In diesem Artikel
- As short as possible and as long as necessary: Personal data between deletion periods and retention obligations
- Practical example: How deletion conflicts arise
- What should a GDPR deletion concept include?
- Why deletion concepts require clear processes
- Managing deletion concepts with caralegal
- FAQs on deletion concepts under the GDPR
As short as possible and as long as necessary: Personal data between deletion periods and retention obligations
The GDPR is the central basis for handling the personal data of EU citizens in the EU. However, it does not define fixed deletion deadlines for every type of personal data. Instead, organizations must determine appropriate retention and deletion periods themselves and document how these rules are applied in practice.
The need for a deletion concept follows in particular from Articles 5 and 17 GDPR:
- Under Art. 5(1)(e) GDPR, the principle of storage limitation applies. Personal data must not be kept in a form that permits identification of data subjects for longer than is necessary for the purposes for which the data is processed.
- Under Art. 17 GDPR, data subjects may request erasure of their personal data in specific cases — for example, where the data is no longer necessary for the original purpose, consent has been withdrawn and no other legal basis applies, or the data has been processed unlawfully. At the same time, the right to erasure is not absolute. In many cases, statutory retention obligations also apply, for example for tax, commercial, or legal documentation purposes. This means that deleting personal data too early can be just as problematic as keeping it for too long.
To meet the GDPR’s accountability requirements, organizations should be able to demonstrate that they have clear processes for deleting personal data and that these processes are applied consistently. If deletion is handled inconsistently or personal data is stored for longer than necessary, this can lead to regulatory scrutiny, remediation requirements, or administrative fines.
A practical GDPR deletion concept helps reconcile these requirements. It should be standardized enough for employees to apply in day-to-day operations, while remaining flexible enough to account for retention obligations, purpose-specific storage periods, and potential deletion conflicts.
Practical example: How deletion conflicts arise
The following example shows how complex deletion management can become in practice.
A company uses the same personal data for two processing activities. Processing activity A requires the data for three months, while processing activity B requires it for twelve months.
If the data is no longer needed for activity A after three months, it should no longer be used for that purpose. However, it may still need to be retained for activity B. In practice, this means the organization must restrict or block further use for activity A while ensuring that the data remains available only for the remaining lawful purpose. Final deletion then takes place once the longest applicable retention period has expired and no further legal obligation applies.
It is essential for efficient and reliable work with personal data that the employees involved maintain an overview of all company processes and identify and resolve deletion conflicts. Depending on the scope of the data situation, this can quickly become a full-time job – and therefore expensive for your company. A software solution, on the other hand, can automatically execute the most important processes in the background and then display its findings in a dashboard in such a clear manner that errors are minimized and processes are accelerated.
What should a GDPR deletion concept include?
A GDPR deletion concept should translate legal requirements into clear operational rules. It defines which personal data is stored, why it is stored, how long it may be retained, when it must be deleted, and who is responsible for carrying out or verifying the deletion.
At a minimum, a deletion concept should include the following elements:
- Categories of personal data: Which types of personal data are processed, such as contact details, contract data, employee data, health data, or usage data.
- Purposes of processing: Why the data is processed and for which business process it is needed.
- Applicable retention periods: How long the data must or may be stored, including statutory retention obligations.
- Start date or trigger for the retention period: When the retention period begins, for example after contract termination, account deletion, completion of a transaction, or end of employment.
- Deletion deadlines: When the data must be deleted once the applicable retention period has expired.
- Deletion method: How the data is deleted, anonymized, blocked, or otherwise removed from active processing.
- Responsible department or role: Who is responsible for reviewing, executing, or confirming deletion.
- Exceptions and retention obligations: Whether legal, contractual, or evidentiary obligations prevent immediate deletion.
- Blocking or restriction periods: Whether data must be restricted from further use before final deletion.
- Documentation of deletion: How deletion decisions, actions, and exceptions are recorded for accountability purposes.
- Review cycles: How often deletion rules are reviewed and updated, especially when processes, systems, or legal requirements change.
A well-structured deletion concept therefore does more than define deadlines. It creates a repeatable process that helps organizations apply deletion rules consistently, resolve conflicts between deletion and retention obligations, and demonstrate compliance with the GDPR’s accountability principle.
Why deletion concepts require clear processes
A deletion concept only fulfills its purpose if the defined rules can also be implemented operationally. In practice, deletion management does not only affect privacy documentation, but also involves multiple departments, systems, and responsibilities across the organization.
Especially in larger organizations, deletion processes often span multiple applications, data repositories, and teams. Data may exist simultaneously in HR systems, CRM platforms, ticketing systems, archives, backups, or specialized business applications. Without clearly defined responsibilities and standardized processes, the consistent implementation of deletion rules quickly becomes difficult to manage.
A practical deletion concept therefore translates legal requirements into clear and operational workflows. Employees should be able to understand
- which rules apply to specific types of data,
- which retention obligations take precedence,
- when retention periods begin,
- which systems are affected, and
- who is responsible for documenting or approving decisions.
Conflicts between deletion obligations and statutory retention requirements in particular require a clear decision-making logic. If centralized processes or transparent responsibilities are missing, organizations often face manual coordination efforts, inconsistent deletion decisions, and increased risks during audits or regulatory investigations.
Managing deletion concepts with caralegal
With caralegal’s data protection management software, deletion periods can be managed directly in connection with processing activities, data categories, person groups, systems, and service providers. Legal retention obligations, storage periods, deletion rules, and deletion practices can be documented in a structured way. Potential conflicts — for example where the same personal data is used for different purposes with different retention periods — become easier to identify.
Privacy teams can see which deletion rules apply, where action is required, and how deletion decisions are documented. caralegal helps reduce the risk of inconsistent, premature, or delayed deletion by making deletion periods, responsibilities, and conflicts transparent. Specialist departments receive clearer guidance, while privacy teams maintain a central overview of relevant deletion processes. Extensive export and reporting options also help organizations provide documentation in the event of internal reviews, audits, or supervisory authority inquiries. This supports a consistent, traceable, and scalable approach to the deletion of personal data under the GDPR.






