Data retention policy

An organisation's rules for how long each kind of data is kept, and how it is deleted when that time is up.

The GDPR’s storage limitation principle requires personal data to be kept in identifiable form no longer than necessary for its purposes (Article 5(1)(e)), and privacy notices must state retention periods or the criteria for them. For vendors, the DPA usually says how long customer data is kept after the contract ends: a term worth watching, because it changes.

Source: GDPR Art. 5(1)(e) ↗

ClauseTrail watches vendors' subprocessor lists, DPAs, privacy policies, terms and AI terms, and tells your team what changed and by when to object.