惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
美团技术团队
Last Week in AI
Last Week in AI
WordPress大学
WordPress大学
博客园 - 三生石上(FineUI控件)
博客园 - 聂微东
雷峰网
雷峰网
阮一峰的网络日志
阮一峰的网络日志
博客园 - 叶小钗
IT之家
IT之家
Google DeepMind News
Google DeepMind News
D
Docker
J
Java Code Geeks
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 【当耐特】
V
V2EX
Hugging Face - Blog
Hugging Face - Blog
博客园 - Franky
月光博客
月光博客
宝玉的分享
宝玉的分享
酷 壳 – CoolShell
酷 壳 – CoolShell
aimingoo的专栏
aimingoo的专栏
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations
Data Retention Policy: Best Practices And Why You Need On...
Alice Perseval · 2023-01-13 · via Compliance Solutions for Websites, Apps and Organizations | iubenda

User data has longtime been a valuable asset for businesses, with data protection laws being introduced to regulate the way it can be responsibly handled. Needless to say, that when it comes to collecting data, businesses need to be aware of the legal requirements and best practices that come with it! One of these practices is having a data retention policy.

👀 Let’s dive in.

What is a data retention policy?

First and foremost, what is data retention? It refers to data being stored and used for a set period of time, called the data retention period. In short, this period defines how long the data (i.e. an email address, medical file, payroll) will be kept for, before having to be deleted.

data retention policy

The data retention policy is not a standalone “policy” document like the privacy policy in the GDPR understanding. It is more of an internal assessment to define all the following information, for each processing activity:

  • what data is stored;
  • for how long data is stored;
  • where data is stored;
  • what happens to data that is no longer needed.

It is an important part of your business’ internal privacy management, along with keeping track and being able to describe security measures, legal basis for processing, data transfer outside the EU and the parties that you share the data with.

Why do you need a data retention policy?

Your data controller needs to carry out an assessment based on a number of criteria to define retention periods for the categories of personal data that is processed, and then disclose this information to users.

In general, data retention periods can be:

  • mandatory because imposed by a specific law or industry, i.e. a fixed period defined by national legislation, tax, anti-fraud or employment laws; or
  • recommended, i.e.by a country’s data protection authority and act as guidelines for the data controller (such as the guide by the French Data Protection Authority, CNIL).

More than just an internal assessment

💡 Apart from carrying out an internal assessment of your data retention policy, please also note that under GDPR Article 13 you are legally required to disclose retention periods for each of your processing activities!

👋 Sounds complicated? It doesn’t have to be! See how to do it in this section

🇺🇸 California’s CPRA (CCPA amended) that came into force in January 2023, is another strong example. It now requires mentioning the retention period for each category of personal information, including sensitive personal information, in a notice at collection. Businesses are therefore advised to limit personal information’s retention to the shortest amount of time necessary and to the purpose for which it was collected.

Best practices for data retention

Questions to address

You might find useful considering the following questions:

📌 Until when do I really need the data for the business to achieve the initial objective?
📌 Am I legally obliged to keep the data for a certain period of time?
📌 Should I keep certain data to protect myself from a potential issue?
📌 Which data needs to be stored? For how long?
📌 What are the rules for storing or deleting data?

Best practices

Here are some key principles to follow as you build your data retention policy:

✅ Have a precise, legal and legitimate purpose;
✅ Set a precise, time-limited retention period;
✅ Data must be relevant and necessary;
✅ Data must be stored for the shortest time possible;
✅ Data is safe and protected.

What you need to do

Here’s how you can disclose data retention to your users.

Best practice is to include accurate data retention information via your privacy documents, such as your privacy policy.

Here’s how to do this with iubenda:

🚀 Use our Privacy and Cookie Policy Generator to add the technologies you use on your website (i.e. Facebook access);
🚀 Use our Internal Privacy Management tool for defining storage duration for each processing activity;
🚀 Generate your privacy policy with all necessary default disclosures! (See example below)

data retention policy

Easily disclose data retention periods

Get started now