Skip to content
+370 5 212 1506 info@dat.lt

How long to keep personal data when the law sets no retention period

23 September 2026 · Good to know

For most of the data an ordinary organisation processes, the law sets no specific retention period. There is a principle: Article 5 GDPR requires data to be kept for no longer than is necessary for the purposes for which it is processed. The organisation sets the period itself, and it must be able to explain why it chose that length.

This is not a gap. It is a duty to decide and to write that decision down — Article 30(1)(f) GDPR requires retention periods to be stated, where possible, in the records of processing activities, and Article 13(2)(a) GDPR requires them to be given to the individual in the privacy notice.

Below are the periods we use most often in practice, and the mistake that is made almost everywhere.

Telephone call recordings — usually 6 months

For recordings of customer service or sales calls, the usual period is six months. It is long enough to resolve a dispute about an order or a service, and not so long that the recordings turn into a separate mountain of data.

The most important part of this point is not the number but the execution: automatic deletion must be in place, unless a separate decision has been taken to keep a particular recording longer.

Automatic deletion is the part almost nobody implements. The period is written in a document, and the recordings sit there until the disk fills up. During an inspection, or when a data subject makes a request, this comes out with a single question: show us where automatic deletion is set up. If the answer is “in the procedure document”, that means there is none.

If the system has no automatic deletion, the right solution is not a longer period. The right solution is a date marked in the calendar and a person who deletes by hand on that day.

Service contracts — 10 years after the contract ends

For contracts and the documents relating to them, the usual period is ten years from the end of the contract. This period comes not from data protection but from how long a contract can matter in a dispute and in accounting.

A practical note: the period runs from the end of the contract, not from its conclusion. A contract that lasted ten years means its documents are kept for twenty.

Video recordings — in practice usually up to 30 days

For video surveillance recordings, the usual period is up to 30 days. The exception is a specific recording that captured an incident: it is saved separately, with the date and the reason, and from then on follows its own period, tied to the investigation of the incident.

The mistake we often see is the opposite: after an incident, the whole system is switched to longer retention “just in case”. That way one event changes the period for everyone who walked past the camera.

When you base the period on legitimate interest

Some periods come straight from the law — for accounting documents, for employment documents. Others come from the organisation’s own decision, most often based on legitimate interest under Article 6(1)(f) GDPR.

Where a period rests on legitimate interest rather than on the law, it has to be justified in writing. A few sentences are enough: what the interest is, why exactly that length of time, and why a shorter period is not enough.

The reason is practical. The question “why exactly that long?” does not come during an inspection. It comes through a data subject’s request, usually from someone who is already unhappy, and it has to be answered within a time limit. A paragraph written in advance is then the answer. Without it, the answer is written in a hurry and usually sounds like an excuse.

The most common mistake: a period nobody applies

The practical mistake we see most often is not a period that is too long or too short.

The organisation writes the periods into its privacy policy and its records of processing activities, the documents look tidy, and nobody checks whether they are actually applied. CVs from a recruitment that ended long ago sit in an email attachment. A customer list from an old system that nobody uses any more is still on the server.

A period nobody applies is worse than having none. It is a written promise that is not kept, and it was made in writing — to the individual, to the authority and to yourselves.

That means something simple: before writing new periods, it is worth checking whether the ones already written down are being applied.

Four steps that close this off

  • write the periods into the records of processing activities, separately for each processing activity;
  • state them in the privacy notice, so the individual can see them without asking;
  • assign who deletes and when — by name, not just by job title;
  • once a year, check whether deletion is happening, and record that check.

The fourth step is the one that turns the first three into reality. It takes half a day a year.

How to start

If you would like someone to check whether the periods you have written down are actually applied, start with a free assessment: send us your privacy policy or your records of processing activities and tell us which systems you use. We will tell you which periods have no mechanism to enforce them.

A practical step-by-step guide is on Privacio, a site built by Linden: Kaip nustatyti saugojimo terminą, kai jo nenurodo įstatymas? (in Lithuanian). You can also check whether your organisation needs a record of processing activities with the Privacio tool (in Lithuanian).

Email: info@linden.lt

More about this service: GDPR audit, compliance documents and advice.

Get a free assessment

Related articles