Privacy
Glossary

Storage limitation

Storage limitation is the principle that personal data should be kept in an identifiable form only for as long as necessary for the specified purposes of the processing.

In brief

Storage limitation is one of the principles in Article 5(1) GDPR. Personal data must not be retained indefinitely. Controllers should determine for each processing activity which retention period, or which objectively verifiable deletion criteria, is necessary for the relevant purposes.

The necessary period depends on the purpose and on the data involved. Employee records, customer relationships, job applications, video recordings and marketing data may therefore require different retention periods and review steps. Statutory retention duties may require data to be kept longer, but they do not automatically resolve the other GDPR requirements. Once the purpose ends, data should be deleted or anonymised so that the individual is no longer identifiable, unless another legal basis supports continued retention.

Article 5(1)(e) GDPR provides a specific exception for archiving in the public interest and for scientific or historical research and statistical purposes. It requires appropriate technical and organisational safeguards under Article 89(1) GDPR. In practice, a retention and deletion policy should document the purposes, periods, exceptions, responsibilities and regular review. The sections on privacy compliance and governance and employee data protection show how this assessment can be built into organisational processes.

General orientation, not individual advice.

Discuss your data protection matter

Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.

Contact

Clarify a data protection question

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich