How long do we keep it? — the CNIL’s practical guide to retention periods and its sector référentiels
GDPR Article 5(1)(e) says personal data may be kept no longer than is necessary for the purpose — and then says nothing about how long that is. Every retention schedule is therefore a set of judgements, and the question a DPO gets asked most is the one the law declines to answer: how long, exactly? In July 2020 the CNIL, working with France’s interministerial archives service, published a 21-page practical guide to reaching that number defensibly, and it has since built a family of sector référentiels — purpose-by-purpose tables giving the period, the phase it applies to and the legal text behind it, with the newest, for HR, published in April 2026. The periods themselves are French law and do not travel. The method does, and it is the most systematic regulator treatment of the question we have found. We summarise it in English below and link the originals.
- Published by
- Commission Nationale de l’Informatique et des Libertés (CNIL), the French supervisory authority, in partnership with the Service interministériel des archives de France (SIAF). We have no relationship with the CNIL and inclusion here is not an endorsement in either direction.
- Type
- A practical guide in question-and-answer form, three chapters: the storage-limitation principle and the three phases of a datum’s life; defining and applying a retention period — sources, who to involve, documentation, information to individuals, privacy by design, how to archive, one datum used for two purposes, the risk of getting it wrong, and a one-page analysis grid; and how the CNIL’s retention référentiels work. The référentiels are separate PDFs, one per sector, laid out as tables: processing activity · detail · period in active use · period in intermediate archiving · legal basis or CNIL reference · date last checked. Currently: health (outside research), health research, medical and paramedical practices, social and medico-social care, and human resources (2026). The HR retention référentiel is distinct from the CNIL’s 2019 reference framework on HR processing, which it complements.
- Versions & language
- Guide: “Version juillet 2020”; 21 pages; no later edition found on cnil.fr — the CNIL’s retention landing page was itself updated 2 April 2026 and still links this version. HR référentiel: published 2 April 2026, updated 20 May 2026, 13 pages. French only — we found no English translation on cnil.fr. Summarised in English on this page; the originals are linked.
- Jurisdiction
- France. The principle is GDPR Art. 5(1)(e), materially identical in UK GDPR, so the method reads across directly. The periods do not: the mandatory durations come from French statute (Code du travail, Code de commerce, Code général des impôts, Code de la sécurité intérieure and others) and the recommended ones from CNIL doctrine. The CNIL is explicit that the legal provisions listed cover French national law only, and that a group established in several countries must check each. A UK schedule takes its statutory periods from UK law (Limitation Act 1980, Companies Act 2006, HMRC and employment rules, sector regulators) and the ICO’s storage-limitation guidance, which asks for a documented retention schedule wherever possible, for regular review with deletion or anonymisation where none exists, and — in the ICO’s own words — not to keep data indefinitely “just in case”, the same point the CNIL makes about archiving au cas où. The ICO notes its page is under review following the Data (Use and Access) Act 2025. The chapter on archives publiques is France-specific and can be skipped by most readers.
- Primary audience
- Whoever owns the retention schedule: DPOs and privacy teams, records and information managers, and the HR, IT and legal colleagues who have to agree a number and then make a system honour it. The HR référentiel is directly useful to anyone with French employees; to everyone else it is a worked example of what a finished sector table looks like.
- Topic tags
- retention · storage limitation · Art. 5(1)(e) · archiving · records management · retention schedule · purge · Art. 30 · privacy notices · HR data
- Availability
- Free PDFs from cnil.fr, no registration. Guide, five sector référentiels, and a landing page (French) that explains the three phases and links everything.
Why it matters
The guide’s first move is the one most schedules skip. It treats a datum’s life as three phases, not one period: base active — everyday use by the teams running the processing, for as long as the purpose needs; archivage intermédiaire — the purpose is achieved, but the data is kept for a legal obligation or a specific, identified administrative or litigation interest, accessible only to specifically authorised people, case by case; and archivage définitif — indefinite retention in the public interest, which in practice concerns public bodies and private bodies with a public-service mission, and almost no one else. The second and third phases are not automatic. Each has to be justified per processing operation, and a selection has to be made of what actually goes into it.
Three things follow from that, and each is stated plainly in the guide.
- “Archiving” is not a way of keeping everything. Intermediate archiving is permitted only if it is necessary and justified; the guide says in terms that data cannot be archived “au cas où” — just in case. Where it is justified, the conditions are specific: select only the data the archiving objective needs; set a period for the archive itself; separate it from the active base, physically or logically; restrict access to authorised people with no ability to modify the data and with access traceability; and apply the same security as the live system. A person exercising their right of access is entitled to their data from the archive too — so the archive must still allow export, access and viewing of an individual’s data, which is the point at which “we just don’t delete anything” stops being an archive at all.
- The period may be a rule rather than a number, and the start may move. Where no statute fixes a period, the controller sets one from the purpose — or, at minimum, sets the criteria for it (the length of the commercial relationship, say). Start dates can be glissants: the guide’s example is prospect data kept until consent is withdrawn or for three years from the last contact initiated by the prospect, so each new contact restarts the clock. One datum used for two purposes carries two periods; deleting it from one processing operation does not require deleting it from the other.
- Three of the failings the CNIL says it meets most often in its inspections are worth reading against your own estate: no retention period defined at all (no policy, data never erased); excessive periods (an old database kept as-is inside the information system); and no purge mechanism (deletion done by hand, at irregular intervals). None of the three is exotic, and the guide’s remedies for them are the ones it sets out elsewhere — the documentation list, the analysis grid, and the automatic, selective purge it asks for at design stage.
The guide then supplies the working tools: a one-page analysis grid that walks a single processing operation through context, active use, intermediate archiving and final disposition, with the questions to ask at each step; a documentation list of what evidences compliance — the Art. 30 register with its periods, a central table of phases and periods per processing operation, the texts and analyses relied on, written instructions to processors, and the procedures for archiving, destruction and access rights; a reminder that privacy notices must state the phases distinctly and, where a number cannot be given, the method of calculation; and, for privacy by design, a short list — define the purpose precisely, identify who needs access in each phase, trace access to archives, build an automatic and selective purge, and verify that any anonymisation actually holds. The Art. 28 point is one sentence and easy to miss: the controller must communicate the applicable periods to its processors, and the processor applies them on instruction.
The référentiels
The référentiels are the second half of the resource and the part that has no equivalent we know of from another supervisory authority. Each row gives a processing purpose, the period in active use, the period in intermediate archiving, the legal basis and the date the reference was last checked, with a colour code: blue for periods a French statute imposes, grey for periods the CNIL recommends, and a third marking where the controller must set the period itself. The CNIL’s landing page adds the practical consequence — a controller may depart from a recommended period provided the choice is documented, and applying the recommended period carries a presumption of conformity. The April 2026 HR retention référentiel covers recruitment, personnel administration, payroll, security of persons and property (including biometric access and CCTV), company vehicles, call recording, collective labour relations, workplace accidents, litigation and pre-litigation, and whistleblowing — and, for a non-French reader, it is chiefly useful as a template: this is what a finished, cited, per-purpose retention table looks like.
Done well, a retention schedule built this way serves both sides. The organisation gets a smaller estate to secure, a shorter answer to a subject access request, and a document that closes the storage-limitation question in a DPIA, an audit or a due-diligence questionnaire in one line. The people whose data it is get the outcome the privacy notice promised — a date after which the organisation genuinely no longer holds it. The aim here is not to hand anyone a schedule; the periods are yours to set and to defend. It is to point at a regulator that has written down how to set them, and we hope you find it useful.
Read alongside NIST SP 800-88 Rev. 2 — Guidelines for Media Sanitization from issue #9, which is where a retention schedule’s last column — the disposal — is answered; the CNIL Practice Guide — Security of Personal Data from issue #6, whose factsheets on access control, logging and end-of-life cover the security the guide asks of an intermediate archive; and the UKAN Anonymisation Decision-Making Framework from issue #7, the reference for the guide’s alternative to erasure at the end of a phase.
