Skip to content

Creating a Deletion Concept With Retention Periods for Personal Data

Provimedia 4 min read 11 July 2026 2 views
Unternehmerpflichten
Creating a Deletion Concept With Retention Periods for Personal Data
Illustrative image · AI-generated

Personal data from job applications, customer contracts, or newsletters ends up in databases at many companies, and often stays stored there far longer than the GDPR allows.

In short: A deletion concept sets out, for every category of personal data, when it must be deleted once the purpose of processing no longer applies and no statutory retention obligation still exists. The basis is Article 17 GDPR and the storage limitation principle under Article 5(1)(e) GDPR. Without documented deletion periods, fines of up to 20 million euros or 4% of annual turnover are at risk.

What Is a Deletion Concept?

A deletion concept is an internal document that sets out, for every category of data processed in the company, such as customer data, applicant data, or log data, a specific deletion period along with the person responsible and the technical process for deletion. It puts the storage limitation principle from Article 5(1)(e) GDPR into operational practice and makes the right to erasure under Article 17 GDPR actually enforceable for data subjects. The usual starting point is the record of processing activities, from which data categories and storage locations can be derived. This affects not only the core databases of the specialist departments, but also email inboxes, cloud storage, and paper files where the same categories of personal data can be found.

Why Is a Deletion Concept Mandatory?

A deletion concept is mandatory because, under the GDPR, personal data may only be stored for as long as it is needed for the original purpose. Once the purpose no longer applies and no statutory retention obligation still exists, the data must be deleted; without defined periods and routines, that rarely happens systematically in practice. A missing deletion concept is one of the most common findings in data protection audits and can be penalized with fines of up to 20 million euros or 4% of annual turnover. Anyone who has their compliance obligations reviewed as part of a Company Audit therefore almost always runs into the topic of the deletion concept too.

How Do You Create a Deletion Concept in 5 Steps?

A deletion concept is created in five steps that build on each other and take their bearings from the record of processing activities. Instead of inventing a period for every data category individually, many companies work from predefined deletion classes with standard periods, which are then applied to their own data categories. A proven structure for deletion classes and periods is provided by the standard DIN 66398, which has become widely established in practice:

  1. Take over data categories and storage locations from the record of processing activities.
  2. Determine the deletion period for each category (purpose lapse minus statutory retention periods).
  3. Define technical and organizational deletion routines (including for backups and archives).
  4. Document responsibilities and deletion cycles.
  5. Carry out deletions regularly and log them in a verifiable way.

What Takes Precedence: Deletion or Retention Obligation?

Statutory retention obligations for tax purposes take precedence over deletion: personal data may only be deleted once the relevant statutory period has expired, even if the original processing purpose has already lapsed. This order must therefore be firmly anchored in the deletion period for each data category: the purpose lapse is extended by the applicable retention period before the actual deletion is triggered. The same applies equally to backups and archives, which are often overlooked even though the same periods apply there.

How Often Must You Review the Deletion Concept?

The deletion concept should be reviewed annually to capture new data categories, changed retention periods, or changed storage locations promptly. A fixed annual review routine ensures that deletion periods, responsibilities, and the deletions actually carried out continue to match the record of processing activities and are documented in a verifiable way if needed. In addition to the annual review, it is advisable to update the deletion concept whenever a specific occasion arises, for example when a new IT system is introduced or a statutory retention period changes.

What Are the Risks Without a Deletion Concept?

Without a deletion concept, companies risk fines of up to 20 million euros or 4% of annual turnover, since a missing or incomplete deletion concept is a common finding in supervisory authority audits. In addition, data subjects cannot reliably enforce their right to erasure under Article 17 GDPR if no documented periods and responsibilities exist.

Frequently Asked Questions

Who Is Responsible for the Deletion Concept?

Responsibility lies with the company as the data controller; implementation is usually assigned to documented responsibilities per data category, which are recorded in the deletion concept itself.

Does the Deletion Concept Also Apply to Backups?

Yes, the technical and organizational deletion routines must explicitly cover backups and archives too, since personal data may not be retained there for longer than in the production system.

What Is DIN 66398?

DIN 66398 is a standard that provides a proven structure for deletion classes and deletion periods and is often used as a template for creating a company deletion concept.

May Data Be Deleted Immediately After the Purpose Lapses?

Only if no statutory retention obligation still exists. Statutory tax retention periods take precedence over deletion, so data may only actually be deleted once those periods have expired.

How Often Should Deletions Be Documented?

Deletions should be carried out regularly and logged in a verifiable way each time, so that compliance with the defined deletion periods can be demonstrated during audits.

Source: Article 17 GDPR, Article 5(1)(e) GDPR. This article is general information and does not replace legal advice in an individual case. As of July 2026.

Share this article

Stay up to date

Get the latest articles, insights and industry updates straight to your inbox.

Unsubscribe at any time. See our privacy policy.

Decide for yourself what Google shows you

Google lets you choose which sources appear more prominently in your search results: in Top Stories and in AI answers. Two clicks, and you see the sites you trust.

Add provimedia.de to my preferred sources

Ihre Unternehmer­pflichten im Griff

Company Audit erstellt Ihnen in wenigen Minuten eine individuelle Pflichtenliste – mit Fristen-Kalender, Erinnerungen und KI-Assistent. Für Selbständige und KMU.