Outbound Wiki

Article

GDPR Data Retention: Policies Irish Companies Need - Open Forest

openforest.co

Open at publisher

Quoted on this wiki

Every place a page here uses this source, in the order the words come in it.

  1. Website analytics and cookies Analytics data should be anonymised or aggregated wherever possible. For guidance on your right to erasure obligations when individuals request deletion, see our right to erasure guide.

    In Prospect data anonymization

  2. Build retention schedules detailing categories, periods, triggers, bases, and owners for accountability. Delete securely via overwriting, destruction, or anonymise; automate in CRM, cloud, HR systems. Audit annually, train staff, assign owners to enforce policy and demonstrate GDPR compliance.

    In Prospect data deletion workflows

  3. Irish laws mandate minimums like 6 years for accounting, tax, payroll; 3 years for working time records. Build retention schedules detailing categories, periods, triggers, bases, and owners for accountability. Delete securely via overwriting, destruction, or anonymise; automate in CRM, cloud, HR systems.

    In Retention documentation and audits

  4. Review your retention schedule at least annually. Check whether: Data is being deleted on schedule New processing activities have been added to the schedule

    In Retention documentation and audits

  5. Step 4: Document justifications This documentation is your evidence if the DPC asks why you are keeping data. A practical retention schedule might look like this:

    In Retention documentation and audits

  6. Step 3: Identify the trigger event The retention period starts from a specific event, not from a fixed date: Date of collection: For one-off data collection (e.g., event registration)

    In Retention trigger rules

  7. End of employment: For employee records Last interaction: For marketing contacts Closure of the matter: For legal case files

    In Retention trigger rules