Data Protection HubIndividual TopicsPrinciples Relating to Processing

Storage Limitation (Article 5(1)(e) GDPR)

Storage limitation as data minimization in temporal terms: the duty to erase once the purpose has been achieved, review intervals, erasure concepts, and the privileged treatment of archiving, research and statistical purposes.

Article 5(1)(e) GDPR requires that personal data be kept in a form which permits identification of data subjects only for as long as is necessary for the purposes for which they are processed. The principle is an expression of the principle of proportionality and gives concrete shape to data minimization in temporal terms.

Key takeaways

  • Storage limitation is the temporal dimension of data minimization: data must be erased once the purpose has been achieved or once they lose their relevance to that purpose.
  • The duty to erase is proactive: the controller may not wait until a right to erasure under Article 17(1) GDPR is invoked.
  • The storage period, or the criteria for determining it, must be established internally and documented; in practice this is done by means of erasure concepts and standard review periods.
  • Precautionary storage for unspecified future purposes is impermissible.
  • Archiving, research and statistical purposes enjoy privileged treatment, but only where the safeguards of Article 89(1) GDPR are complied with.

1 Overview

The fact that the Union legislature has cast the temporal dimension as a self-standing principle gives that dimension particular weight and increases the burden of justification borne by the controller. Recital 39, eighth sentence, GDPR expressly requires that the storage period be limited to a "strict minimum".

1.2 Internal determination of the storage period

Under Article 13(2)(a) and Article 14(2)(a) GDPR, the controller must inform the data subject of the period for which the personal data will be stored or, where a specific period cannot be stated, of the criteria used to determine that period. It follows from the link with the accountability principle (Article 5(2) GDPR) that the storage period, or the criteria relied on to determine it, must be established internally, in much the same way as the purpose of the processing. That determination also serves to demonstrate compliance vis-à-vis the supervisory authority.

2 Content of the principle

2.1 Necessity in temporal terms

Article 5(1)(e), first half-sentence, GDPR covers two situations:

  • Achievement of the purpose: once the purpose of the processing has been fulfilled, the basis for storage falls away. The data must be erased.
  • Loss of relevance to the purpose: data may lose their relevance to the purpose even before that purpose has been achieved, for instance because they are no longer up to date or have been superseded by more recent information (CJEU, judgment of 13 May 2014, C-131/12, Google Spain, paras. 93 et seq.).

2.2 Proactive duty to erase

The controller must erase the data on its own initiative; it may not wait until the data subject asserts the right to erasure under Article 17(1) GDPR (CJEU, judgment of 13 May 2014, C-131/12, Google Spain, para. 72; CJEU, judgment of 16 December 2008, C-524/06, Huber, para. 60).

2.3 Regular review

In order to give practical effect to the duty to erase, the controller must review its data holdings at regular intervals (Recital 39, tenth sentence, GDPR). The review intervals must be documented in the records of processing activities pursuant to Article 30(1), second sentence, point (f), GDPR.

Where large data holdings are concerned, it is not necessary to focus on the individual record. In practice, controllers work with "standardized review periods" or with comprehensive erasure concepts that specify when which categories of data are to be erased, whether on a case-by-case basis or at fixed intervals.

2.4 Precautionary storage is impermissible

Where data are no longer necessary for the purpose of the processing, they may not be kept in reserve for unspecified future purposes. The prohibition of precautionary storage follows directly from the interplay between purpose limitation and storage limitation.

3 Privileged purposes

3.1 Archiving purposes, research, statistics

Article 5(1)(e), second half-sentence, GDPR contains an exception in favor of processing for archiving purposes in the public interest, for scientific or historical research purposes, or for statistical purposes. In doing so, the Union legislature takes account of society's interest in functioning research and in the preservation of the collective memory.

3.2 Accompanying safeguards under Article 89 GDPR

Longer storage is permissible only where the technical and organizational measures required by Article 89(1) GDPR are complied with. Under Article 89(1), third sentence, GDPR, the controller must examine whether the purpose can also be achieved with anonymized data. Only where that is not possible may data be processed in identifiable form.

There is a certain tension between the retention rule in Article 5(1)(e), second half-sentence, GDPR and the obligation under Article 89(1), third sentence, GDPR. The retention rule permits storage that is, in a sense, precautionary, covering processing operations that have not yet been specified; as soon as a specific processing operation is carried out, however, it must be examined afresh whether personal data are genuinely necessary for it.

4 Relationship to the other principles

Storage limitation interlocks with purpose limitation: without a specified purpose, no storage period can be determined. It is also dovetailed with accountability, because the controller must be able to demonstrate compliance with erasure periods, and with integrity and confidentiality, because erasure itself constitutes a technical and organizational measure.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn