Preparing and implementing data-retention and record-keeping policies and systems
For data retention policies and procedures, we have good news and bad news.
The good news is that the GDPR’s requirements on data retention are, for a change, not complicated or difficult to understand. Indeed, the EU Data Protection Directive and the privacy laws of other countries such as Canada’s PIPEDA have long required that data not be retained or processed longer than the minimum necessary. The GDPR’s data retention requirements merely implement the use limitation principle of the traditional Fair Information Practices: Keep personal data only so long as necessary to fulfill the original basis for collecting and processing it — and no longer.