Saltar al contenido

Traceability and compliance

The deletion you do have to do

Keeping everything forever is not prudence: in some cases it is a breach.

Updated on 13/08/2026

The default reflex is to keep everything just in case, and for most documents that is reasonable. For those containing personal data it is not: keeping them beyond what is necessary stops being prudence and becomes a problem.

The three groups

GroupCriterionExamples
Kept by obligationA legal period sets the minimumTax, employment, safety
Kept by interestWhile a claim remains possibleContracts, deliveries, evidence
DeletedWhen no longer needed for the purpose collectedRejected applications, visitor logs, ID copies

Important

The third group is the one almost nobody has defined, and the only one where not acting is itself the breach. A CV from someone you did not hire four years ago is not kept out of prudence: it is kept because nobody decided what to do with it.

How to build a policy that runs itself

  1. 1

    List the document types you hold

    By type, not by document. Usually fewer than twenty.

  2. 2

    Assign a period to each type

    Using the criteria above and, when unsure, asking your advisers.

  3. 3

    Have the clock start from an event, not from upload

    "Four years from contract end", not "from when it was uploaded".

  4. 4

    And review it annually

    Obligations change and so do the document types you handle.

Watch out

The expensive mistake is automatic deletion with no exceptions. If there is open litigation or a live request, retention stops being your decision: you must be able to suspend deletion for what is affected, and know what that is.

What is not deleted when you delete

The first line matters: being able to show something was deleted when it should have been is as useful as being able to show it was kept.

Worth knowing

If someone exercises their right to erasure, this is already half done: you know where their material is, what can be deleted and what must be kept by obligation, which is exactly what you must tell them.

How long must each thing be kept?

It depends on type and country. That is the part to check rather than improvise.

What if I delete something that was needed?

Hence assigning periods by type and reviewing them; deleting without criteria is worse than not deleting.

Can it be automated?

The warning yes. The decision to delete is better confirmed by a person.

A real case

The situation

A company keeps CVs from recruitment processes five years old.

What you do

  1. Defines periods by document type and start event
  2. Suspends deletion for anything caught by open litigation

What you get

Stops accumulating data it should not hold and can show when each item was deleted.

The situation

Everything is kept and grows unchecked.

What you do

  1. Reviews what has passed its period

What you get

The archive stops growing without criteria.

The situation

Things are deleted without checking whether they had to be kept.

What you do

  1. Checks the policy before deleting

What you get

Deleting stops being a gamble.

The situation

A client asks for their material to be deleted.

What you do

  1. Locates where it appears and acts on the policy

What you get

The request is handled on a basis.

The situation

Deletion happens and there is no record of it.

What you do

  1. Records what was deleted and when

What you get

What was done is demonstrable.

The situation

Nobody is responsible for reviewing the periods.

What you do

  1. Schedules the periodic review

What you get

Deletion happens because it is due, not because somebody remembers.

This article answers

  • when personal data must be deleted
  • document retention policy
  • cannot keep everything indefinitely
  • deleting documents with personal data