Do you still need that old data?

Old form entries, abandoned accounts and exports are easy to forget. They still need a reason to stay.

By GDPRFix · Published · 2 min read
AI-assisted reporting and commentary · Official sources linked below.
Practical explainer

Practical explainer; retention decisions depend on purpose and applicable obligations.

What happened

The ICO’s storage-limitation guidance explains that personal information should not be kept longer than necessary for its purposes. Organisations need to decide and justify appropriate retention periods. There is no single GDPR retention period that fits every type of business record.

Source: ICO — original source ↗

What it means for your website

Start with the places your website quietly accumulates information: form submissions in WordPress, copied emails, spreadsheet exports, support tickets and backups. Deleting one visible copy may leave several others. Create a schedule that distinguishes operational data from records that need to be retained for a particular obligation or dispute. Then test the actual deletion process using a safe fixture. Avoid promising a precise deletion period in your policy until the system can follow it. A browser scan cannot inspect your databases or confirm internal deletion; that needs a separate review of the application and your procedures.

Three useful next steps

  1. List the places website information is copied or stored.
  2. Choose and document retention rules by purpose.
  3. Verify that routine deletion works as described.

Sources & context

Official sources consulted on 1 October 2026. A regulator’s announcement records its findings at that time; it is not proof of payment or the outcome of every later appeal.

ICO — original source

Our practical suggestions are GDPRFix commentary. A public website scan cannot establish your full legal position. For advice on a specific obligation or enforcement matter, use a suitably qualified adviser.

Keep reading