Data Retention & Deletion
Also called: Retention Period · Data Deletion Clause
Data retention provisions define how long data is kept and what happens to it afterwards. Most data-protection regimes require that personal data is not held longer than necessary for the purpose it was collected for, making indefinite retention a compliance risk.
In more detail
Two obligations sit in tension: minimisation principles push toward deleting data promptly, while legal, tax, and dispute-defence needs push toward keeping records. A defensible retention schedule reconciles the two by category rather than applying one blanket period.
In vendor contracts, the operative question is exit: how long after termination does the provider keep your data, in what form can you export it, and when is it actually destroyed — including in backups, which are frequently overlooked.
Backup deletion deserves specific attention. A clause promising deletion within 30 days that silently excludes backup systems may mean data persists far longer than the customer believes.
What our lawyers check
- Whether retention periods are defined by data category or left open-ended
- Post-termination export window and format
- Whether deletion covers backups and archived copies
- Whether deletion can be certified on request
Contracts where this clause matters
Related terms
This definition is general information about commercial contracting practice, not legal advice. How a clause operates depends on the specific wording of your agreement and the law that governs it. For advice on your contract, have it reviewed by a lawyer.
All glossary terms