---
id: KB-TZ-013
url: https://app.codecontract.io/help/traceability-and-compliance/the-deletion-you-do-have-to-do
idioma: en
categoria: trazabilidad
audiencia: administrador
nivel: avanzado
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-TZ-003, KB-TZ-006]
citadoPor: [KB-CF-015, KB-TZ-017]
---

# The deletion you do have to do

_Keeping everything forever is not prudence: in some cases it is a breach._

**Responde a:** when personal data must be deleted · document retention policy · cannot keep everything indefinitely · deleting documents with personal data

The default reflex is to keep everything just in case, and for most documents that is reasonable. For those containing personal data it is not: keeping them beyond what is necessary stops being prudence and becomes a problem.

## The three groups

| Group | Criterion | Examples |
| --- | --- | --- |
| Kept by obligation | A legal period sets the minimum | Tax, employment, safety |
| Kept by interest | While a claim remains possible | Contracts, deliveries, evidence |
| Deleted | When no longer needed for the purpose collected | Rejected applications, visitor logs, ID copies |

> [!IMPORTANT]
> The third group is the one almost nobody has defined, and the only one where not acting is itself the breach. A CV from someone you did not hire four years ago is not kept out of prudence: it is kept because nobody decided what to do with it.

## How to build a policy that runs itself

1. **List the document types you hold** — By type, not by document. Usually fewer than twenty.
2. **Assign a period to each type** — Using the criteria above and, when unsure, asking your advisers.
3. **Have the clock start from an event, not from upload** — "Four years from contract end", not "from when it was uploaded".
4. **And review it annually** — Obligations change and so do the document types you handle.

> [!WARNING]
> The expensive mistake is automatic deletion with no exceptions. If there is open litigation or a live request, retention stops being your decision: you must be able to suspend deletion for what is affected, and know what that is.

## What is not deleted when you delete

**En corto**

- The record that it existed and was deleted, with a date.
- Aggregate data that identifies nobody.
- And anything covered by a different obligation, even from the same file.

The first line matters: being able to show something was deleted when it should have been is as useful as being able to show it was kept.

> [!NOTE]
> If someone exercises their right to erasure, this is already half done: you know where their material is, what can be deleted and what must be kept by obligation, which is exactly what you must tell them.

**How long must each thing be kept?**

It depends on type and country. That is the part to check rather than improvise.

**What if I delete something that was needed?**

Hence assigning periods by type and reviewing them; deleting without criteria is worse than not deleting.

**Can it be automated?**

The warning yes. The decision to delete is better confirmed by a person.

## Ejemplos

**A company keeps CVs from recruitment processes five years old.**

- Defines periods by document type and start event
- Suspends deletion for anything caught by open litigation

→ Stops accumulating data it should not hold and can show when each item was deleted.

**Everything is kept and grows unchecked.**

- Reviews what has passed its period

→ The archive stops growing without criteria.

**Things are deleted without checking whether they had to be kept.**

- Checks the policy before deleting

→ Deleting stops being a gamble.

**A client asks for their material to be deleted.**

- Locates where it appears and acts on the policy

→ The request is handled on a basis.

**Deletion happens and there is no record of it.**

- Records what was deleted and when

→ What was done is demonstrable.

**Nobody is responsible for reviewing the periods.**

- Schedules the periodic review

→ Deletion happens because it is due, not because somebody remembers.
