Carbon dating your user data
This week, an audit I was helping an organisation with turned up user data that had been fossilising in their systems for, in some cases, over 10 years.
The question then was: what do we do with it? It wasn’t used anymore; most of it dated from a time when they weren’t even offering the same services.
The GDPR doesn’t set a number for this. Article 5(1)(e), the storage limitation principle, just says you keep personal data only as long as it’s necessary for the purpose you collected it for. The exact duration doesn’t matter; what matters is that you can tie it to an actual, documented purpose (that’s what you’ll be asked for).
You’ve probably received emails from software services notifying you your account would be deleted because you hadn’t used it for two years. This is an arbitrary cutoff that seems to have become folklore. But folklore is a good place to start, so we purged all accounts older than that.
The next steps: for each dataset, ask what the original purpose was, whether that purpose is still active, and how long “necessary” is to fulfil it. In some cases there are legal retention duties, like accounting.
Before you end up with a decade-old archive yourself, think about setting up a periodic data clean-up. You’ll be in a stronger legal position, and you limit the damage if you’re ever hacked.
Colin