Storage limitation

The GDPR principle in Article 5(1)(e): personal data may be kept in a form that identifies people only for as long as the purpose it was processed for requires.

Storage limitation is one of the data protection principles in Article 5(1)(e) of the GDPR, and of the UK GDPR. Personal data is to be kept in a form that permits identification of the people it relates to for no longer than the purposes of the processing require. Longer storage is allowed only for archiving in the public interest, scientific or historical research, or statistical purposes, and then only with Article 89(1) safeguards.

The principle works alongside purpose limitation and data minimisation: once the purpose has been met, the justification for keeping identifiable data ends. In practice it is met through a data retention schedule, followed by deletion or anonymisation. The phrase “in a form which permits identification” matters. Properly anonymised data falls outside the GDPR, whereas pseudonymised data is still personal data, so pseudonymised records remain subject to the limit. Under Article 5(2), the data controller must meet it and be able to show that it does.

Exam relevance: a scenario is likely to describe personal data kept “just in case” after its purpose has ended, or a retention period set with no stated reason. Candidates are expected to recognise storage limitation, to tell it apart from data minimisation (which limits what is collected), and to know that anonymisation, not pseudonymisation, takes data outside the limit.