How long are personal Data retention : what does this involve?
Personal data may only be retained for a limited period of time, which is established either by law (e.g, laws, decrees, regulations) or directly by the French supervisory authority, the CNIL (National Commission for Information Technology and Civil Liberties), through recommendations, simplified standards, etc.
This is undoubtedly the most perilous and complex project to implement, since it involves raising awareness and providing in-house training for the departments concerned.
Fortunately, more and more “line-of-business software,” particularly in the human resources sector, is finally beginning to offer tools that automatically ensure compliance Data retention personal Data retention periods.
However, not only is this not always the case, but there may also be many lingering doubts in day-to-day operations regarding the applicable Data retention period Data retention personal data.
In this article, you will find information on the Data retention periods Data retention personal data applicable to the following areas: Human Resources; Sales and Marketing; Accounting and Employment Records; Security and General Services; and Health.
Master Data retention periods – Practical GDPR guide
What data should you keep? For how long? This guide helps you define and apply Data retention periods Data retention with GDPR. A clear tool to limit risks and structure your data management.
The Data Lifecycle: The Three Phases You Need to Know
Before consulting the tables, it is essential to understand how the CNIL (National Commission for Information Technology and Civil Liberties) Data retention . For each processing Data retention , personal data goes through successive phases. This is what the CNIL (National Commission for Information Technology and Civil Liberties) the “data lifecycle.”
Phase 1: Active Base (Systematic)
The data is accessible on a daily basis to the operational departments that need it to carry out their duties. This is the time required to achieve the initial purpose of the processing: the time needed to manage a hiring process, fulfill a contract, or handle a sales lead.
Phase 2: Interim Archiving (to be evaluated on a case-by-case basis)
The data is no longer needed for its Purpose , but must be retained to comply with a legal obligation or for administrative purposes (typically, in the event of a dispute or audit). This archiving is not automatic. It must be justified and involves a physical or logical separation from the active database: archived data must be accessible only to specifically authorized individuals.
Phase 3: Permanent Archiving (Exceptional)
Data retained indefinitely for public, historical, or statistical purposes. This phase does not apply to ordinary businesses.
Good to know: The retention periods listed in the CNIL (National Commission for Information Technology and Civil Liberties) guidelines CNIL (National Commission for Information Technology and Civil Liberties) either mandatory (required by law or regulation) or recommended (a guideline from which you may deviate, provided you document your decision). Adhering to the recommended retention periods establishes a presumption of compliance during a CNIL (National Commission for Information Technology and Civil Liberties) audit.
Determine the Data retention period
To determine the Data retention period Data retention personal data you process, you must conduct a compliance analysis of your processing activities. It should be noted, however, that the regulations specify a Data retention period Data retention personal Data retention certain processing operations. In other words, in some cases, the Data retention period Data retention personal Data retention is set by specific provisions of the law. For example, Article L3243-4 of the Labor Code requires that an employee’s pay stub (considered here to be personal data) be retained for 5 years.
On the other hand, for the majority of personal data processing operations, the Data retention period is not imposed by any regulation or text. It is up to the data controller to define and determine the Data retention period for the personal data he processes, depending on the Purpose the processing.
What are the tools for defining the duration of Data retention ?
With a mission to assist professionals in achieving GDPR compliance, the CNIL (National Commission for Information Technology and Civil Liberties) developed tools to help determine the applicable Data retention periods Data retention personal data. In addition, the data protection regulator has published a guide to facilitate the implementation of this principle—namely, compliance with Data retention periods.
This guide is intended to answer any questions professionals may have, whether regarding the principle of limiting the retention period for personal data or its practical application. It also includes a Data retention Period Reference Data retention covering both content and usage.
The primary purpose of these Data retention guidelines is to make it easier for a data controller to determine the appropriate retention period.
For each type of processing in a given sector, these guidelines present, in tabular form, the data lifecycle process to be followed (active database or interim archiving). The timeframes listed may therefore be either mandatory or recommended. In the first case, the retention periods are mandated by law, in the form of a legislative or regulatory provision. Conversely, if they are recommended, the retention periods serve as a guideline for data controllers.
Good to know: The government also provides an online simulator that allows you to determine the minimum legal Data retention period Data retention business document based on keywords: service-public.fr/simulateur/calcul/ConserverSesPapiersPro. This tool covers civil documents
What should be done in the absence of applicable guidelines?
If no guidelines or documents specify the duration applicable to your processing, you must define it yourself. The recommended method:
Identify the Purpose of the data processing.
Identify internal operational needs: How long is the data actually useful to your teams?
Check the available settings in your business tools to apply and automate these time frames.
Define a retention period and documented objective criteria, which you should record in your record of processing activities (Art. 30 GDPR).
Dipeeo Tip: Regardless of the retention period you choose, you must be able to justify it at any time. An audit CNIL (National Commission for Information Technology and Civil Liberties) first CNIL (National Commission for Information Technology and Civil Liberties) on your data processing records: an undocumented retention period is indefensible. At Dipeeo, our legal experts—including e.g—define these Data retention periods for you.
Tables of Data retention Periods Data retention Personal Data
Human Resources
Good to know: On April 2, 2026, the CNIL (National Commission for Information Technology and Civil Liberties) a comprehensive guide on Data retention periods Data retention HR Data retention . The following day, it announced that recruitment is among its priority areas for oversight in 2026. If you use a tool for automatically scoring or ranking applications, make sure your retention periods are properly configured and that your candidates are informed of their right to object to automated decision-making (Art. 22 GDPR).
Processing activities
Treatment details
Operating times
Prescription period
Legal references
Recruitment: Selected Candidate
NA
Duration of the process until a result is obtained, followed by reuse in human resources management
In accordance with the applicable personnel management rules
CNIL (National Commission for Information Technology and Civil Liberties) HR Guidelines, April 2, 2026
Recruitment: Unsuccessful Candidate
Resume database / talent pool (with the candidate's information and consent)
2 years from the last contact
5 years from the date the position was filled (anti-discrimination probationary period)
CNIL (National Commission for Information Technology and Civil Liberties) HR Guidelines, April 2, 2026
Absences
NA
During the term of the employment or assignment contract
5 years from employee's departure
CNIL (National Commission for Information Technology and Civil Liberties) HR Guidelines, April 2, 2026
Accidents at work
NA
While the accident is being managed
5 years from employee's departure
Article D4711-3 of the Labor Code
Directory
NA
Duration of contract of employment or service contract for personnel on secondment
NA
CNIL (National Commission for Information Technology and Civil Liberties) HR Guidelines, April 2, 2026
Pay stubs
Worker Identification
While the employee is on the payroll
6 rolling years after the last DSN
Article L102 B of the General Tax Code, Article L243-16 of the Social Security Code, CNIL (National Commission for Information Technology and Civil Liberties) HR Guidelines, April 2, 2026
Pay stubs
Provision of report cards (paper or electronic format)
1 month from the date of notification to the employee
5 years from the date of delivery to the employee. Exception for electronic pay stubs: The employer must ensure that the pay stub remains available for 50 years or until the employee reaches retirement age plus 6 years. For claims for payment of wages: 3 years.
Article L3243-4 of the Labor Code, Article D3243-8 of the Labor Code, CNIL (National Commission for Information Technology and Civil Liberties) HR Guidelines, April 2, 2026
Social security charges
URSSAF, pension, provident fund, etc.
While processing payroll taxes
6 years from the date the items were prepared or received
Article L243-16 of the Social Security Code, CNIL (National Commission for Information Technology and Civil Liberties) HR Guidelines, April 2, 2026
GDPR requests
NA
While the request is being processed
5 years from response to request
Article 2224 of the French Civil Code
Job Interview
NA
During the term of the employment relationship
6 years
CNIL (National Commission for Information Technology and Civil Liberties) HR Guidelines, April 2, 2026
Fees
Transport, travel, etc.
While fees are being processed
5 years
Article 2224 of the French Civil Code
Marketing and sales prospecting
Processing activities
Treatment details
Operating times
Prescription period
Legal references
Sales Prospecting (B2B and B2C)
Prospect Data
3 years from the last active contact
NA
CNIL (National Commission for Information Technology and Civil Liberties) Guidelines for Commercial CNIL (National Commission for Information Technology and Civil Liberties)
Chatbots
NA
3 years from last contact
NA
CNIL (National Commission for Information Technology and Civil Liberties) Guidelines for Commercial CNIL (National Commission for Information Technology and Civil Liberties)
Contract concluded electronically
For contracts over 120 euros only
For the entire duration of the business relationship
10 years
Articles L213-1 and D213-2 of the Consumer Code
Paper contract
NA
For the entire duration of the business relationship
5 years
Article L110-4 of the French Commercial Code
Cookie policy
Audience measurement
A maximum of 13 months from the time the cookies are installed on the device
NA
CNIL (National Commission for Information Technology and Civil Liberties) Decision No. 2020-092 of September 17, 2020
CRM ( clients records)
NA
For the duration of the business relationship
5 years
Article L110-4 of the French Commercial Code
Credit Card Security Code (CVV2)
NA
Prohibition of Data retention
NA
Article 5 of GDPR Decision No. 03-034 of June 19, 2003, of the CNIL (National Commission for Information Technology and Civil Liberties)
Accounting and billing
Processing activities
Treatment details
Operating times
Prescription period
Legal references
Business correspondence
Purchase orders, delivery notes, etc.
During the entire processing period
10 years from the end of the financial year
Article L123-22 of the French Commercial Code
clients billing
Invoices, estimates, etc.
During the entire processing period
10 years from the end of the financial year
Article L123-22 of the French Commercial Code
Accounting books and records
NA
For the duration of the accounting process
10 years from the closing of the book or register
Article L123-22 of the French Commercial Code
Tax Documents
Tax returns, VAT documentation, etc.
During the period of use
6 years
Article L102 B of the Book of Tax Procedures
Corporate life
Processing activities
Treatment details
Operating times
Prescription period
Legal references
Notices of meeting, attendance sheets and proxies
NA
3 years
NA
Article L235-9 of the Commercial Code
Securities orders and registers
NA
5 years
NA
Article 2224 of the French Civil Code
Minutes
NA
5 years from the last recorded minute
NA
Article 2224 of the French Civil Code
Management Report
NA
3 years
NA
Article L235-9 of the Commercial Code
Auditors' Report
NA
3 years
NA
Article L235-9 of the Commercial Code
By-laws
NA
5 years from deregistration
NA
Article 2224 of the French Civil Code
Security and general services
Processing activities
Treatment details
Operating times
Prescription period
Legal references
Access to premises
NA
Period of access to premises
3 months from access
CNIL (National Commission for Information Technology and Civil Liberties) HR Guidelines, April 2, 2026
Phone calls
NA
6 months for call history
NA
CNIL (National Commission for Information Technology and Civil Liberties) Guide: CNIL (National Commission for Information Technology and Civil Liberties) and Privacy
Internet connection data
e.g IP address, logs, etc.
1 year
NA
Decree No. 2011-219 of February 25, 2011
Electronic messaging
NA
6 months for connection history
NA
CNIL (National Commission for Information Technology and Civil Liberties) Guide: CNIL (National Commission for Information Technology and Civil Liberties) and Privacy
Telephone records
NA
1 year
NA
Article L34-2 of the Postal and Electronic Communications Code
Internet use
NA
6 months for connection history
NA
CNIL (National Commission for Information Technology and Civil Liberties) Guide: CNIL (National Commission for Information Technology and Civil Liberties) and Privacy
Video protection
NA
During recording and playback
1 month from registration
Article L252-3 of the Internal Security Code
Health (excluding Research)
Processing activities
Details
Active Base
Interim Archiving
Legal references
Patient Record: Healthcare Facility
General Case
Duration of operational coverage + 20 years from the last visit for treatment
Case-by-case assessment by the data controller
Article R. 1112-7 of the CSP
Patient Record: Death
If death occurs less than 10 years after the last visit
10 years from the date of death
Case-by-Case Assessment
Article R. 1112-7 of the CSP
Patient Record: Minor
If the Data retention period Data retention before the 28th anniversary
Data retention until the patient's 28th birthday
Case-by-Case Assessment
Article R. 1112-7 of the CSP
Medical or paramedical practice
Patient Record
5 years from the last procedure
15 years on a separate medium with equivalent security conditions
CNIL (National Commission for Information Technology and Civil Liberties) Guidelines: Medical and Paramedical CNIL (National Commission for Information Technology and Civil Liberties)
Retail Pharmacy
Patient Record
3 years from the date of the last procedure
15 years
CNIL (National Commission for Information Technology and Civil Liberties) Guidelines, June 18, 2020
Retail Pharmacy
Prescription Pad
NA
10 years
Article R. 5125-45 of the CSP
Retail Pharmacy
Accounting Register of Narcotic Drugs
NA
10 years from the date of their last mention
Article R. 5132-36 of the CSP
Clinical Laboratory
Patient Record
5 years from the last procedure
15 years
CNIL (National Commission for Information Technology and Civil Liberties) Guidelines, June 18, 2020
Shared Medical Record (DMP)
NA
Length of time the patient uses the file
10 years from the date the case is closed
Article L. 1111-18 of the CSP
Pharmaceutical Record: Medication Dispensing
Article R. 1111-20-2-I-2° of the CSP
4 months from the date of entry
32 months
Article R. 1111-20-12 of the CSP
Health (Research)
Processing activities
Details
Active Base
Interim Archiving
Legal references
Interventional Research Involving Human Subjects (RIPH): Compliant with MR-001
Data from research participants
Until the product is launched, or 2 years after the last publication; otherwise, until the final report is signed
Duration in accordance with current regulations
MR-001 – CNIL (National Commission for Information Technology and Civil Liberties) Decision CNIL (National Commission for Information Technology and Civil Liberties) dated May 3, 2018
Interventional Research Involving Human Subjects (RIPH): Compliant with MR-001
Data on professional speaker the search results
No later than 15 years after the end of the last study in which they participated
Duration in accordance with current regulations
MR-001 – CNIL (National Commission for Information Technology and Civil Liberties) Decision CNIL (National Commission for Information Technology and Civil Liberties) dated May 3, 2018
Non-interventional research (RIPH): compliant with MR-003
Data of the individuals concerned
2 years after the last publication; otherwise, until the final report is signed
20 years at most
MR-003 – CNIL (National Commission for Information Technology and Civil Liberties) Decision CNIL (National Commission for Information Technology and Civil Liberties) dated May 3, 2018
Research Not Involving Human Subjects (RNIPH): Compliant with MR-004
Data of the individuals concerned
2 years after the last publication; otherwise, until the final report is signed
20 years at most
MR-004 – CNIL (National Commission for Information Technology and Civil Liberties) Decision CNIL (National Commission for Information Technology and Civil Liberties) dated May 3, 2018
Analyses of PMSI/RPU Data: Compliant with MR-005
Data of the individuals concerned
Time required on the secure platform + up to 2 years after the last publication. Exporting data outside the platform is prohibited.
NA
MR-005 – CNIL (National Commission for Information Technology and Civil Liberties) Decision CNIL (National Commission for Information Technology and Civil Liberties) dated June 7, 2018
Studies Using PMSI Data (Healthcare Manufacturers): Compliant with MR-006
Data of the individuals concerned
Time required within the secure solution + up to 2 years after the last publication. Exporting outside the secure solution is prohibited.
NA
MR-006 – CNIL (National Commission for Information Technology and Civil Liberties) Decision CNIL (National Commission for Information Technology and Civil Liberties) dated June 7, 2018
Search does not comply with an MR
Data on Individuals and Professionals
A period determined by the data controller, proportionate to the purposes of the research
Duration in accordance with current regulations
Art. 5.1.e GDPR duration subject to approval and specified in the CNIL (National Commission for Information Technology and Civil Liberties) authorization
Duration of data retention in the event of prolonged user inactivity
User accounts (excluding administrator accounts) are deleted after 36 months of complete inactivity. The user is notified 30 days, 15 days, and then 5 days before the account is deleted, so that they can object to the deletion.
The time limit resets to 36 months each time you log in to the app or platform.
In the event of a dispute with the user, the account must be retained for the duration of the dispute.
The deletion of the account implies the deletion of the user account except :
administrative data that may be requested by the tax authorities (e.g invoices)
administrative data that may be requested by the CNIL (e.g access request),
technical data (e.g connection logs and IP address) that may be requested by the police for a maximum period of 12 months
data relating to client's misconduct (e.g non-payment, etc.).
Duration of data retention of personal data in the event of termination of the business relationship as a processor
The user may request deletion of his or her account at any time.
Deleting an account means that the account will be archived for a period of 3 months, during which time the user can request to recover their account.
At the end of this 3-month period, the account is automatically deleted, except:
administrative data that may be requested by the tax authorities (e.g invoices)
administrative data that may be requested by the CNIL (e.g access request),
technical data (e.g connection logs and IP address) that may be requested by the police for a maximum period of 12 months
data relating to client misconduct (e.g non-payment, etc).
Data retention Period Data retention CNIL (National Commission for Information Technology and Civil Liberties) Data retention CNIL (National Commission for Information Technology and Civil Liberties) Connection Logs and Tokens
Login logs (IP addresses, session IDs, authentication tokens) are technical data subject to GDPR they can be used to identify a user. Their Data retention period is 12 months; after this period, they must be deleted or anonymized, unless requested by the authorities within that timeframe.
How can these Data retention periods be implemented Data retention
Knowing the timeframes is one thing. Applying them in practice is another. Here are three concrete steps to take:
Document this in your processing record. For each processing activity listed, the record must specify the Data retention period Data retention and the rationale for it (reference text or documented reasoning). This is your first line of defense during a CNIL (National Commission for Information Technology and Civil Liberties) audit CNIL (National Commission for Information Technology and Civil Liberties) Art. 30 GDPR).
Set up automatic data deletion in your systems. Manual deletion is a source of errors and oversights. Verify that your CRM, HRIS, ATS, and email marketing tools allow you to configure automatic retention periods. The CNIL (National Commission for Information Technology and Civil Liberties) that data has actually been deleted, not just that there was an intention to do so.
Separate the active database from the interim archive. Data in the interim archive should not be accessible to all teams. This separation can be physical (a dedicated archive database) or logical (restrictions on access rights within your existing information system).
Tip from Dipeeo: Managing Data retention periods Data retention one of the most time-consuming aspects of GDPR compliance, because it affects all your tools and services. Dipeeo handles your compliance from start to finish. We define the Data retention periods for you and help you implement clear data deletion procedures.
Schedule an appointment with Dipeeo – an external DPO registered with the CNIL (National Commission for Information Technology and Civil Liberties)