Data retention purge
None of the held texts sets a fixed period on this consumer; every row below reads no period set by the text. Paste one job that feeds this consumer, for example pii_retention_purge, weekly, and the register reads its period against the clocks below, names the gap in hours, and carries the question for its owner.
Matched on the job name or the consumer column by these words: purge, retention job, erasure, ttl, delete old, retention purge, expire, retention purge.
The clock each rule sets
| Regime | Clock | Clause |
|---|---|---|
| GDPR | no clock | GDPR Art. 5 Principles relating to processing of personal data |
Questions this page answers
How often does GDPR require data retention purge?
The held text of GDPR Art. 5 (Principles relating to processing of personal data) sets no fixed period: no period set by the text. Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.
What does the register ask the owner of a data retention purge job?
Which retention periods does the purge apply, and where are they written down?
The clauses in full
Process personal data lawfully, fairly and in a transparent manner; collect it for specified, explicit and legitimate purposes and do not process it further in a way incompatible with those purposes; keep it adequate, relevant and limited to what the purpose needs; keep it accurate and up to date, erasing or rectifying inaccurate data without delay; keep it in a form permitting identification no longer than the purpose requires; and secure it against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. The controller is responsible for all six principles and must be able to demonstrate compliance with them.
What an assessor asks to see: The purpose recorded for each processing activity, stated specifically enough that a later use can be tested against it; Retention schedule per data category with the criteria that set each period, and deletion evidence showing the schedule actually runs; Minimisation analysis per collection point showing why each field is necessary for the stated purpose; Accuracy controls: how inaccurate data is detected, and records of rectification or erasure carried out without delay. Where it usually falls short: Purposes written so broadly, for example business purposes or service improvement, that no later use could ever be incompatible with them
Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. Run this job through the register