Designing a document retention policy that survives GDPR scrutiny

Everyone knows they should delete documents eventually. Almost nobody can say on what basis, on what trigger, or with what evidence. Here is how to build a schedule that holds up.

The most common question we hear from records managers is "how long does the GDPR say we have to keep this?" The answer is that it says nothing at all, and that is precisely the difficulty.

Article 5(1)(e) requires that personal data be kept "no longer than is necessary for the purposes for which the personal data are processed." It sets no periods and gives no table. It hands you a principle and expects you to derive the periods yourself — and, under Article 5(2), to demonstrate how you derived them.

Harder than being handed a number, but tractable. Here is a method that produces a schedule you can defend.

Start with classes, not documents

You cannot make a retention decision about every document individually. Group them into records classes — sets sharing a purpose, and therefore a retention logic.

For a professional services firm: client matter files, engagement and conflict records, anti-money-laundering records, financial and accounting records, employment and recruitment records, supplier contracts, marketing contacts, corporate governance.

Ten to twenty-five classes is normal. If you find yourself at sixty, you are describing folders rather than classes.

For each class, ask four questions in order

1. What is the purpose, and when does it end? The primary driver, and the one most often skipped. A client matter file exists to deliver and evidence the engagement; that purpose ends at matter close, not when someone gets round to archiving it.

2. Is there a statutory minimum? Some periods are set by law — accounting records seven years under Estonian law, anti-money-laundering records typically five. Write down the provision: "seven years, Accounting Act § 12" is defensible; "seven years, we think" is not.

3. What is the realistic limitation period? You may retain records to defend potential claims — usually the longest limitation period for professional negligence where you practise, plus a margin. This supports a defined period, not indefinite retention.

4. Is there a genuine business need beyond those? Sometimes. Usually it is habit. "It might be useful one day" is not a purpose under Article 5(1)(e), and saying so honestly is what separates a schedule from a wish.

The retention period for the class is the longest of the answers to questions 2, 3 and 4, measured from the trigger identified in question 1.

Get the trigger right — it matters more than the number

Most schedules specify a duration and leave the trigger implicit, which makes them unimplementable. "Seven years" from what? Four trigger types cover nearly everything:

  • Event-based — matter close, engagement sign-off, contract expiry, end of employment. Almost always right for client work.
  • Date-based — end of the financial year in which the record was created. Suits financial and tax records, and disposes in predictable annual batches.
  • Last-access-based — a defined period since anyone touched the record. Treat with caution: one incidental access resets the clock and can quietly make retention indefinite.
  • Review-based — flagged for a human decision. Reserve for genuinely irregular classes; if most records need review, the schedule is under-specified.

The event-based trigger fails most often, because the event is not captured anywhere a system can read. If your matters have no recorded closure date, no rule keyed to matter close will ever fire. That is a prerequisite, not a detail.

Legal hold must override everything, automatically

When litigation is reasonably anticipated or a regulator opens an enquiry, disposal must stop for the affected records — immediately, and regardless of what the schedule says.

Three properties matter. The hold must be applied by criteria — this client, this matter, this date range — rather than by hand. It must survive deletion attempts, including by administrators. And it must be evidenced: who applied it, when, on what basis, and when it was released.

A schedule without a working legal hold is worse than none: it disposes of material on time in exactly the circumstances where that is most damaging.

Evidence the disposal, not just the intention

Accountability means demonstrating compliance, so every disposal should produce a record: what was destroyed, under which rule, on what date, and who approved it.

That certificate is what you produce when a regulator asks whether the policy is real. It also protects the people involved: a documented disposal under an approved schedule is routine records management, while an undocumented deletion during a dispute looks like something else.

Two practical notes. Build a review step before irreversible disposal of high-value classes — a named approver catches the matter closed in error. And be realistic about backups: production data is deleted on a date, backups age out on a cycle. State the cycle rather than claiming erasure you cannot deliver.

Then actually run it

The gap between a written policy and a running one is where most programmes fail. A schedule that requires someone to remember, each quarter, to review a list and press delete will not survive its author's next holiday.

Encode the schedule in the systems that hold the records: classification at creation, the trigger captured as data, disposal proposed automatically, holds enforced by the system rather than by convention, every step logged. Then review the schedule annually and record that you did.

The result is not just compliance: a smaller estate, faster subject access responses, less to search in litigation, and a straight answer when a client asks what you still hold — which, increasingly, they do.


Written by Aino Laaksonen, Chief Information Security Officer at Vaultline. Vaultline provides encrypted document exchange and virtual data rooms to professional services firms across the European Union. See how the platform works, or talk to our team.

Related reading

Ready to stop sending attachments?

Talk to our team about a workspace for your firm, or start with a 14-day evaluation on the Team plan.