Skip to content
PolicyForge
All posts
By Vyrhak SATH · Founder, NAGASHIELD SECURITY5 minReviewed

How to write a data retention policy

A data retention policy defines how long you keep data and when you delete it. Here is what to include — retention periods, deletion, GDPR — with a free template.

Why keeping data forever is a liability

Every record you keep is data you must protect — and, under GDPR, data you must justify keeping. A data retention policy defines how long each category of data is kept and how it is securely deleted, reducing both your breach exposure and your compliance risk.

What to include

  1. Scope — data categories covered (customer, HR, financial, logs, backups).
  2. Retention periods — how long each category is kept, tied to legal, contractual and business needs.
  3. Legal basis — the obligation or justification behind each period (GDPR storage-limitation principle).
  4. Deletion — secure, documented deletion when the period ends, including backups.
  5. Holds — how legal holds suspend deletion when required.
  6. Responsibilities — who owns retention decisions and enforcement.
  7. Review — periodic update as obligations change.

Common mistakes

  • "Keep everything forever," which maximises breach impact and breaches GDPR.
  • Retention periods with no legal basis recorded.
  • Forgetting backups, where data lives on after deletion from production.

Framework alignment

Supports ISO 27001:2022 Annex A 5.33 (protection of records) and 8.10 (information deletion), the SOC 2 criteria, and the GDPR storage-limitation principle.

Primary sources

Generate it in minutes

See a sample data retention policy or generate yours free.

Frequently asked questions

How do I set retention periods?

Work backwards from the legal, regulatory, and contractual obligations for each data type, then add any genuine business need. Where laws conflict, the longest mandatory period usually wins. Record the period and the reason per data category, so the schedule is defensible rather than arbitrary.

Does GDPR require a maximum retention period?

GDPR storage limitation (Article 5(1)(e)) says personal data must not be kept longer than necessary for the purpose it was collected for. It does not give fixed numbers; you set proportionate periods, document them, and delete or anonymise data once the purpose and any legal hold have ended.

What is the difference between retention and deletion?

Retention defines how long data is kept; deletion is what happens at the end of that period. A complete policy covers both, including secure disposal and how backups are handled — data is not truly deleted while it still sits in a recoverable backup beyond its retention window.