Article
Data Retention: How Long Should You Really Keep ...
griffinhouseconsultancy.co.uk
Quoted on this wiki
Every place a page here uses this source, in the order the words come in it.
Building a retention schedule “For each activity, think about the type of personal data you hold, why you are using it, how long you need to keep it, when the retention period starts, and whether any exceptions apply.” — the processing activity or legal/business reason,,
A good retention schedule should set out all your significant processing activities in a clear and practical way. For each activity, think about the type of personal data you hold, why you are using it, how long you need to keep it, when the retention period starts, and whether any exceptions apply. Keep it simple: four columns are usually enough: “— the processing activity or legal/business reason,,” — the data category,
— the data category, “— the retention period, and” — the disposal method.
Make sure every relevant department is identified, including IT, HR, Finance, Marketing, and other central operations. “Your retention schedule should be reviewed at least once a year and checked regularly to make sure it is being followed.” Sometimes the law will help by setting out how long certain records should be kept, for example, in areas such as tax, employment, or children’s services. There may also be guidance from regulators or industry bodies. Where there is no clear rule, you will need to justify the retention period based on the purpose of the processing and the potential benefit or harm to both the individual and the organisation. As a general rule, the more sensitive the data, the stronger the case for keeping it only for as long as strictly necessary. And of course remember, if you can anonymise the data, GDPR no longer applies and you can keep indefinitely.
Make sure every relevant department is identified, including IT, HR, Finance, Marketing, and other central operations. “It should also line up with yourRecord of Processing Activities(RoPA) and your Privacy Notice or Privacy Policy, so everything stays consistent and up to date.” Sometimes the law will help by setting out how long certain records should be kept, for example, in areas such as tax, employment, or children’s services. There may also be guidance from regulators or industry bodies. Where there is no clear rule, you will need to justify the retention period based on the purpose of the processing and the potential benefit or harm to both the individual and the organisation. As a general rule, the more sensitive the data, the stronger the case for keeping it only for as long as strictly necessary. And of course remember, if you can anonymise the data, GDPR no longer applies and you can keep indefinitely.