Article
GDPR Data Retention: Policies Irish Companies Need - Open Forest
openforest.co
Quoted on this wiki
Every place a page here uses this source, in the order the words come in it.
Website analytics and cookies “Analytics data should be anonymised or aggregated wherever possible.” For guidance on your right to erasure obligations when individuals request deletion, see our right to erasure guide.
Build retention schedules detailing categories, periods, triggers, bases, and owners for accountability. “Delete securely via overwriting, destruction, or anonymise; automate in CRM, cloud, HR systems.” Audit annually, train staff, assign owners to enforce policy and demonstrate GDPR compliance.
Irish laws mandate minimums like 6 years for accounting, tax, payroll; 3 years for working time records. “Build retention schedules detailing categories, periods, triggers, bases, and owners for accountability.” Delete securely via overwriting, destruction, or anonymise; automate in CRM, cloud, HR systems.
Review your retention schedule at least annually. Check whether: “Data is being deleted on schedule” New processing activities have been added to the schedule
Step 4: Document justifications “This documentation is your evidence if the DPC asks why you are keeping data.” A practical retention schedule might look like this:
Step 3: Identify the trigger event “The retention period starts from a specific event, not from a fixed date:” Date of collection: For one-off data collection (e.g., event registration)
End of employment: For employee records “Last interaction: For marketing contacts” Closure of the matter: For legal case files