Legal retention periods, in short
The starting point is the Accounting Law (Law 82/1991), which requires, as a rule, that registers and supporting documents be kept for 10 years from the close of the financial year, and payroll records for 50 years, precisely because employment history is reconstructed from them. For some financial-accounting documents, the regulation sets a shorter period of 5 years (OMFP Order 2634/2015). The remaining categories — correspondence, internal notes, technical documentation, personnel files — get their periods through the company's records retention schedule, drawn up following the logic of Law 16/1996. Don't try to memorize these periods: write them once into the records schedule and let the platform apply them.
What GDPR requires on top of the archival-legislation periods
Regulation (EU) 2016/679 adds a principle that applies over all the others: storage limitation, set out in Art. 5(1)(e). Personal data is kept in a form that allows identifying people only for as long as necessary for the purpose it's processed for. The right to erasure, set out in Art. 17, lets the data subject request that their data be deleted — but this right isn't absolute: it yields, among other things, to legal retention obligations. In practice, if a former employee requests deletion, a payroll record cannot be deleted, because the law requires it to be kept. 4docs.net explicitly flags these situations, so your response is correct, not improvised.
What disposal on schedule looks like in the platform
Automatic, uncontrolled deletion is a bad idea: a misconfigured rule can wipe out an entire category. That's why the flow always has a human in it. With a configurable interval before expiry, the platform generates a list of proposals: which documents are reaching their deadline, from which category, on what basis. The person in charge reviews the list, excludes anything that must still be kept (for example, a file involved in litigation) and approves the rest. Disposal produces a written record of what was removed and under what rule, and the log keeps the trace. The document disappears; the proof that it was disposed of correctly remains.
Data-subject requests, kept in one place
An access or deletion request received by email and handled from memory is the most common point of failure for compliance. In the platform, the request is registered as such: who made it, what they're asking for, when it was received and by when it must be answered. Searching the archive shows you where that person's data appears, including in scanned documents, via OCR. The response is recorded together with the documents that supported it. In an inspection, you no longer have to reconstruct what happened eight months ago: the record is there, with deadlines and decisions.