.
Once the retention period expires, does encrypting, tokenizing, or archiving the data satisfy our obligation to stop retaining it?
Not necessarily. Encryption and tokenization do not render data non-personal; the underlying data typically remains personal data and therefore remains subject to retention obligations. Moving data to an archive tier or applying security controls addresses how data is protected, not whether it should still be held. Where a retention period has ended and no lawful basis or legal obligation supports continued retention, the expectation in most regimes is that the data is deleted or irreversibly anonymized. This entry does not detail the technical standards that would qualify a given process as irreversible anonymization.
How should we determine the appropriate retention period for a given dataset?
Generally, retention periods are derived from the specific purpose of processing, the lawful basis relied upon, and any applicable legal, regulatory, or contractual requirements that mandate a minimum or maximum holding time. Because these drivers vary by data category and jurisdiction, organizations typically map each processing activity to its purpose and to any statutory retention or limitation rules before assigning a period. Where no external rule applies, the period is usually justified by reference to how long the data remains necessary for the stated purpose. This entry does not enumerate jurisdiction-specific statutory periods.
Where should retention periods be documented and who is accountable for them?
Retention periods are commonly documented within records of processing activities, data retention schedules or policies, and data catalogs, and are often reflected in privacy notices where required. Under accountability principles found in several governance frameworks, the controller generally bears responsibility for defining and justifying retention, while processors typically act on the controller's documented instructions, including instructions to delete or return data. Accountability here requires demonstrable evidence, such as an approved schedule and records of deletion, not merely a stated intention. This entry does not address the contractual mechanics governing controller-processor retention instructions.
How can we enforce retention periods across systems in practice?
Enforcement typically combines documented schedules with operational mechanisms such as automated deletion or lifecycle rules, periodic review cycles, and controls that trigger disposal when a period lapses. Because data is often distributed across multiple systems, backups, and copies, effective enforcement usually requires knowing where data resides through lineage or cataloging efforts that fall within data governance, alongside secure deletion controls that fall within information security. These disciplines overlap but remain distinct. This entry does not prescribe specific deletion technologies or address backup retention mechanics in detail.
What should we do when different legal or business requirements imply conflicting retention periods for the same data?
Conflicts commonly arise when one obligation requires deletion while another, such as a legal hold or a statutory recordkeeping duty, requires continued retention. In most cases organizations resolve this by identifying the governing requirement for each purpose, segregating data so that only the portion subject to a mandatory retention obligation is kept, and documenting the rationale for the decision. Because the correct outcome depends on jurisdiction and the specific obligations involved, this is generally a case-by-case determination supported by evidence. This entry does not resolve conflicts arising under any specific regime or address legal hold procedures in detail.

Common misconceptions

A retention period is a single fixed number of years that applies uniformly across all of an organization's data.
Retention is generally tied to purpose and data category, and different datasets typically warrant different periods or criteria-based rules. Some sector-specific obligations may set minimums or maximums, so a single blanket figure rarely reflects lawful practice across an entire organization.
Once the retention period ends, encrypting or tokenizing the data is sufficient to comply with storage limitation expectations.
Encryption and tokenization are security measures and do not, by themselves, render data non-personal. Data that can still be linked to an individual, including via a reversible transformation, generally remains personal data and subject to the applicable regime's requirements.
Deleting data at the end of a retention period always removes it from regulatory scope, and archiving is the same as deletion.
Only genuine, irreversible removal or anonymization typically takes data out of scope of most regimes. Archived, backed-up, or restricted-access copies generally still count as retained personal data and must be accounted for in the retention approach.

Best practices

Define retention rules by processing purpose and data category rather than applying a single uniform period, and express durations relative to clear triggering events where a fixed date is not appropriate.
Document the legal, contractual, or business justification for each retention rule so that the approach is demonstrable as evidence under an accountability model rather than stated only as intent.
Specify the disposition action for the end of each period, distinguishing secure deletion from anonymization and from mere access restriction, and confirm whether the chosen action actually removes data from scope.
Extend retention rules to backups, archives, and derived copies, since these generally remain retained personal data even when the primary record is deleted.
Review and update retention schedules periodically to reflect changes in purposes and applicable jurisdictional requirements, recognizing that sector-specific minimums or maximums differ across regimes.
Consult applicable legal or regulatory sources for specific minimum or maximum retention obligations rather than assuming a period is universal, as this entry does not enumerate jurisdiction-specific figures.