How long are personal Data retention : what does this involve?

Personal data may only be retained for a limited period of time, which is established either by law (e.g, laws, decrees, regulations) or directly by the French supervisory authority, the CNIL (National Commission for Information Technology and Civil Liberties), through recommendations, simplified standards, etc.

This is undoubtedly the most perilous and complex project to implement, since it involves raising awareness and providing in-house training for the departments concerned.

Fortunately, more and more “line-of-business software,” particularly in the human resources sector, is finally beginning to offer tools that automatically ensure compliance Data retention personal Data retention periods.

However, not only is this not always the case, but there may also be many lingering doubts in day-to-day operations regarding the applicable Data retention period Data retention personal data.

In this article, you will find information on the Data retention periods Data retention personal data applicable to the following areas: Human Resources; Sales and Marketing; Accounting and Employment Records; Security and General Services; and Health.

Master Data retention periods – Practical GDPR guide

What data should you keep? For how long? This guide helps you define and apply Data retention periods Data retention with GDPR. A clear tool to limit risks and structure your data management.

The Data Lifecycle: The Three Phases You Need to Know

Before consulting the tables, it is essential to understand how the CNIL (National Commission for Information Technology and Civil Liberties) Data retention . For each processing Data retention , personal data goes through successive phases. This is what the CNIL (National Commission for Information Technology and Civil Liberties) the “data lifecycle.”

Phase 1: Active Base (Systematic)

The data is accessible on a daily basis to the operational departments that need it to carry out their duties. This is the time required to achieve the initial purpose of the processing: the time needed to manage a hiring process, fulfill a contract, or handle a sales lead.

Phase 2: Interim Archiving (to be evaluated on a case-by-case basis)

The data is no longer needed for its Purpose , but must be retained to comply with a legal obligation or for administrative purposes (typically, in the event of a dispute or audit). This archiving is not automatic. It must be justified and involves a physical or logical separation from the active database: archived data must be accessible only to specifically authorized individuals.

Phase 3: Permanent Archiving (Exceptional)

Data retained indefinitely for public, historical, or statistical purposes. This phase does not apply to ordinary businesses.

Good to know: The retention periods listed in the CNIL (National Commission for Information Technology and Civil Liberties) guidelines CNIL (National Commission for Information Technology and Civil Liberties) either mandatory (required by law or regulation) or recommended (a guideline from which you may deviate, provided you document your decision). Adhering to the recommended retention periods establishes a presumption of compliance during a CNIL (National Commission for Information Technology and Civil Liberties) audit.

Determine the Data retention period

To determine the Data retention period Data retention personal data you process, you must conduct a compliance analysis of your processing activities. It should be noted, however, that the regulations specify a Data retention period Data retention personal Data retention certain processing operations. In other words, in some cases, the Data retention period Data retention personal Data retention is set by specific provisions of the law. For example, Article L3243-4 of the Labor Code requires that an employee’s pay stub (considered here to be personal data) be retained for 5 years.

On the other hand, for the majority of personal data processing operations, the Data retention period is not imposed by any regulation or text. It is up to the data controller to define and determine the Data retention period for the personal data he processes, depending on the Purpose the processing.

Archived data; a person searching through files

What are the tools for defining the duration of Data retention ?

With a mission to assist professionals in achieving GDPR compliance, the CNIL (National Commission for Information Technology and Civil Liberties) developed tools to help determine the applicable Data retention periods Data retention personal data. In addition, the data protection regulator has published a guide to facilitate the implementation of this principle—namely, compliance with Data retention periods.

This guide is intended to answer any questions professionals may have, whether regarding the principle of limiting the retention period for personal data or its practical application. It also includes a Data retention Period Reference Data retention covering both content and usage.

The primary purpose of these Data retention guidelines is to make it easier for a data controller to determine the appropriate retention period.

For each type of processing in a given sector, these guidelines present, in tabular form, the data lifecycle process to be followed (active database or interim archiving). The timeframes listed may therefore be either mandatory or recommended. In the first case, the retention periods are mandated by law, in the form of a legislative or regulatory provision. Conversely, if they are recommended, the retention periods serve as a guideline for data controllers.

Good to know: The government also provides an online simulator that allows you to determine the minimum legal Data retention period Data retention business document based on keywords: service-public.fr/simulateur/calcul/ConserverSesPapiersPro. This tool covers civil documents 

What should be done in the absence of applicable guidelines?

If no guidelines or documents specify the duration applicable to your processing, you must define it yourself. The recommended method:

  1. Identify the Purpose of the data processing.
  2. Identify internal operational needs: How long is the data actually useful to your teams?
  3. Check the available settings in your business tools to apply and automate these time frames.
  4. Define a retention period and documented objective criteria, which you should record in your record of processing activities (Art. 30 GDPR).

Dipeeo Tip: Regardless of the retention period you choose, you must be able to justify it at any time. An audit CNIL (National Commission for Information Technology and Civil Liberties) first CNIL (National Commission for Information Technology and Civil Liberties) on your data processing records: an undocumented retention period is indefensible. At Dipeeo, our legal experts—including e.g—define these Data retention periods for you.

A person holding a computer in a large space

Tables of Data retention Periods Data retention Personal Data

Human Resources

Good to know: On April 2, 2026, the CNIL (National Commission for Information Technology and Civil Liberties) a comprehensive guide on Data retention periods Data retention HR Data retention . The following day, it announced that recruitment is among its priority areas for oversight in 2026. If you use a tool for automatically scoring or ranking applications, make sure your retention periods are properly configured and that your candidates are informed of their right to object to automated decision-making (Art. 22 GDPR). 

Processing activitiesTreatment detailsOperating timesPrescription periodLegal references
Recruitment: Selected CandidateNADuration of the process until a result is obtained, followed by reuse in human resources managementIn accordance with the applicable personnel management rulesCNIL (National Commission for Information Technology and Civil Liberties) HR Guidelines, April 2, 2026
Recruitment: Unsuccessful CandidateResume database / talent pool (with the candidate's information and consent)2 years from the last contact5 years from the date the position was filled (anti-discrimination probationary period)CNIL (National Commission for Information Technology and Civil Liberties) HR Guidelines, April 2, 2026
AbsencesNADuring the term of the employment or assignment contract5 years from employee's departureCNIL (National Commission for Information Technology and Civil Liberties) HR Guidelines, April 2, 2026
Accidents at workNAWhile the accident is being managed5 years from employee's departureArticle D4711-3 of the Labor Code
DirectoryNADuration of contract of employment or service contract for personnel on secondmentNACNIL (National Commission for Information Technology and Civil Liberties) HR Guidelines, April 2, 2026
Pay stubsWorker IdentificationWhile the employee is on the payroll 6 rolling years after the last DSNArticle L102 B of the General Tax Code, Article L243-16 of the Social Security Code, CNIL (National Commission for Information Technology and Civil Liberties) HR Guidelines, April 2, 2026 
Pay stubsProvision of report cards (paper or electronic format)1 month from the date of notification to the employee 5 years from the date of delivery to the employee. Exception for electronic pay stubs: The employer must ensure that the pay stub remains available for 50 years or until the employee reaches retirement age plus 6 years. For claims for payment of wages: 3 years. Article L3243-4 of the Labor Code, Article D3243-8 of the Labor Code, CNIL (National Commission for Information Technology and Civil Liberties) HR Guidelines, April 2, 2026 
Social security chargesURSSAF, pension, provident fund, etc.While processing payroll taxes6 years from the date the items were prepared or received Article L243-16 of the Social Security Code, CNIL (National Commission for Information Technology and Civil Liberties) HR Guidelines, April 2, 2026
GDPR requestsNAWhile the request is being processed5 years from response to requestArticle 2224 of the French Civil Code
Job InterviewNADuring the term of the employment relationship6 yearsCNIL (National Commission for Information Technology and Civil Liberties) HR Guidelines, April 2, 2026
FeesTransport, travel, etc.While fees are being processed5 yearsArticle 2224 of the French Civil Code

Marketing and sales prospecting

Processing activitiesTreatment detailsOperating timesPrescription periodLegal references
Sales Prospecting (B2B and B2C)Prospect Data3 years from the last active contactNACNIL (National Commission for Information Technology and Civil Liberties) Guidelines for Commercial CNIL (National Commission for Information Technology and Civil Liberties)
ChatbotsNA3 years from last contactNACNIL (National Commission for Information Technology and Civil Liberties) Guidelines for Commercial CNIL (National Commission for Information Technology and Civil Liberties)
Contract concluded electronicallyFor contracts over 120 euros onlyFor the entire duration of the business relationship10 yearsArticles L213-1 and D213-2 of the Consumer Code
Paper contractNAFor the entire duration of the business relationship5 yearsArticle L110-4 of the French Commercial Code
Cookie policy Audience measurementA maximum of 13 months from the time the cookies are installed on the deviceNACNIL (National Commission for Information Technology and Civil Liberties) Decision No. 2020-092 of September 17, 2020
CRM ( clients records)NAFor the duration of the business relationship5 yearsArticle L110-4 of the French Commercial Code
Credit Card Security Code (CVV2)NAProhibition of Data retentionNAArticle 5 of GDPR Decision No. 03-034 of June 19, 2003, of the CNIL (National Commission for Information Technology and Civil Liberties)

Accounting and billing

Processing activitiesTreatment detailsOperating timesPrescription periodLegal references
Business correspondencePurchase orders, delivery notes, etc.During the entire processing period10 years from the end of the financial yearArticle L123-22 of the French Commercial Code
clients billingInvoices, estimates, etc.During the entire processing period10 years from the end of the financial yearArticle L123-22 of the French Commercial Code
Accounting books and recordsNAFor the duration of the accounting process10 years from the closing of the book or registerArticle L123-22 of the French Commercial Code
Tax DocumentsTax returns, VAT documentation, etc.During the period of use6 yearsArticle L102 B of the Book of Tax Procedures

Corporate life

Processing activitiesTreatment detailsOperating timesPrescription periodLegal references
Notices of meeting, attendance sheets and proxiesNA3 yearsNAArticle L235-9 of the Commercial Code
Securities orders and registersNA5 yearsNAArticle 2224 of the French Civil Code
MinutesNA5 years from the last recorded minuteNAArticle 2224 of the French Civil Code
Management ReportNA3 yearsNAArticle L235-9 of the Commercial Code
Auditors' ReportNA3 yearsNAArticle L235-9 of the Commercial Code
By-lawsNA5 years from deregistrationNAArticle 2224 of the French Civil Code

Security and general services

Processing activitiesTreatment detailsOperating timesPrescription periodLegal references
Access to premisesNAPeriod of access to premises3 months from accessCNIL (National Commission for Information Technology and Civil Liberties) HR Guidelines, April 2, 2026
Phone callsNA6 months for call historyNACNIL (National Commission for Information Technology and Civil Liberties) Guide: CNIL (National Commission for Information Technology and Civil Liberties) and Privacy
Internet connection datae.g IP address, logs, etc.1 yearNADecree No. 2011-219 of February 25, 2011
Electronic messagingNA6 months for connection historyNACNIL (National Commission for Information Technology and Civil Liberties) Guide: CNIL (National Commission for Information Technology and Civil Liberties) and Privacy
Telephone recordsNA1 yearNAArticle L34-2 of the Postal and Electronic Communications Code
Internet useNA6 months for connection historyNACNIL (National Commission for Information Technology and Civil Liberties) Guide: CNIL (National Commission for Information Technology and Civil Liberties) and Privacy
Video protectionNADuring recording and playback1 month from registrationArticle L252-3 of the Internal Security Code

Health (excluding Research)

Processing activitiesDetailsActive BaseInterim ArchivingLegal references
Patient Record: Healthcare Facility General CaseDuration of operational coverage + 20 years from the last visit for treatmentCase-by-case assessment by the data controllerArticle R. 1112-7 of the CSP
Patient Record: DeathIf death occurs less than 10 years after the last visit10 years from the date of deathCase-by-Case AssessmentArticle R. 1112-7 of the CSP
Patient Record: MinorIf the Data retention period Data retention before the 28th anniversaryData retention until the patient's 28th birthdayCase-by-Case AssessmentArticle R. 1112-7 of the CSP
Medical or paramedical practicePatient Record5 years from the last procedure15 years on a separate medium with equivalent security conditionsCNIL (National Commission for Information Technology and Civil Liberties) Guidelines: Medical and Paramedical CNIL (National Commission for Information Technology and Civil Liberties)
Retail PharmacyPatient Record3 years from the date of the last procedure15 yearsCNIL (National Commission for Information Technology and Civil Liberties) Guidelines, June 18, 2020
Retail PharmacyPrescription PadNA10 yearsArticle R. 5125-45 of the CSP
Retail PharmacyAccounting Register of Narcotic DrugsNA10 years from the date of their last mentionArticle R. 5132-36 of the CSP
Clinical LaboratoryPatient Record5 years from the last procedure15 yearsCNIL (National Commission for Information Technology and Civil Liberties) Guidelines, June 18, 2020
Shared Medical Record (DMP)NALength of time the patient uses the file10 years from the date the case is closedArticle L. 1111-18 of the CSP
Pharmaceutical Record: Medication DispensingArticle R. 1111-20-2-I-2° of the CSP4 months from the date of entry32 monthsArticle R. 1111-20-12 of the CSP

Health (Research)

Processing activitiesDetailsActive BaseInterim ArchivingLegal references
Interventional Research Involving Human Subjects (RIPH): Compliant with MR-001Data from research participantsUntil the product is launched, or 2 years after the last publication; otherwise, until the final report is signedDuration in accordance with current regulationsMR-001 – CNIL (National Commission for Information Technology and Civil Liberties) Decision CNIL (National Commission for Information Technology and Civil Liberties) dated May 3, 2018
Interventional Research Involving Human Subjects (RIPH): Compliant with MR-001Data on professional speaker the search resultsNo later than 15 years after the end of the last study in which they participatedDuration in accordance with current regulationsMR-001 – CNIL (National Commission for Information Technology and Civil Liberties) Decision CNIL (National Commission for Information Technology and Civil Liberties) dated May 3, 2018
Non-interventional research (RIPH): compliant with MR-003Data of the individuals concerned2 years after the last publication; otherwise, until the final report is signed20 years at mostMR-003 – CNIL (National Commission for Information Technology and Civil Liberties) Decision CNIL (National Commission for Information Technology and Civil Liberties) dated May 3, 2018
Research Not Involving Human Subjects (RNIPH): Compliant with MR-004Data of the individuals concerned2 years after the last publication; otherwise, until the final report is signed20 years at mostMR-004 – CNIL (National Commission for Information Technology and Civil Liberties) Decision CNIL (National Commission for Information Technology and Civil Liberties) dated May 3, 2018
Analyses of PMSI/RPU Data: Compliant with MR-005Data of the individuals concernedTime required on the secure platform + up to 2 years after the last publication. Exporting data outside the platform is prohibited.NAMR-005 – CNIL (National Commission for Information Technology and Civil Liberties) Decision CNIL (National Commission for Information Technology and Civil Liberties) dated June 7, 2018
Studies Using PMSI Data (Healthcare Manufacturers): Compliant with MR-006Data of the individuals concernedTime required within the secure solution + up to 2 years after the last publication. Exporting outside the secure solution is prohibited.NAMR-006 – CNIL (National Commission for Information Technology and Civil Liberties) Decision CNIL (National Commission for Information Technology and Civil Liberties) dated June 7, 2018
Search does not comply with an MRData on Individuals and ProfessionalsA period determined by the data controller, proportionate to the purposes of the researchDuration in accordance with current regulationsArt. 5.1.e GDPR duration subject to approval and specified in the CNIL (National Commission for Information Technology and Civil Liberties) authorization

Duration of data retention in the event of prolonged user inactivity

User accounts (excluding administrator accounts) are deleted after 36 months of complete inactivity. The user is notified 30 days, 15 days, and then 5 days before the account is deleted, so that they can object to the deletion.

The time limit resets to 36 months each time you log in to the app or platform.

In the event of a dispute with the user, the account must be retained for the duration of the dispute.

The deletion of the account implies the deletion of the user account except :

  • administrative data that may be requested by the tax authorities (e.g invoices)
  • administrative data that may be requested by the CNIL (e.g access request),
  • technical data (e.g connection logs and IP address) that may be requested by the police for a maximum period of 12 months
  • data relating to client's misconduct (e.g non-payment, etc.).

Duration of data retention of personal data in the event of termination of the business relationship as a processor

The user may request deletion of his or her account at any time.

Deleting an account means that the account will be archived for a period of 3 months, during which time the user can request to recover their account.

At the end of this 3-month period, the account is automatically deleted, except:

  • administrative data that may be requested by the tax authorities (e.g invoices)
  • administrative data that may be requested by the CNIL (e.g access request),
  • technical data (e.g connection logs and IP address) that may be requested by the police for a maximum period of 12 months
  • data relating to client misconduct (e.g non-payment, etc).
2 people looking at archived files

Data retention Period Data retention CNIL (National Commission for Information Technology and Civil Liberties) Data retention CNIL (National Commission for Information Technology and Civil Liberties) Connection Logs and Tokens

Login logs (IP addresses, session IDs, authentication tokens) are technical data subject to GDPR they can be used to identify a user. Their Data retention period is 12 months; after this period, they must be deleted or anonymized, unless requested by the authorities within that timeframe.

How can these Data retention periods be implemented Data retention

Knowing the timeframes is one thing. Applying them in practice is another. Here are three concrete steps to take:

  • Document this in your processing record. For each processing activity listed, the record must specify the Data retention period Data retention and the rationale for it (reference text or documented reasoning). This is your first line of defense during a CNIL (National Commission for Information Technology and Civil Liberties) audit CNIL (National Commission for Information Technology and Civil Liberties) Art. 30 GDPR).
  • Set up automatic data deletion in your systems. Manual deletion is a source of errors and oversights. Verify that your CRM, HRIS, ATS, and email marketing tools allow you to configure automatic retention periods. The CNIL (National Commission for Information Technology and Civil Liberties) that data has actually been deleted, not just that there was an intention to do so.
  • Separate the active database from the interim archive. Data in the interim archive should not be accessible to all teams. This separation can be physical (a dedicated archive database) or logical (restrictions on access rights within your existing information system).

Tip from Dipeeo: Managing Data retention periods Data retention one of the most time-consuming aspects of GDPR compliance, because it affects all your tools and services. Dipeeo handles your compliance from start to finish. We define the Data retention periods for you and help you implement clear data deletion procedures.

Schedule an appointment with Dipeeo – an external DPO registered with the CNIL (National Commission for Information Technology and Civil Liberties)

Dipeeo
Dipeeo