Updated: August 2026
Storage limitation is a fundamental principle of the General Data Protection Regulation (GDPR). It requires that personal data be kept in a form that permits identification of data subjects for no longer than necessary for the purposes of processing. Keeping personal data for longer than that puts a company in breach of one of GDPR’s core principles.
• GDPR doesn’t set fixed retention periods. Instead, it requires companies to determine how long to keep each type of personal data based on why it was collected and any applicable legal or regulatory requirements.
• A Data Retention Policy sets the high-level rules for retention, while a Data Retention Schedule is the operational document that spells out retention periods, disposal methods, and actions for specific data categories.
• Non-compliance with the storage limitation principle, often combined with breaches of other GDPR principles, has already cost companies over €33 million in fines, according to the GDPR Enforcement Tracker.
The retention period for personal data depends on several factors, including legal requirements, business needs, and the purpose for which the data was collected. GDPR doesn’t set a specific retention period for every type of data. Instead, it requires companies to apply the principle of data minimisation and determine an appropriate retention period based on that purpose and any applicable legal requirements.
• Legal compliance: some laws require companies to retain personal data for a set period. Tax law, for example, often requires companies to keep financial records, including customer information, for several years.
• Contractual obligations: where there’s a contractual relationship with an individual, retaining their personal data may be necessary to fulfil the contract or provide an ongoing service.
• Business purposes: retaining data can support legitimate business purposes such as customer support, record-keeping, analytics, and research, and lets companies maintain accurate historical records of their interactions with individuals.
• Security and fraud prevention: keeping data for a period supports detecting and preventing security breaches, unauthorised access, and fraud, and supports incident investigations.
What’s retained varies by company and relationship, but it typically includes basic contact information such as name, address, and email, along with transaction details, communication history, and other data relevant to the company’s relationship with the individual.
A company needs a clear Data Retention Policy that sets out the purposes and legal basis for retaining data, specifies retention periods for different types of data, and confirms compliance with applicable privacy laws.
Appropriate security measures must protect retained personal data throughout storage and eventual disposal.
A Data Retention Schedule is a documented, operational plan for how long a company retains each category of personal data. Where the Policy sets the high-level principles and framework, the Schedule provides the detailed breakdown, specific data categories, retention periods, and disposal methods that put the policy into practice. Both documents matter for effective data management and for meeting legal and regulatory requirements.
A Data Retention Schedule is generally an internal document that specifies:
• the retention period for each set of personal data;
• the rationale for choosing that period;
• the planned action once the retention period ends;
• a plan for regular retention actions, such as deletion or archiving;
• any other specifications relevant to that retention schedule.
• Evidence function: if a Data Protection Authority investigates or supervises your company, this document helps show you have a retention approach in place and that it’s actually being followed.
• Operational function: it helps you respond to a data subject rights request from a customer or employee, and confirms personal data gets deleted or anonymised when it should.
• Business function: it helps your company reduce the risk of a data breach and cut the cost of keeping data that’s no longer needed.
Non-compliance with the storage limitation principle, whether on its own or combined with breaches of other GDPR principles, has cost companies over €33 million in fines imposed by EU data protection authorities, according to the GDPR Enforcement Tracker.
Beyond direct fines, non-compliant companies face a higher risk of data breaches and higher costs from keeping data they no longer need. Those indirect costs are hard to calculate precisely, but they’re significant: IBM’s Cost of a Data Breach Report puts the global average cost of a data breach at $4.44 million.
To avoid penalties under GDPR and other data protection laws, companies need to build these principles into day-to-day operations, not just document them on paper.
Compliance with GDPR’s storage limitation principle matters for avoiding regulatory penalties, legal consequences, reputational damage, data breach costs, and lost business opportunities.
To get there, companies need a clear Data Retention Policy that sets out the purposes and legal basis for retention, specifies retention periods, and confirms compliance with the relevant privacy laws, backed by a Data Retention Schedule that breaks that down into specific data categories, retention periods, and disposal methods.
Keeping both documents current helps companies reduce non-compliance risks, protect individuals’ data rights, and cut unnecessary costs and data breach risk.
GDPRLocal can help with all of this. Sign up on the GDPRLocal Portal for a personalised path to GDPR compliance, including access to templates for the Data Retention Policy and Data Retention Schedule documents covered above.
It’s the GDPR principle requiring personal data to be kept in a form that allows identification of data subjects for no longer than necessary for the purpose it was collected for. It’s one of the core principles set out in GDPR, alongside requirements like lawfulness, fairness, and data minimisation.
A Data Retention Policy sets the high-level principles and legal basis for how a company retains personal data. A Data Retention Schedule is the operational document that breaks that down by specific data category, setting out exact retention periods and disposal methods.
GDPR sets no fixed retention period. Companies need to determine an appropriate period for each type of data based on the purpose it was collected for and any applicable legal or regulatory requirements.
Non-compliance can lead to regulatory fines, which have already totalled over €33 million across cases involving the storage limitation principle. It also raises the risk of data breaches and the cost of storing data a company no longer needs.
Disclaimer: This blog post is intended solely for informational purposes. It does not offer legal advice or opinions. This article is not a guide for resolving legal issues or managing litigation on your own. It is not a replacement for professional legal counsel and does not provide legal advice for any specific situation or employer.