Article
How long can you keep marketing data under UK GDPR?
data.sortediq.com
Quoted on this wiki
Every place a page here uses this source, in the order the words come in it.
Publish a summary in your privacy notice. The ICO's own published guidance on retention (available at ico.org.uk) states that controllers should tell individuals how long their data will be kept, or the criteria used to determine that period. A privacy notice that says "we keep your contact details for up to 24 months from your last interaction with us, after which we delete or anonymise the record" is both legally compliant and commercially reassuring to prospects who read it. “For B2B prospecting under legitimate interests, your Legitimate Interests Assessment is the primary document.” What are your options when data reaches the end of its retention period?
How does the storage limitation principle apply to B2B marketing data? “The retention window for that basis is tied to how long the legitimate interest genuinely subsists.” In practice, 24 months from the last meaningful engagement is the figure that appears repeatedly in ICO enforcement correspondence and the DMA's own member guidance. "Meaningful engagement" means something more than a passive email delivery: a reply, a click, a meeting request, an inbound call, or a purchase all qualify. An unopened email probably does not, though reasonable people disagree on this edge case.
How do data refreshes affect the retention clock? “Refreshing a record (verifying that the contact details are still current and the individual is still in the same role) can legitimately reset the retention clock, provided you treat it as a new data-collection event and document it accordingly.” What this means in practice: when you re-verify a B2B record against a live public source such as Companies House or a corporate website, note the verification date and source in your CRM. The record's retention period then runs from that verification date, not from the original import date. You still need to ensure the lawful basis holds (the legitimate interest in marketing to this person must still exist), but the storage limitation clock legitimately restarts.
B2B vs B2C retention: a comparison “Suppression file (opted-out contacts) Legal obligation / legitimate interests in honouring opt-outs Indefinite (minimum data: identifier and opt-out date) Date of opt-out request Process note showing suppression file is checked before every send” How should you set and document a retention policy?
Suppression files “A suppression file holds the minimum information needed to prevent re-contacting someone: typically an email address, a telephone number, or a postal identifier, plus the date of the opt-out.” How do data refreshes affect the retention clock?