Data Protection HubIndividual TopicsPrinciples Relating to Processing

Storage Limitation (Article 5(1)(e) GDPR)

Storage limitation as data minimization in temporal terms: the duty to erase once the purpose has been achieved, review intervals, erasure concepts, and the privileged treatment of archiving, research and statistical purposes.

Article 5(1)(e) GDPR requires that personal data be kept in a form which permits identification of data subjects only for as long as is necessary for the purposes for which they are processed. The principle is an expression of the principle of proportionality and gives concrete shape to data minimization in temporal terms.

Key takeaways

  • Storage limitation is the temporal dimension of data minimization: data must be erased once the purpose has been achieved or once they lose their relevance to that purpose.
  • The duty to erase is proactive: the controller may not wait until a right to erasure under Article 17(1) GDPR is invoked.
  • The storage period, or the criteria for determining it, must be established internally and documented; in practice this is done by means of erasure concepts and standard review periods.
  • Precautionary storage for unspecified future purposes is impermissible.
  • Archiving, research and statistical purposes enjoy privileged treatment, but only where the safeguards of Article 89(1) GDPR are complied with.

1 Overview

The fact that the Union legislature has cast the temporal dimension as a self-standing principle gives that dimension particular weight and increases the burden of justification borne by the controller. Recital 39, eighth sentence, GDPR expressly requires that the storage period be limited to a "strict minimum".

1.2 Internal determination of the storage period

Under Article 13(2)(a) and Article 14(2)(a) GDPR, the controller must inform the data subject of the period for which the personal data will be stored or, where a specific period cannot be stated, of the criteria used to determine that period. It follows from the link with the accountability principle (Article 5(2) GDPR) that the storage period, or the criteria relied on to determine it, must be established internally, in much the same way as the purpose of the processing. That determination also serves to demonstrate compliance vis-à-vis the supervisory authority.

2 Content of the principle

2.1 Necessity in temporal terms

Article 5(1)(e), first half-sentence, GDPR covers two situations:

  • Achievement of the purpose: once the purpose of the processing has been fulfilled, the basis for storage falls away. The data must be erased.
  • Loss of relevance to the purpose: data may lose their relevance to the purpose even before that purpose has been achieved, for instance because they are no longer up to date or have been superseded by more recent information (CJEU, judgment of 13 May 2014, C-131/12, Google Spain, paras. 93 et seq.).

2.2 Proactive duty to erase

The controller must erase the data on its own initiative; it may not wait until the data subject asserts the right to erasure under Article 17(1) GDPR (CJEU, judgment of 13 May 2014, C-131/12, Google Spain, para. 72; CJEU, judgment of 16 December 2008, C-524/06, Huber, para. 60).

2.3 Regular review

In order to give practical effect to the duty to erase, the controller must review its data holdings at regular intervals (Recital 39, tenth sentence, GDPR). The review intervals must be documented in the records of processing activities pursuant to Article 30(1), second sentence, point (f), GDPR.

Where large data holdings are concerned, it is not necessary to focus on the individual record. In practice, controllers work with "standardized review periods" or with comprehensive erasure concepts that specify when which categories of data are to be erased, whether on a case-by-case basis or at fixed intervals.

2.4 Precautionary storage is impermissible

Where data are no longer necessary for the purpose of the processing, they may not be kept in reserve for unspecified future purposes. The prohibition of precautionary storage follows directly from the interplay between purpose limitation and storage limitation.

3 Privileged purposes

3.1 Archiving purposes, research, statistics

Article 5(1)(e), second half-sentence, GDPR contains an exception in favor of processing for archiving purposes in the public interest, for scientific or historical research purposes, or for statistical purposes. In doing so, the Union legislature takes account of society's interest in functioning research and in the preservation of the collective memory.

3.2 Accompanying safeguards under Article 89 GDPR

Longer storage is permissible only where the technical and organizational measures required by Article 89(1) GDPR are complied with. Under Article 89(1), third sentence, GDPR, the controller must examine whether the purpose can also be achieved with anonymized data. Only where that is not possible may data be processed in identifiable form.

There is a certain tension between the retention rule in Article 5(1)(e), second half-sentence, GDPR and the obligation under Article 89(1), third sentence, GDPR. The retention rule permits storage that is, in a sense, precautionary, covering processing operations that have not yet been specified; as soon as a specific processing operation is carried out, however, it must be examined afresh whether personal data are genuinely necessary for it.

4 Relationship to the other principles

Storage limitation interlocks with purpose limitation: without a specified purpose, no storage period can be determined. It is also dovetailed with accountability, because the controller must be able to demonstrate compliance with erasure periods, and with integrity and confidentiality, because erasure itself constitutes a technical and organizational measure.

Über den Autor

Über den Autor

Dieser Beitrag wurde von Dr. Thomas Helbing, Fachanwalt für IT-Recht in München, verfasst.

Dr. Helbing wird seit 2020 durchgehend bis heute (2026) vom Handelsblatt als einer der „Deutschlands besten Anwälte" im Bereich IT-Recht und Datenschutzrecht ausgezeichnet.

Laut Kanzleimonitor.de (Ausgaben 2024–2026) zählt er zu den führenden Anwälten für Datenschutz und IT-Recht und ist unter den Top-100 Anwälten in Deutschland (2024/25) gelistet. Kanzleimonitor gilt als besonders aussagekräftige Marktstudie, da sie ausschließlich auf persönlichen Empfehlungen von Unternehmensjuristen basiert.

Dr. Helbing verfügt über langjährige Beratungserfahrung im Datenschutz- und IT-Recht und berät Mandanten unterschiedlichster Größen, vom Startup über wachstumsstarke SaaS-Unternehmen und Unicorns bis hin zu internationalen Konzernen.

Sein beruflicher Hintergrund umfasst das gesamte Spektrum der Praxis im IT- und Technologierecht. Er begann seine Laufbahn in einer internationalen Großkanzlei, sammelte anschließend Inhouse-Erfahrung in einem DAX-Unternehmen und ist selbst Unternehmer und Gründer mehrerer digitaler Projekte. Darüber hinaus verfügt er über praktische Programmiererfahrung, wodurch er technische Systeme, Softwarearchitekturen und digitale Geschäftsmodelle nicht nur juristisch, sondern auch aus technischer Perspektive versteht.

Zu seinen Mandanten zählen seit vielen Jahren unter anderem Technologieunternehmen und SaaS-Anbieter, führende deutsche Forschungseinrichtungen sowie eine systemrelevante deutsche Großbank. Seine Beratungsschwerpunkte liegen insbesondere in den Bereichen DSGVO-Compliance, Datenökonomie, SaaS, KI-Regulierung und IT-Vertragsrecht.