-
The GDPR itself sets no fixed retention periods, only the "storage limitation" principle: keep data no longer than necessary for its purpose. These are commonly used practical benchmarks referenced by data protection authorities, not a legal requirement, and this is not legal advice. Check with a data protection officer for your exact case.
| Data category | Legal basis | Max retention |
|---|
Why the GDPR never gives you a number
The GDPR's storage limitation principle (Article 5.1.e) requires that personal data be kept "for no longer than is necessary for the purposes for which the personal data are processed", but it deliberately avoids fixing exact durations, since the right duration depends on the purpose, the sector, and other laws that may apply on top of the GDPR. In practice, data protection authorities such as France's CNIL publish reference benchmarks for common situations, which is what this checklist reproduces.
A few common benchmarks
| Data category | Typical maximum |
|---|---|
| Marketing prospecting data | 3 years after last contact |
| Cookies and trackers | 13 months |
| CCTV footage | 1 month, unless part of an ongoing investigation |
Where this tool falls short
These figures are commonly cited practical benchmarks, not hard legal minimums or maximums written into the GDPR text itself, and a specific sector, a national law layered on top of the GDPR, or an ongoing legal claim can justify a longer retention in a documented case. This tool cannot assess your specific processing purpose or legal basis, only show the general reference point.
The one rule that always applies
Whatever the category, the retention period must be tied to a documented purpose, reviewed periodically, and personal data should be deleted or anonymised once that purpose no longer applies, rather than kept indefinitely by default.