Retention Periods – How Long Is A Piece Of String?
3rd June 2024
Two recent cases in Europe concern data retention periods, raising the question: how long is too long to retain an individual’s data? In February 2024, the Italian DPA, aka Garante per la Protezione dei dati Personali, fined an Italian public transport company, Trasporto Passeggeri Emilia-Romagna S.p.A. (TPER) €50,000 for breaching the GDPR, specifically by collecting invalid consent for data processing for marketing purposes and profiling and excessive retention of the data. Another similar case involves Garante fining an Italian supermarket chain Coop Italia €90,000 for failing to assist a data subject in exercising their rights and having ‘excessive’ data storage periods. So what defines an ‘excessive’ data storage period? This all depends on the type of data collected and for what purpose.
The TPER Case
In the TPER case, the data controller did not obtain valid consent for using personal data for marketing purposes, i.e. market research, satisfaction surveys, promotions, and phone calls. Personal data was also processed by a third party for an SMS service messaging customers about any changes to the public transport service. The form they provided did not allow for any distinction between mandatory and optional data and failed to inform users that they didn’t have to consent to their data being used for marketing purposes. These actions violate several parts of the GDPR including Article 7(4) about freely given consent upon the performance of a contract, Article 21, which concerns the data subject’s right to object to data processing for marketing purposes, and more.
The Italian DPA authority Garante also ruled that TPER violated data retention rules. The GDPR does not specify a particular time period that the subject’s personal data can be retained, rather it is left up to the data controller to decide this. Article 5(e) of the GDPR states that:
‘Personal data should be […] kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed…’
In the TPER case, personal data was stored for up to 10 years after the expiry of the purchased season ticket, which was decided to be excessive and not in line with the GDPR. TPER as the Controller relied upon the lawful basis of legitimate interests to inform the customer about changes to the service, which would arguably be unnecessary after the season ticket expires, and also for marketing purposes, for which consent was not expressly given in the first place. Garante ordered the TPER to adhere to a maximum retention period of 24 months for marketing purposes and 12 months for profiling purposes.
The Coop Italia Case
Following a complaint made in January 2022, Garante investigated supermarket chain Coop Italia Società Cooperativa’s data policies. In January 2022, the data subject bought an e-sim card from Coop Italia’s phone operator service and subsequently kept receiving promotional text messages from them. The data subject objected to their data being processed for this purpose and filed a data access request. Both their objection and data access request were ignored and they continued to receive promotional messages, so they filed a complaint with Garante.
Upon investigation, Garante found that the data controller Coop Italia was storing personal data from individuals’ social media after they contacted the company through their social media pages. This data included identification, contact details images and more which was then kept for 5 years. Coop Italia was then discovered to be retaining more data including images and video & audio recordings used for promotional purposes for 5 years. Consent was originally obtained for this data to be collected, but the long retention period was deemed excessive by Garante.
In addition to the original complaint about sending promotional messages to customers without their consent, the data retention period for the data obtained specifically from social media communications was ruled as excessive for promotional purposes, and also invasive of an individual’s privacy, especially as they weren’t necessarily Coop Italia’s customers. Coop Italia was found to be in violation of Article 5(1)(e), Article 12(3), Article 15, and Article 21(2) of the GDPR, and fined €90,000.
How Long Can I Keep Data For?
So how long can an organisation keep data? Well that all depends on the reason for the original data collection, the amount of data held and the reasons for it being held for any length of time. Often a Controller will be under a legal obligation, for example, 6 years for tax records, or they may keep medical records for as long as an individual may bring a claim.
However, where a Controller relies upon consent or legitimate interests to process personal data, (please note I am not referring to consent for unsolicited electronic marketing here as that is covered by PECR legislation, albeit that similar rules apply), the consent or legitimate interests will start to decay over time. As a rule of thumb, if a data subject is engaging with a Controller regularly you can continue to process data and engage with the individual until they tell you to stop. If however, they are not engaging or replying, then a reasonable period for a Controller to continue processing personal data would be 24 months. After this time a Controller would have to justify why they are still processing data subject’s information or delete the information no longer ‘necessary’ for the original purpose.
In summary, in order to remain compliant with the GDPR, companies should not retain data for any longer than is necessary, comply swiftly with data access requests, adhere to data minimisation, only keep the data that is necessary and destroy or anonymise the rest.
Author: Paul Adams LLB (HONS)
Paul is an information governance specialist and one of the founder Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.