Data Governance
Guide

GDPR Data Retention: How Long to Keep Customer Data

The GDPR sets no fixed number for how long you may keep customer data — only a principle that it must be as short as the purpose requires. This guide covers where tax law actually sets the floor, how to set and document a period where no law does, and what has to happen once it expires.

Oct 2, 2026
9 min read
GDPR Data Retention: How Long to Keep Customer Data

Ask most SMEs how long they keep customer data and the honest answer is "forever, because nobody told the system to stop." That answer feels safe. It is not. The GDPR (AVG) does not hand you a number to comply with, but it does hand you a principle: you may not keep personal data longer than necessary, and you have to be able to explain why whatever period you chose is the right one. At the same time, other Dutch law — tax law above all — sets hard floors that have nothing to do with what the AVG would otherwise allow. Getting the two confused is how SMEs end up either deleting invoices they were legally required to keep, or holding onto a prospect's email address for six years because nobody built a stop condition.

This guide walks through what actually governs how long you keep data, where the legal floors come from, how to set a period for data that has no floor, and what changes once that period runs out.

The AVG sets no fixed number — that is the first thing to get right

A lot of advice pages imply the GDPR specifies retention periods. It does not. The Autoriteit Persoonsgegevens states this directly: the AVG contains no concrete retention period for personal data, and organisations determine for themselves how long they keep it. The only hard rule is the principle underneath it — you may not retain personal data for longer than the purpose for which you collected it requires. There is, in the AP's own words, no formula for working this out. What there is instead is a test you apply per category of data, based on why you are holding it in the first place.

This cuts both ways for an SME. You are not out of compliance just because you cannot point to an article naming "24 months." But "we've just always kept it" is not a defence either — the AP can ask you to justify a retention period, and "we never set one" does not hold up.

Where the actual floor comes from: other laws, not the AVG

While the AVG leaves the ceiling open, other legislation sets a floor you cannot go under, and tax law is the one that touches nearly every SME. The Belastingdienst requires you to keep your administration for seven years; records relating to immovable property and rights to immovable property must be kept for ten. The clock does not start when a document is created — it starts once the data loses its "current value." The Belastingdienst's own example: a lease running four more years stays part of your active administration for those four years, and only then does the seven-year retention period begin.

Basic bookkeeping data — your debtor and creditor administration, purchase and sales administration, and general ledger — must always be kept for seven years. For other records, you can agree a shorter period directly with the Belastingdienst, including agreements on whether you keep it digitally or on paper. Businesses using the EU's one-stop-shop Union or import scheme for cross-border digital services face a ten-year retention duty on the records tied to those schemes specifically.

Data categoryWhat sets the periodRetention
Invoices, bank statements, purchase/sales and general ledger recordsBelastingdienst (tax administration duty)7 years, starting once the data loses current value
Records on immovable property and related rightsBelastingdienst10 years
Records tied to the EU one-stop-shop Union/import schemeBelastingdienst10 years
Customer data with no other legal floor (CRM records, marketing contacts, support history)AVG storage limitation principleNo fixed number — as short as the purpose requires, set and documented by you

The practical consequence: a customer's invoice has a floor of seven years whether or not you still have a relationship with them, because tax law says so, not because the AVG does. The same customer's newsletter subscription or support ticket history has no such floor — that is squarely an AVG storage-limitation decision, and it is yours to make and justify.

Setting a period for data with no legal floor

For everything that is not pinned down by tax law, the Archiefwet, or an ongoing legal procedure, the AP points to a short set of questions rather than a formula: is there a statutory term you must respect, or an open legal procedure that requires you to keep the data regardless? How long do you actually need the data for the purpose you collected it for — including a legitimate business reason, such as still needing records to follow up on an outstanding invoice? And given that the law's starting assumption is the shortest period that still serves the purpose, can you tighten whatever period you land on?

If you belong to a trade association, the AP suggests checking whether it publishes a code of conduct with customary retention periods for your sector — that is a genuine shortcut worth using before inventing your own number from scratch.

Write the period down, and put it in your privacy statement

Once you have settled on a period, the AP's expectation is explicit: record the retention periods and your reasoning for choosing them — your privacy policy is the natural place for this — so you can account for the decision if the AP ever asks. The AP checks, among other things, whether your justification is reasonable and whether you genuinely kept the period as short as the processing purpose allows.

The periods themselves also belong in your privacy statement, the public-facing document, not just an internal policy. The reasoning is direct: people whose data you process are entitled to know how long you keep it. If someone believes you are holding their data longer than justified, they can ask you to delete it — they have a right to erasure once you no longer need the data, or once the legally determined retention period has expired — and they can file a complaint with the AP if you do not delete it in time.

What happens once the period runs out

Retention policies only work if something happens at the end of them. The AP's guidance is to check periodically whether a retention period has lapsed or the data is no longer necessary, and if either is true, destroy the data or anonymise it. How you destroy it matters: the AP specifically flags that this needs care, especially for sensitive categories like medical data, and notes that systems exist for digitally stored data that delete it automatically at a predetermined point — which is a more reliable mechanism than a recurring item on someone's calendar that eventually gets skipped.

Building this into your systems, not just your policy

None of the above helps if it only lives in a document nobody reopens. A working retention policy tags data by category and purpose inside the systems that hold it — CRM, invoicing software, HR system, backups — so "how long do we keep this" is answered when data is created, not reconstructed from memory when the AP asks. A few things separate a policy on paper from one that actually runs:

  • Tie retention rules to the system, not to a person's memory. If the rule lives only in someone's head or a policy document on a shared drive, it survives until that person leaves or the drive gets reorganised.
  • Separate what has a legal floor from what does not, at the data-model level if you can. Invoice data and CRM marketing data sitting in the same table with the same deletion job is how one gets deleted too early or the other kept for years past its justified purpose.
  • Decide what "deleted" means for your backups before you need the answer. A deletion request or an expired retention period that only removes a record from the live database but leaves it recoverable in six months of backups has not actually been resolved — settle how your backup cycle interacts with deletion before it comes up as a live question.
  • Review retention settings at least annually. A period that was defensible when you set it can become indefensible as your processing purpose changes — a marketing list built for one campaign that is still active two years later needs a fresh justification, not the original one copied forward.

This is exactly the kind of governance work that pays off when it is built into how your data is structured and processed, rather than bolted on as a policy document after the fact.

Common mistakes

  • Treating "no fixed AVG period" as "no obligation." The absence of a specific number in the regulation is not the absence of a duty to set, justify and document one.
  • Applying one retention period to everything. Invoices, support tickets and marketing contacts are different categories with different justifications and, often, different legal floors — a single blanket period rarely holds up for all of them.
  • Never revisiting the number. A period that was defensible when set can drift out of line with the purpose that justified it, especially once the backing business reason has quietly disappeared.

FAQ

How long may I keep customer data under the AVG? There is no fixed number in the regulation itself. You determine the period based on how long you actually need the data for the purpose you collected it for, keep it as short as that purpose allows, and document your reasoning. Where another law — most commonly tax law — sets a specific term, that term applies regardless of what the AVG would otherwise allow.

What is the retention period for invoices and bookkeeping records? Seven years under Belastingdienst rules, starting once the data loses its current value rather than from the invoice date itself. Records on immovable property, and records tied to the EU's one-stop-shop Union or import scheme, must be kept for ten years.

Do I have to state my retention periods in my privacy statement? Yes. The AP expects the periods to be stated in your privacy statement so the people whose data you process know how long you keep it, in addition to recording your reasoning internally, for instance in your privacy policy.

What happens if I keep data longer than I can justify? Someone can ask you to delete data you no longer need or that has passed its legal retention period, and they can complain to the AP if you do not act on that request in time. The AP can also ask you to account for a retention period directly and assess whether your justification is reasonable.

Where this fits with the rest of your data setup

A retention policy only works if the systems holding your data can actually enforce it. Our Data & Databases team builds the governance and access structure — tagging, lifecycle rules, deletion jobs — that turns a written retention policy into something your database and CRM actually do automatically, instead of a document nobody reopens until an audit. Where retention intersects with broader access and identity questions, our Cybersecurity & Identity team can review who can reach that data in the meantime, and for how long.

AVG
GDPR
Data Governance
MKB

Related Articles

Managed IT

What Does Managed IT Cost for SMBs? Prices Per User (2026)

How much does managed IT support really cost for an SMB in the Netherlands? This guide breaks down price-per-user tiers, what each package includes, one-off and per-server costs, and how to compare quotes without surprises in 2026.

Read More
Cybersecurity

NIS2 for SMBs: What the Law Means and What You Must Arrange

The Dutch Cyberbeveiligingswet (NIS2) lands in 2026 and brings duty of care, a 24-hour reporting duty and personal director liability. Here is who is in scope, what you must arrange, and a practical step-by-step plan for SMBs.

Read More
Managed IT

How to Choose the Right IT Partner for Your SMB (Checklist)

Choosing an IT partner is a multi-year decision that touches every part of your business. This practical checklist covers the questions to ask, the red flags to avoid, how to read an SLA, and how to compare managed service providers fairly.

Read More

Need Help with Your IT Infrastructure?

Let's discuss how we can help transform your IT operations with modern solutions.