Data Retention Laws by Country (2026): GDPR, CJEU and Global Rules

Independently fact-checked against primary sources (last audited August 24, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 24, 2026. · 19 primary sources cited on this page. How we verify our legal content

Data Retention Laws by Country (2026): GDPR, CJEU and Global Rules

Frequently Asked Questions

What is the difference between the GDPR storage-limitation principle and mandatory data retention laws?

The GDPR storage-limitation principle (Article 5(1)(e)) is a privacy protection: it prohibits keeping personal data longer than necessary for the original purpose. Mandatory data retention laws are surveillance tools: they compel internet providers and telecoms to retain subscriber and traffic metadata for a fixed period so law enforcement can access it. Both can apply to the same data simultaneously, creating a lawful retention window between the mandatory minimum and the storage-limitation maximum.

How long can a company keep personal data under the GDPR?

The GDPR sets no specific time limits. Article 5(1)(e) requires personal data be kept no longer than necessary for the purpose collected. Organizations must determine and document retention periods based on their processing purpose, any legal obligations, and sector-specific rules. The EDPB's 2025 enforcement report found most organizations struggle to do this consistently.

What happened to the EU's Data Retention Directive?

The Court of Justice of the EU invalidated the Data Retention Directive (2006/24/EC) in Digital Rights Ireland (Case C-293/12, April 8, 2014), finding that requiring blanket retention of all communications metadata for all users with no differentiation violated Charter rights to privacy and data protection. The European Commission is now consulting on a replacement mandatory retention framework; as of January 2026 legal tracking, the expected timing for a draft proposal had slipped to later in 2026 or early 2027.

Is general telecom metadata retention still allowed in the EU?

No, for most crime-fighting purposes. The CJEU's case law from 2014 to 2022 established that general and indiscriminate retention of all traffic and location data for all users is incompatible with EU law. Only targeted retention (based on person, geography, or category), quick-freeze orders, and real-time surveillance with judicial authorization are permissible. The 2024 La Quadrature du Net II ruling created a narrow exception for IP address retention, which is treated as less intrusive than other metadata.

What happened with India's DPDPA retention rules?

India's DPDPA Rules were finalized on November 13, 2025. The Rules require at least one year of retention for personal data processed under national security and statutory obligations. Large e-commerce platforms, social media intermediaries (20+ million users), and online gaming platforms (5+ million users) face a three-year maximum retention cap. Data fiduciaries must notify users 48 hours before deleting their data if the user has not recently interacted with the platform.

What is the status of Canada's privacy reform?

Canada's Bill C-27, which would have replaced PIPEDA with the Consumer Privacy Protection Act (CPPA), died on the Order Paper when Parliament prorogued in January 2025. A federal election in April 2025 pushed reform further. Canada still operates under PIPEDA, enacted in 2000. Quebec's Law 25 (effective September 2023) provides stronger provincial requirements.

Do litigation holds override data retention policies?

Yes. When litigation is reasonably anticipated, organizations must preserve all potentially relevant data regardless of standard retention schedules. In the US, FRCP Rule 37(e) addresses sanctions for failure to preserve electronically stored information. Under the GDPR, Recital 65 permits retention beyond the original purpose to establish, exercise, or defend legal claims. This obligation continues until the litigation concludes or the hold is formally lifted.

How should personal data be destroyed when the retention period ends?

Most privacy laws require irreversible destruction. NIST SP 800-88 provides methods including physical destruction, cryptographic erasure, and multi-pass overwriting. South Korea requires documented destruction within five days. India requires a 48-hour notice before deletion for certain platforms. Organizations should maintain destruction logs recording date, method, and responsible person. Backup systems require specific deletion procedures; the EDPB found this to be a widespread compliance gap.

Are data retention laws different for health records vs. financial records?

Yes, significantly. Health records typically have longer mandatory retention periods (8-25 years in many jurisdictions) due to ongoing clinical relevance and potential malpractice claims. Financial records generally require 3-10 years depending on the jurisdiction and record type. Each sector has its own regulatory framework. In the US, HIPAA governs health record documentation (6 years) while state medical practice laws typically require 7-10 years for the underlying records.

Can a company use the same retention period for all countries?

Setting retention periods at the longest required period globally is legally conservative but may conflict with data minimization requirements in countries with shorter mandated maximum periods. The safer approach is a jurisdiction-specific retention schedule based on where data subjects reside, with documented legal bases for each period. Multinational organizations should build a cross-border matrix identifying the lawful window between mandatory minimums and storage-limitation maximums for each data category and jurisdiction.

Updates

Replaced a dead India DPDPA citation link with the live official MeitY host, updated three instances of a stale "expected in early 2026" prediction for the EU's mandatory metadata-retention proposal to reflect current tracking (slipped to later 2026 or early 2027), added a missing citation for the EU telecom-retention comparison statistic, and softened the attribution of South Korea's five-day data-destruction window from the PIPA Act itself to its implementing Enforcement Decree.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Major expansion: added two-meanings framework (storage limitation vs mandatory retention), full CJEU case law section (Digital Rights Ireland through La Quadrature du Net II, April 2024), new country sections for Japan, Singapore, South Africa, Mexico; updated India (DPDPA Rules finalized Nov 2025), Canada (Bill C-27 died Jan 2025), UK (DPDI died May 2024; Data Use and Access Act 2025), Australia (Privacy Amendment Act Dec 2024), China (Network Data Security Regulations Jan 2025). Added EU Commission May 2025 metadata retention proposal. Word count expanded from approximately 2,450 to approximately 4,800 words. Title updated to reflect CJEU coverage.

Reviewed and approved by an editor

Sources and References

  1. GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council(eur-lex.europa.eu).gov
  2. GDPR Article 5: Principles Relating to Processing of Personal Data(gdpr-info.eu)
  3. CJEU Digital Rights Ireland (Cases C-293/12 and C-594/12, April 8, 2014)(curia.europa.eu).gov
  4. CJEU Tele2 Sverige and Watson (Cases C-203/15 and C-698/15, December 21, 2016)(eur-lex.europa.eu).gov
  5. CJEU La Quadrature du Net I (Cases C-511/18, C-512/18, C-520/18, C-623/17, October 6, 2020)(curia.europa.eu).gov
  6. CJEU SpaceNet and Telekom Deutschland (Cases C-793/19 and C-794/19, September 20, 2022)(curia.europa.eu).gov
  7. CJEU La Quadrature du Net II (Case C-470/21, April 30, 2024)(eur-lex.europa.eu).gov
  8. EDPB Coordinated Enforcement Action 2025: Implementation of the Right to Erasure (February 2026)(edpb.europa.eu).gov
  9. UK ICO: Storage Limitation Guidance(ico.org.uk).gov
  10. 26 USC 6501: IRS Limitations on Assessment and Collection(law.cornell.edu)
  11. 45 CFR 164.530: HIPAA Administrative Requirements(law.cornell.edu)
  12. 29 CFR 516: FLSA Records to Be Kept by Employers(law.cornell.edu)
  13. 18 USC 1520: SOX Destruction of Corporate Audit Records(law.cornell.edu)
  14. Cal. Civ. Code 1798.100: CCPA Consumer Right to Know(leginfo.legislature.ca.gov).gov
  15. Brazil LGPD: Lei 13.709/2018(planalto.gov.br).gov
  16. China PIPL Full Text (NPC)(npc.gov.cn).gov
  17. China Network Data Security Management Regulations (effective January 1, 2025)(english.www.gov.cn).gov
  18. India DPDPA 2023 Full Text(meity.gov.in).gov
  19. IAPP: India DPDPA Rules Finalized (November 2025)(iapp.org)
  20. South Korea PIPA English Translation(law.go.kr).gov
  21. Australian Privacy Principles (OAIC)(oaic.gov.au).gov
  22. Privacy and Other Legislation Amendment Act 2024 (Cth), Parliament of Australia(aph.gov.au).gov
  23. Canada PIPEDA: Personal Information Protection and Electronic Documents Act, SC 2000, c 5(laws-lois.justice.gc.ca).gov
  24. Singapore PDPA: Data Protection Obligations (PDPC)(pdpc.gov.sg).gov
  25. South Africa POPIA: Section 14 Retention and Restriction of Records(popia.co.za)
  26. NIST SP 800-88 Rev. 1: Guidelines for Media Sanitization(csrc.nist.gov).gov
  27. FRCP Rule 37(e): Failure to Preserve Electronically Stored Information(law.cornell.edu)
  28. Cullen International: Update on National Data Retention Laws in Europe (July 2025)(cullen-international.com)
Share: