CIPP/E Study Guide
Ch 6.6 - Storage limitation

Storage limitation

Storage limitation (Article 5(1)(e)) means personal data must not be kept longer than necessary for the purpose; once no longer needed, it must be securely deleted or anonymised. Controllers should set retention periods, check for statutory retention requirements, and define a data retention policy with controls (including deleting from backups and third-party clouds). An exception allows longer storage solely for archiving in the public interest, scientific/historical research or statistical purposes. Irreversibly anonymised data may be kept indefinitely.

Article 5(1)(e): data must be kept in a form permitting identification for no longer than is necessary. Once the purpose is met, securely delete or anonymise. Set internal retention periods when the law is silent, and review them as the legal landscape changes.

Storage limitation in practice
StepWhat the controller does
Identify purpose(s)Limit keeping to the period the data is actually needed
Check the lawApply any statutory retention periods (tax, health & safety, employment) - including local laws for global orgs
Law silent?Set internal retention periods; document in a data retention policy
Enforce deletionControls so data is actually deleted - including from backups and third-party clouds
ReviewRegularly update the policy; delete or anonymise once periods expire
The archiving exception

Data may be stored longer only when processed solely for archiving in the public interest, scientific/historical research, or statistical purposes. Otherwise, indefinite retention is permitted only where data is irreversibly anonymised.

Recruitment example

Once recruitment ends, data of unsuccessful candidates must not be kept - unless the candidate consents to remain in the database for future roles. This is storage limitation, not data minimisation.

Key terms - quick answers

What is “Storage limitation”?
Keep data in identifiable form no longer than necessary for the purpose; delete or anonymise when no longer needed.
What is “Data retention policy”?
A documented framework setting how long each category of data is kept and when it is deleted.
What is “Statutory retention period”?
A legally required minimum keeping period (e.g. tax, health and safety, employment) - keeping data to meet it is not 'too long'.