GDPR Data Retention: How Long Can Your Business Hold Data?
If your business collects customer details, employee records, marketing information, payment data or website analytics, one important question is what is the maximum length of time you can hold data for GDPR purposes?
There is no single maximum data retention period under the UK GDPR.
Instead, personal data can be kept only for as long as it is genuinely necessary for the purpose for which it was collected. A business must be able to explain and document why a particular retention period is appropriate.
That means:
- Some CCTV recordings may only be needed for days or weeks
- Payroll records have statutory record-keeping requirements
- Company accounting records generally need to be kept for six years
- Certain occupational health surveillance records can require retention for 40 years
- Some qualifying research, statistical and public-interest archive data may be retained indefinitely with appropriate safeguards
The important point is that six years, seven years or 30 days are not universal GDPR limits. Different information requires different retention periods.
The ICO’s storage limitation guidance confirms that organisations must be able to justify how long they keep identifiable personal information and should erase or anonymise it when it is no longer required.
What Does UK GDPR Actually Say About Data Retention?
Article 5(1)(e) of the UK GDPR establishes the storage limitation principle.
In practical terms, it means businesses must not keep identifiable personal information for longer than necessary for the purposes for which it is processed.
The legislation deliberately avoids prescribing a universal number of months or years. A retailer, employer, SaaS company, accountant and healthcare provider may have completely different reasons for retaining information.
This remains the position in 2026. The Data (Use and Access) Act 2025, whose data-protection provisions are now in force, amended parts of the UK’s data-protection framework but did not replace the UK GDPR or remove the storage limitation principle.
Good retention practices also support wider data privacy practices because collecting less unnecessary information reduces the amount of customer and employee data that could be exposed, misused or become outdated.
How Long Can Businesses Keep Different Types of Data?
The following table provides practical starting points. Some periods come from separate statutory requirements, while others must be set by the organisation according to necessity and risk.
| Data Type | Typical Retention Starting Point | Important GDPR Consideration |
| Customer account data | While the relationship exists, plus a justified period afterwards | Keep only information required for complaints, contracts, tax or legal claims |
| Customer contracts and transaction records | Often several years after completion where legal claims remain possible | Six years may be relevant to simple contract claims in England and Wales, but this is not a universal GDPR rule |
| Limited company accounting records | Generally 6 years from the end of the relevant financial year | Longer retention may be required in certain HMRC circumstances |
| VAT records | Generally at least 6 years | Certain OSS or former MOSS records may require 10 years |
| PAYE and payroll records | At least 3 years from the end of the relevant tax year | Do not automatically retain an entire personnel file for the same period |
| Recruitment information | Until the recruitment purpose and relevant claim risk have ended | Unsuccessful applicant information should not simply be kept indefinitely |
| CCTV footage | As short as reasonably necessary | There is no general statutory GDPR 30-day limit |
| Marketing records | While processing remains lawful and necessary | Stop marketing after an objection or relevant consent withdrawal, but retain minimal suppression information where necessary |
| Website and server logs | Business-defined period based on security and operational need | Often measured in weeks or months rather than years |
| Customer support records | Based on service history, complaint and claim requirements | Delete routine conversations once they no longer serve a purpose |
| COSHH health surveillance records | At least 40 years in relevant cases | This is a specific statutory requirement, not a general employee-record rule |
| Research or statistical data | Potentially much longer or indefinitely in qualifying circumstances | Specific conditions and safeguards apply |
HMRC requires limited companies to retain many accounting records for six years from the end of the relevant financial year, subject to exceptions.
Businesses already managing their company accounts and financial records therefore need to distinguish between statutory accounting retention and GDPR retention rather than treating every piece of customer information as a six-year record.
VAT records generally need to be kept for at least six years, with a ten-year period applying to certain One Stop Shop records. PAYE records, by comparison, generally need to be retained for three years from the end of the tax year they relate to.
Is Six Years the Standard GDPR Retention Period?
No.
Six years appears frequently in UK retention schedules because several legal and commercial considerations can point towards that period. For example, an action founded on a simple contract in England and Wales generally has a six-year limitation period.
However, this does not give a business permission to retain every piece of information about a customer for six years.
Suppose a former customer could potentially make a contractual claim. The company might have a legitimate reason to preserve the contract, invoices and important correspondence.
That does not automatically justify retaining an old marketing profile, unnecessary identity documents, behavioural tracking data or obsolete support notes.
Businesses operating throughout the UK should also avoid assuming that England and Wales’ six-year limitation period applies everywhere.
Relevant contractual obligations in Scotland commonly operate under a five-year prescriptive period, while the particular circumstances and type of claim can change the applicable period.
Does GDPR Require CCTV to Be Deleted After 30 Days?
There is no universal 30-day CCTV retention rule under UK GDPR.
Thirty days is often used as an organisational benchmark, but the correct retention period depends on why surveillance is being carried out and how quickly an incident would normally become apparent.
A small shop may only require routine footage for a relatively short period. A business operating CCTV around high-risk equipment, fraud-sensitive locations or premises where incidents may be discovered later could justify a different period.
If a particular recording becomes evidence in a criminal investigation, insurance claim or workplace investigation, the relevant footage may need to be preserved beyond the normal deletion date.
The ICO itself gives examples showing that different organisations can reasonably need different CCTV periods. The test is necessity rather than an arbitrary number of days.
How Long Should Employee And Recruitment Data Be Kept?
Employee records should be divided according to purpose instead of being placed into one large personnel file with a single deletion date.
For example, a former employee’s emergency contact information may quickly become unnecessary after they leave, while payroll, pension or legal records may still need to be retained.
The ICO specifically recommends that employers review employee information when employment ends and remove information they are unlikely to require again.
Payroll is different because HMRC imposes specific record-keeping requirements. Businesses managing employees through PAYE compliance processes should therefore make sure statutory payroll records and general HR records are classified separately.
Recruitment records require similar care. Information about unsuccessful candidates should normally be deleted once the recruitment purpose has ended and any justified period for handling potential claims has passed.
Holding every CV forever because the person might be suitable for a vacancy in the future is difficult to justify.
If a business wants to retain someone’s details for future vacancies, it should establish an appropriate lawful basis, tell the individual what it intends to do and set a clear review or deletion date.
What Happens When Someone Unsubscribes From Marketing?
Businesses should not assume that an unsubscribe means every trace of a person’s information must immediately disappear.
When somebody withdraws consent or objects to direct marketing, the organisation must stop using their personal information for that marketing.
However, it can be appropriate to retain a small amount of information on a suppression or do-not-contact list.
For example, retaining an email address solely to ensure the person is not accidentally imported into a future campaign may be more compliant than deleting every record and later contacting them again.
The ICO specifically recommends suppression lists for this purpose.
This is a good example of why GDPR retention decisions are purpose-specific. The original marketing purpose has ended, but a limited compliance purpose may continue.
Deletion, Anonymisation And Pseudonymisation Are Not The Same
Once personal data reaches the end of its justified retention period, businesses will normally need to delete or anonymise it.
Deletion
Information should be securely removed when the organisation no longer has a reason to process it.
Moving old files from an active CRM into an archive folder does not count as deletion. The information is still personal data and remains subject to the UK GDPR.
Businesses should also consider backups. Where immediate physical deletion from a backup is technically impractical, the data should be protected and placed beyond normal operational use until the backup is overwritten or securely destroyed.
Anonymisation
Properly anonymised information is transformed so individuals can no longer be identified.
For example, a business might remove customer identifiers and retain aggregated sales statistics to analyse purchasing trends.
If the information is genuinely anonymous, it falls outside the normal personal-data rules.
Pseudonymisation
Pseudonymisation is different.
Replacing names with customer numbers or separating identifiers from the main database may reduce privacy risk, but if the business can reconnect the information to an individual, the information remains personal data.
The storage limitation principle therefore still applies to pseudonymised data.
What Should A GDPR Data Retention Schedule Include?
A practical retention schedule does not need to be complicated.
Businesses can start with a table such as this:
| Data Category | Purpose | Lawful Basis | Location | Retention Period | End Action |
| Customer accounts | Provide service | Contract | CRM | Account life + justified post-contract period | Delete/anonymise |
| Sales invoices | Accounting and tax | Legal obligation | Accounting system | Statutory period | Secure deletion |
| Payroll records | PAYE compliance | Legal obligation | Payroll system | Statutory HMRC period | Secure deletion |
| Marketing subscribers | Direct marketing | Consent/legitimate interests as applicable | Email platform | Until no longer justified | Suppress/delete |
| CCTV | Security | Legitimate interests or other applicable basis | CCTV system | Short defined period | Automatic overwrite |
| Support tickets | Customer support | Contract/legitimate interests as applicable | Helpdesk | Defined service period | Delete/anonymise |
| Website logs | Security and diagnostics | Legitimate interests where applicable | Server/cloud | Defined short period | Automated deletion |
The ICO recommends documenting storage periods for categories of personal information and recording what happens after the retention period expires.
Automated systems can also flag information for review or delete records according to predetermined rules.
A retention schedule should not become an excuse to keep information until the last possible day. If a record becomes unnecessary earlier, businesses should consider deleting it earlier.
How Should Startups And Growing Businesses Handle Retention?
Growing companies can accumulate personal information much faster than expected. CRMs, analytics platforms, payment tools, cloud services and investor systems can all create additional copies.
Several situations deserve particular attention.
SaaS Trial Users Who Never Become Customers
A SaaS company may need a trial user’s information while providing the trial and for a short period afterwards for security, support or legitimate sales follow-up.
That does not justify storing the person’s complete account indefinitely.
A retention process could automatically flag non-converting trial accounts after a defined period and remove unnecessary profile, usage or behavioural information.
Cap Tables And Investor Information
Cap tables, shareholder records and investment documentation may need lengthy retention for corporate, regulatory and evidential reasons.
However, a company should separate legally important ownership records from incidental personal information collected during fundraising.
Funding Data Rooms
A funding round may involve passports, CVs, employee information, customer contracts, financial records and other highly sensitive documents.
Once due diligence ends, businesses should review who still needs access and whether duplicated documents held in temporary data rooms can be removed.
When A Business Pivots?
Changing business models does not automatically allow data collected for the original service to be repurposed.
A company should assess whether the new use remains compatible with the original purpose, whether another lawful basis is available and whether customers need to be informed.
When A Business Closes?
Closing a company does not mean every record should immediately be deleted.
Some accounting, tax, employment, insolvency, corporate or legal records may still need to be retained.
Other personal information that has no continuing purpose should be securely disposed of rather than being left indefinitely in old cloud accounts.
What About Cloud Providers, CRMs And Other Data Processors?

Businesses remain responsible for considering retention even when information is stored by another company.
This matters because modern businesses often hold personal data across CRM platforms, accounting software, email services, payroll systems, cloud storage and analytics providers.
Managing cloud security risks should therefore include knowing where personal data exists, which suppliers can access it and what happens when a service is cancelled.
Under Article 28 processor arrangements, contracts must provide for personal data to be returned or deleted at the controller’s choice when the processing service ends, unless UK law requires continued storage.
A business should therefore check:
- What retention period the supplier applies
- Whether deleted records remain in backups
- How long backup copies survive
- Whether subcontractors hold additional copies
- What happens when the contract ends
- Whether deletion can be confirmed
- Whether information is exported before the account closes
Data-sharing agreements should similarly explain what happens after the shared purpose ends. The ICO recommends agreeing retention and disposal arrangements before information is shared.
What About Smart Devices, Apps And IoT Products?
Technology businesses should build retention controls into their products rather than treating deletion as a later administrative task.
A smart speaker, wearable device, connected appliance or mobile app may generate large volumes of account activity, location data, voice recordings, telemetry or behavioural information.
Keeping all of that information indefinitely because storage is inexpensive does not satisfy the storage limitation principle.
Useful product-level controls can include:
- Automatic deletion after defined periods
- User-controlled retention settings
- Account-closure deletion workflows
- Separate retention periods for security logs and product data
- Anonymisation of old analytical datasets
- Clear explanations in privacy information
The same logic increasingly applies to AI systems. ICO audit guidance recommends assessing retention at both training and inference stages and removing data that is no longer required.
Can Personal Data Ever Be Kept Indefinitely?
Yes, but only in specific circumstances.
UK GDPR contains special provisions allowing longer-term or potentially indefinite retention where personal data is processed solely for qualifying:
- Archiving in the public interest
- Scientific research
- Historical research
- Statistical purposes
Appropriate safeguards must be used.
This exception should not be interpreted as permission for an ordinary company to label an old customer database “research” and preserve it forever.
The purpose genuinely needs to qualify, and the relevant safeguards and other data-protection requirements continue to apply.
What Can Happen If A Business Keeps Data Too Long?
Unnecessary retention increases both regulatory and commercial risk.
It can mean:
- More personal information is exposed during a cyberattack
- Subject access requests become harder and more expensive
- Old information becomes inaccurate
- Businesses accidentally use obsolete contact or preference data
- Storage and security costs increase
- The organisation struggles to demonstrate GDPR accountability
Serious infringements of provisions subject to the higher UK GDPR maximum can attract fines of up to £17.5 million or 4% of worldwide annual turnover for an undertaking, whichever applicable maximum is higher. The actual penalty depends on the circumstances of the infringement.
The Clearview AI Example
Retention has featured directly in ICO enforcement.
In its 2022 action against Clearview AI, the ICO said the company did not have a data retention policy and could not demonstrate that personal information was being kept for no longer than necessary.
The ICO imposed a penalty of approximately £7.55 million alongside an enforcement notice addressing a number of alleged UK data-protection infringements.
The case has subsequently involved substantial tribunal proceedings over the ICO’s jurisdiction, so it should not be presented as a simple final precedent.
In October 2025 the Upper Tribunal largely accepted the ICO’s jurisdictional arguments, and Clearview was later granted permission to appeal that decision.
For businesses, the practical lesson remains straightforward: a retention period should be deliberate, documented and defensible rather than indefinite by default.
Can A Customer Demand That A Business Deletes Their Data?

Individuals have a right to request erasure of personal data in certain circumstances, including where the information is no longer necessary or where relevant consent has been withdrawn.
However, the right to erasure is not absolute.
A company may still have grounds to retain information where processing remains necessary, including to:
- Meet a legal obligation
- Establish, exercise or defend legal claims
- Perform certain public-interest functions
- Conduct qualifying research, statistical or public-interest archiving activities
For example, a former employee cannot necessarily require an employer to erase payroll information that the employer is legally required to retain.
The ICO’s guidance confirms that businesses should assess each erasure request according to the particular information and purpose rather than applying a blanket rule.
How Can Businesses Decide On The Right Retention Period?
For each category of personal information, ask six questions:
1. Why was this information collected?
Identify the precise purpose instead of relying on a broad statement such as “business purposes”.
2. Is the information still required for that purpose?
If the purpose has ended, determine whether another genuine purpose or legal obligation remains.
3. Is there a legal record-keeping requirement?
Tax, payroll, health and safety, financial services and other regulated activities may impose specific periods.
4. Could the information reasonably be required for a legal claim?
Consider the relevant limitation or prescription period and retain only information that could actually matter.
5. How sensitive is the information?
Keeping large volumes of identity, health, financial or behavioural data creates greater privacy and security risk.
6. Can identifiable information be removed?
If a business only needs statistics or trends, proper anonymisation may allow useful information to be retained without preserving identifiable customer records.
The answer should then be documented in the organisation’s retention schedule.
Conclusion
There is no universal answer to what is the maximum length of time you can hold data for GDPR. UK GDPR focuses on necessity rather than imposing one fixed number of years.
Businesses should set different retention periods for different categories of information, account for statutory requirements, document why each period is justified and regularly remove or anonymise information that is no longer needed.
The strongest retention policy is not the one that keeps everything for as long as possible. It is the one that can clearly explain what is being kept, why it is needed, when it will be reviewed and what happens when that need ends.
Frequently Asked Questions
What Is The Maximum Length Of Time You Can Hold Data For GDPR?
There is no general maximum period. Personal data can be retained for as long as it is necessary for a legitimate and lawful purpose, provided the organisation can justify the period.
Does GDPR Have A Seven-Year Data Retention Rule?
No. UK GDPR does not contain a general seven-year rule. Some legal, accounting or industry requirements may lead organisations to retain particular records for several years, but those periods do not automatically apply to every type of personal data.
Does GDPR Require Data To Be Deleted After Six Years?
No. Six years is relevant to certain accounting requirements and legal limitation periods, but it is not a universal GDPR deletion deadline.
Can CCTV Be Kept For More Than 30 Days?
Yes, if there is a genuine and proportionate reason. There is no general UK GDPR rule requiring CCTV to be deleted precisely after 30 days. Businesses must establish a justified retention period based on the purpose of surveillance.
Can Businesses Keep Customer Data After An Account Is Closed?
Potentially. Certain information may still be needed for accounting, complaints, fraud prevention, contractual disputes or legal obligations. Data that no longer serves a valid purpose should be deleted or anonymised.
Does Pseudonymised Data Still Come Under GDPR?
Usually, yes. If information can be reconnected to an identifiable person using additional information, it remains personal data and the storage limitation principle continues to apply.
Can A Business Keep An Email Address After Someone Unsubscribes?
A business should stop using the address for direct marketing, but may retain minimal information on a suppression list to ensure the individual is not accidentally contacted again.
Should A Data Retention Policy Cover Third-Party Software?
Yes. Businesses should know how personal information is retained by CRMs, payroll providers, cloud platforms, email systems and other processors, including what happens to information and backups after contracts end.
