How do you set a GDPR-compliant document retention policy?

How do you set a GDPR-compliant document retention policy?

A retention policy means a written period for every document type, and a deletion that actually happens.

Răspuns scurt

  1. You inventory the document types that contain personal data.
  2. For each type you set a retention period and its basis: a legal obligation or a documented legitimate interest.
  3. When the period expires, the document is deleted or anonymized automatically, not "whenever someone remembers".
  4. Every deletion is recorded, so you can prove compliance with the storage-limitation principle.

What the law says (in brief)

  • Regulation (EU) 2016/679, Art. 5(1)(e) — storage limitation: personal data is kept only as long as necessary for the purpose.
  • Regulation (EU) 2016/679, Art. 17 — the right to erasure; it doesn't apply where retention is required by a legal obligation.
  • Law 82/1991: the 10 years for registers and supporting documents and the 50 years for payroll records apply over a deletion request.
  • OMFP Order 2634/2015: for some financial-accounting documents the period is 5 years.
  • Law 16/1996: the records retention schedule is the document where these periods are actually written down.

Practical examples

  • CVs of rejected candidates: a short period set by the company, often 6–12 months, with the candidate informed beforehand.
  • A former employee requests data deletion: their file can't be deleted in full, because the payroll record has a legal period of 50 years.
  • The building access log: a period of a few months, then automatic deletion, with no manual step.
  • A company with 300 document types narrows the list to 42 categories with distinct periods and automates the rest.

Common mistakes

  • The policy exists on paper, but no actual deletion has ever taken place.
  • Every deletion request is accepted, including for documents with a mandatory legal period.
  • Backups still hold data that was already deleted from the main system.
  • No proof of deletion is kept, so compliance can't be demonstrated.
  • Periods are set "out of caution" at 30 years for everything, which violates the storage-limitation principle.

How 4docs helps

  • A retention period configured for each document type, with its basis noted alongside.
  • An alert before expiry, so deletion is checked by a person in charge.
  • Automatic deletion or anonymization on schedule, including for attached files.
  • The deletion register stays as proof for the supervisory authority.

Vezi și

4b2b.net
Business Ecosystem
4conta.ro
Accounting
4invoices.net
Invoicing App
4expenses.net
Expense Management
4notify.net
Notifications
4hosting.net
Hosting
4database.net
Databases
4buildsite.net
Website Builder
4myapp.net
App Builder
4avatars.net
AI Avatars
4chaty.net
AI Chatbot
4webagency.net
Web Agency Software
4softedu.net
Education Websites
4softcrm.net
CRM Platform
4softerp.net
ERP System
4softhr.net
Human Resources
4mystaff.net
Staff Portal
4myprojects.net
Project Manager
4docs.net
Document Management
4mycontracts.net
Contracts
4appointments.net
Appointments
4marketingonline.net
Marketing
4insurance.net
Insurance
4property.net
Real Estate
4lawyers.net
Legal Software
4mygarage.net
Auto Service
4driving.net
Driving Schools
4fleet.net
Fleet Management
4myevents.net
Events
4therapy.net
Therapy
4clinics.net
Clinics
4dental.net
Dental Practices
4restaurants.net
Restaurants
4beautify.net
Beauty Salons
4gym.net
Fitness Gyms
4guards.net
Security Companies
4construct.net
Construction Companies
4marketplace.net
Marketplace
4shopy.net
Online Store
4pricing.net
Price Comparison
4salefood.net
Food Delivery
4rentify.net
Rentals
4transports.net
Transport
4agencytravel.net
Travel Agency
4hotel.net
Hotels & Guesthouses
4ong.net
NGO Management
How do you set a GDPR-compliant document retention policy?