Stale Data The Potential GDPR Risk Hiding in Records

Stale Data: The Potential GDPR Risk Hiding in Records

A customer database that nobody has cleaned in three years is not just clutter. Under GDPR, stale data (outdated personal information, no longer accurate, or kept well past the point it served any purpose) breaches two separate principles at once: accuracy and storage limitation. Two European fines, one for keeping data too long and one for acting on data that was simply wrong, show regulators treat both failures as enforcement priorities, not housekeeping issues.

Principaux enseignements

Stale data breaches GDPR’s accuracy principle (Article 5(1)(d)) when it is out of date, and the storage limitation principle (Article 5(1)(e)) when it is kept longer than necessary. A single dataset can fail both at once.

France’s CNIL fined Free Mobile €27 million and its parent Free €15 million in January 2026, partly over retaining millions of former subscribers’ records without justification.

Italy’s Garante fined Axpo Italia €10 million after the company used outdated customer data to open unsolicited energy contracts affecting over 5,000 people.

Automated systems built on stale data compound the risk: a credit scoring or eligibility system trained on outdated records will keep producing decisions based on information that is no longer true.

What Counts as Stale Data Under GDPR?

Stale data is personal data that has drifted out of date, is no longer accurate, or has outlived the purpose it was originally collected for. It typically falls into two overlapping categories: data that is factually wrong because circumstances changed and nobody updated it, and data that is still accurate but should have been deleted once its original purpose was fulfilled.

GDPR addresses these through two separate principles in Article 5. The accuracy principle requires that personal data be accurate and, where necessary, kept up to date, with inaccurate data erased or corrected without delay. The storage limitation principle requires that personal data be kept in a form permitting identification of individuals for no longer than necessary for the purposes it was collected for.

Why Is Stale Data a Compliance Risk Rather Than Just a Data Quality Problem?

Because GDPR treats both failures as principal violations subject to the regulation’s highest enforcement tier, not as internal quality control matters, Article 5 violations, covering both accuracy and storage limitation, fall under the fine bracket that can reach up to €20 million or 4% of global annual turnover, the same tier as unlawful processing or ignoring data subject rights.

The risk compounds where automated decisions rely on stale data. A system making eligibility, credit, or risk decisions based on outdated records will keep producing decisions grounded in information that no longer reflects reality, which turns a data quality issue into a pattern of potentially unlawful automated decisions.

What Happened in the CNIL Fine Against Free Mobile?

On 13 January 2026, France’s CNIL fined Free Mobile €27 million and its parent company Free €15 million, a combined €42 million, following a data breach investigation that also exposed how the company handled data retention. The CNIL found that Free Mobile had retained millions of records belonging to former subscribers without any documented justification for keeping them, and had no process in place to sort and purge that data once it was no longer needed for the purposes it was collected for.

The violation was grounded in Article 5(1)(e), the storage limitation principle specifically. As part of the resolution, Free Mobile agreed to retain only the subscriber data necessary for accounting purposes going forward, for a maximum of ten years. The CNIL gave it six months to complete the purge of everything else.

What Happened in the Italian Fine Against Axpo Italia?

Italy’s data protection authority, the Garante, fined energy supplier Axpo Italia €10 million after an investigation found the company’s sales agents were using an outdated customer database to open unsolicited electricity and gas contracts. More than 5,000 individuals were affected, with contracts activated in their names using information that was no longer accurate and, in several cases, had never been verified against the real customer in the first place.

The Garante found violations of Article 5(1)(a) and (d), covering lawfulness and accuracy, alongside Article 5(2) accountability and Article 24, which requires controllers to implement measures ensuring processing meets GDPR’s requirements. The case illustrates the accuracy side of the stale data problem specifically: the company was not accused of holding data too long, but of acting on data that was simply wrong.

How Do You Identify Stale Data in Your Systems?

Practical detection usually starts with mapping which datasets have no defined retention period or review cycle attached to them, since undefined retention is exactly the gap the Free Mobile case exposed. From there, organisations typically flag records that have had no update or interaction in a defined period, cross-check high-risk datasets such as billing, contract, or credit information against a recent verification source, and audit any automated decision-making system to confirm the data feeding it reflects current, not historical, information.

Our guide to GDPR’s accuracy principle and our companion piece on storage limitation and retention compliance both cover the practical mechanics of building these checks into a retention schedule.

How Do You Prevent Stale Data From Building Up?

Preventing stale data from accumulating is more sustainable than periodically cleaning it out. A documented retention schedule, tied to the specific purpose each dataset serves, forces a decision point at collection time rather than leaving data to sit indefinitely by default. Automated deletion or anonymisation triggers, set against that schedule, remove the reliance on someone remembering to review the data manually. Where full deletion is not practical, for example because of accounting or legal retention obligations, restricting access to that data rather than actively processing it reduces the risk it gets reused in a way that requires it to be still accurate.

Conclusion

Stale data sits at the intersection of two GDPR principles that regulators are actively enforcing at meaningful scale, not treating as minor housekeeping. The Free Mobile case shows what happens when data is kept without a defined reason to keep it. The Axpo Italia case shows what happens when data is acted on without checking whether it is still true. Both point to the same underlying fix: a retention schedule with defined purposes, review points, and deletion triggers, rather than data that persists until someone notices it should not have.

Frequently Asked Questions

Is keeping inaccurate data automatically a GDPR violation, even without a breach?

Yes. The accuracy principle under Article 5(1)(d) requires inaccurate personal data to be corrected or erased without delay, regardless of whether that inaccurate data has caused any external harm or breach. The violation exists in holding and processing inaccurate data, not just in what happens because of it.

How long can we legally keep customer data “just in case” we need it later?

GDPR does not permit indefinite retention on a “just in case” basis. The Free Mobile case specifically penalised this approach: retaining data without a documented, purpose-linked justification breaches the storage limitation principle, even if the data itself was never misused.

Does anonymising stale data solve the compliance problem?

Yes, provided the anonymisation is genuinely irreversible. Once data can no longer be linked to an identifiable individual, it falls outside GDPR’s scope entirely, which removes both the accuracy and storage limitation obligations that apply to personal data specifically.

Disclaimer: This blog post is intended solely for informational purposes. It does not offer legal advice or opinions. This article is not a guide for resolving legal issues or managing litigation on your own. It should not be considered a replacement for professional legal counsel and does not provide legal advice for any specific situation or employer.

Ana Mishova

About the Author

Ana Mishova

Sales and Business Development Consultant — GDPRLocal

Ana focuses on helping organisations understand their compliance obligations and find the right data protection solutions. At GDPRLocal she works closely with businesses of all sizes, making GDPR and privacy compliance clear, practical, and accessible.

About the Author

Ana Mishova

Sales & Business Development Consultant

Ana Mishova is a Sales & Business Development Consultant at GDPRLocal, the UK’s fastest-growing B2B compliance partner. With four years at the company, she has experience across operations, from creating processes and shaping compliance services to driving growth through sales, marketing, and strategic partnerships.

Her prior experience includes working closely with current and prospective clients and coordinating with stakeholders to design and plan compliance products. She has led internal change initiatives, driven sales, and guided organisations in selecting the most appropriate compliance strategies.

She holds a degree in psychology, which enhances her ability to connect with people and understand their needs. At GDPRLocal, she works with colleagues to strengthen the sales function and plays an active role in developing the sales strategy.