Ch.4 Managing Data, Information and Content Regulation 236 words

Storage limitation: the retention schedule rule

Do not keep personal data longer than needed for its purpose; the exam trap is confusing 'storage limitation' with 'data minimisation'.

Audio

Listen to this page (beta)

Subtitles

Storage limitation means you must delete or anonymise personal data once the original purpose is fulfilled. The key contrast with data minimisation is that minimisation limits what you collect at the start, whereas storage limitation limits how long you keep it. For example, if you collect customer names to process an order, you cannot keep those names for five years just in case of a future marketing campaign — that violates storage limitation unless you have a separate lawful basis and a defined retention period.

To spot the difference in exam questions, look for time-related phrases like 'keep indefinitely', 'retain for ten years', or 'archive without a set expiry' — these flag storage limitation issues, not minimisation ones. A useful trick is to ask: 'Is the problem about what was collected (minimisation) or about how long it is held (storage limitation)?' Also remember that a retention schedule is a practical digital-skill tool: it lists data types, purposes, retention periods, and deletion dates. If a scenario mentions a schedule, the question likely tests storage limitation, not minimisation.

To test yourself quickly, imagine a company that collects email addresses for a one-time newsletter and then keeps them for three years 'just in case'. The violation is storage limitation, not minimisation, because the collection was fine but the retention was excessive. A compact memory aid: 'Collect little, delete early — minimisation for the first, storage limitation for the second.'

Related flashcard

What does GDPR storage limitation mean in practice?

Do not keep personal data longer than needed for its purpose.

Back to flashcard View all flashcards