Legal and compliance
What is Data retention?
How long personal data is kept before deletion. GDPR requires that data is held no longer than necessary for the purpose it was collected for, which means every category needs a stated period and an actual deletion process rather than an intention.
Also called: retention period · storage limitation
Typical periods for a small business site
- Contact form enquiries
- Commonly 12 to 24 months, unless they become customers.
- Order records
- Usually six or seven years, driven by tax law rather than choice.
- Marketing list
- Until withdrawal, with periodic re-confirmation of interest.
- Server logs
- Days to a few months, depending on security needs.
- Analytics
- Whatever the tool is configured to, which is frequently longer than anyone intended.
The gap between policy and reality
Most sites state a retention period and never delete anything. A stated period with no deletion process is worse than no statement, because it documents a rule you are visibly not following. Automate the deletion or shorten the claim.
Deleting is a security measure
Data you no longer hold cannot be breached, subpoenaed, or requested. Retention discipline is the cheapest security control available and the one most consistently skipped.
Where this is covered in depth
A definition can only go so far. Who actually owns your website — a checklist you can verify today covers this properly — 3 minutes, free, no email required.
Who wrote this
Anas Bin Masud builds e-commerce sites and does technical SEO for businesses in the UK, Canada and Pakistan. These definitions come from client work rather than from a content brief — where an entry describes a mistake, it is usually one found on a real site. More about how I work.