Data Retention: Why Organisations Might Keep Personal Data

Data retention and disposal are key elements of data flows. As part of this retention schedules and Records of Processing Activities (RoPAs) are essential tools for GDPR compliance. They set out how long personal data should be kept and when it should be deleted. In principle, this supports the storage limitation principle—that personal data should not be kept longer than necessary (see Article 5(1)e of the UK GDPR).

However, in practice, organisations do not always delete data exactly when a retention period expires. Often this is a symptom of ineffective processes. However, there are legitimate, lawful reasons why personal data may need to be retained beyond the original timeframe.

Understanding these exceptions is critical. Retention periods are not fixed. Data destruction is a managed process that must remain responsive to risk, legal obligations, and individual rights.

 

Periodic Table of the GDPR

 


The Starting Point: Retention Periods and the Storage Limitation Principle

Under the UK GDPR, organisations must:

  • define how long they will retain personal data,
  • document those periods (often in a retention schedule or RoPA),
  • and ensure data is not kept longer than necessary.

Retention periods are usually based on:

  • legal requirements (e.g. limitation periods),
  • regulatory expectations,
  • operational needs,
  • risk management considerations.

But these periods are not absolute. They represent normal conditions, not every possible scenario.


Why Data May Be Retained Longer Than Planned

There are several common and legitimate reasons why data retention may be extended.


1. Safeguarding Concerns

Safeguarding is one of the strongest justifications for extended retention.

Where there are concerns about:

  • vulnerable individuals,
  • ongoing risk of harm,
  • patterns of behaviour over time,

organisations may need to retain information beyond standard retention periods.

Why this matters

Safeguarding decisions often rely on historical context. Deleting information too early could:

  • obscure patterns of risk,
  • prevent effective intervention,
  • compromise future investigations.

In these situations, retention becomes a risk management tool, not just an administrative process.

To rely on safeguarding as a reason for retaining data the conditions of Article 84B of the UK GDPR must be met:

  • the processing consists of the collection of the personal data (whether from the data subject or otherwise),
  • the processing is carried out in order to convert the personal data into information which can be processed in a manner which does not permit the identification of a data subject, or
  • without the processing, the safeguarding purposes cannot be fulfilled.

The processing of personal data for safeguarding purposes must be carried out subject to appropriate safeguards for the rights and freedoms of the data subject


2. Legal Claims and Litigation (Actual or Anticipated)

One of the most common reasons for extended retention is legal action.

If an organisation is:

  • involved in litigation,
  • anticipating a claim,
  • defending a complaint or tribunal case,

it may need to retain relevant personal data until the matter is resolved.

Legal basis for extended retention

This is often justified under:

  • the need to establish, exercise, or defend legal claims,
  • applicable limitation periods,
  • legal hold or litigation hold procedures.

Example

An employer may retain disciplinary records beyond their normal retention period if an employee brings a tribunal claim. Deleting the data prematurely could undermine the organisation’s ability to defend itself.


3. Regulatory Investigations or Inquiries

If an organisation is subject to:

  • regulatory scrutiny,
  • an audit or inspection,
  • a formal investigation,

it may need to retain relevant data until the process is complete.

This can apply in sectors such as:

  • healthcare,
  • financial services,
  • education,
  • public authorities.

Retention in these circumstances supports accountability and evidence preservation.

 

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 


4. Requests from the Data Subject

In some cases, the individual themselves may request that data is retained.

For example:

  • an employee may ask for records to be kept during a grievance or dispute,
  • a patient may request continued retention of records for continuity of care,
  • a customer may ask for information to be preserved for a complaint.

While organisations must assess such requests carefully, they can provide a valid basis for extending retention.


5. Ongoing Operational or Business Need

Sometimes the original retention period proves insufficient because of evolving business needs.

For example:

  • long-term contracts may extend beyond initial expectations,
  • historical data may be needed for audits or trend analysis,
  • organisational restructuring may delay disposal processes.

However, this must be approached cautiously. Convenience alone is not a sufficient justification. The organisation must still demonstrate necessity and proportionality. Crucially data retention must be for purposes compatible with the original purposes it was originally collected for. You must not decide to reuse the data for new purposes, and if you do have a new purpose in mind you are likely to need to rely on consent as the lawful basis for doing so, or – if any other lawful basis applies – contacting the data subject to let them know to comply with the transparency principle.


6. Data Subject Rights and Disputes

Where an individual exercises their rights—for example:

  • submitting a Subject Access Request,
  • challenging accuracy,
  • objecting to processing,

the organisation may need to retain data longer to:

  • respond properly,
  • evidence decisions,
  • manage ongoing correspondence.

Retention in this context supports compliance with GDPR obligations themselves.


7. Errors, Backlogs, and Practical Realities

In some cases, extended retention occurs because of:

  • system limitations,
  • incomplete data mapping,
  • delays in disposal processes,
  • legacy systems that are difficult to update.

While these factors may explain why data is retained longer, they do not justify indefinite retention. Organisations must still take steps to address underlying issues. It’s not necessarily a data breach for data to be retained a little longer than its planned retention period, as retention periods are a minimum not a maximum. What will be an issue is a serial or ongoing failure to review data for destruction.


Managing Extended Retention Properly

Retaining data beyond its original retention period is not inherently non-compliant. The key is how it is managed.


1. Document the Reason

Any deviation from standard retention periods should be recorded.

This might include:

  • legal hold notices,
  • safeguarding justifications,
  • regulatory requirements,
  • data subject requests.

Documentation supports accountability and auditability.


2. Apply Targeted Retention (Not Blanket Extensions)

Extended retention should be:

  • limited to relevant data, rather than everything,
  • specific to the issue at hand,
  • not applied across entire datasets unnecessarily.

This ensures compliance with data minimisation principles.


3. Review Regularly

Extended retention should not become permanent by default.

Organisations should:

  • review retained data periodically,
  • remove it when the justification no longer applies,
  • ensure disposal processes resume when appropriate.

4. Maintain Security and Access Controls

Data retained for extended periods may be particularly sensitive.

Ensure:

  • access is restricted,
  • audit logs are in place,
  • security controls remain robust.

Retention increases risk exposure. Controls must reflect this.


5. Align with Policies and Governance

Retention policies should acknowledge that exceptions exist.

Good practice includes:

  • defining when retention can be extended,
  • setting out approval processes,
  • linking to legal hold or safeguarding procedures.

This ensures consistency across the organisation.


When Extended Retention Becomes a Risk

While there are legitimate reasons to retain data longer, organisations must avoid:

  • keeping data indefinitely “just in case”
  • failing to revisit extended retention decisions
  • using operational inconvenience as justification
  • losing visibility of why data is still held

Over-retention increases:

  • security risk,
  • regulatory exposure,
  • reputational risk.

The principle remains: data should only be kept as long as it is necessary—even when that period changes.

 

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star rating and testimonial

 

 

 


Final Thought

Retention schedules and RoPAs provide structure, but they are not rigid rules. Real-world situations—particularly safeguarding, legal disputes, and regulatory oversight—often require flexibility.

The key is not to avoid extending retention. It is to ensure that any extension is:

  • justified,
  • documented,
  • proportionate, and
  • regularly reviewed.

Done properly, extended retention is not a failure of compliance. It is a reflection of responsible and accountable data governance. It is also, as a final thought, worth remembering that there are no limits on storage limitation for data that are fully anonymised.