Skip to content

Anonymise or delete? Document retention under the GDPR

When a retention period ends, you can delete, archive with restricted access or truly anonymise. Why a redacted copy is rarely anonymous.

By Alexis de ONYRI

When a document has served its purpose, you have three options in practice. Delete it. Keep it in a restricted archive, only while a law or a possible dispute requires it. Or anonymise it for real. A redacted copy is usually not anonymous: at best it is pseudonymised, so it stays personal data and needs an end date too.

Take Jane Example, an HR manager. John Sample left in 2023. His contract, payslips and a masked copy of his last appraisal still sit on the shared drive. Which files may stay, and for how long? This is general information as of September 2026, not legal advice.

What does the GDPR say about keeping documents?

Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed. (Article 5(1)(e) GDPR, storage limitation)

EU and UK: data protection law sets no fixed periods. You set them and must be able to justify them. Recital 39 asks for time limits for erasure or a periodic review. The UK regulator, the ICO, warns against keeping data indefinitely just in case. Note the words “in a form which permits identification”: that is why anonymising is an alternative to deleting.

What are your options when the retention period ends?

OptionWhen it fitsWhat it means for the file
DeleteThe default: the purpose is met and nothing requires the file.Remove every copy you control: drives, attachments, downloads, exports, masked versions.
Archive with restricted accessA law requires it, or it may serve as evidence in a dispute.Out of daily use. Only named people open it, for a stated reason. Set an end date, then delete.
AnonymiseYou want the knowledge, not the people: statistics, a model clause, a training case.No one may be identifiable, by you or by anyone else. Removing names is rarely enough. Anonymous data fall outside the GDPR.

France's regulator, the CNIL, describes this life cycle in three phases: active use, intermediate archiving and final archiving, which is mainly for public archives. Its July 2020 guide says intermediate archiving is not automatic. Only specifically authorised people may consult the data, and you cannot archive just in case. Once archiving is no longer justified, the data must be deleted or anonymised.

When can you keep documents longer under Article 89?

Article 5(1)(e) allows longer storage for three purposes only: archiving in the public interest, scientific or historical research, and statistics. Article 89(1) sets the conditions. You need safeguards that respect data minimisation, and they may include pseudonymisation. If the purpose can be met with data that no longer identify anyone, you must work that way.

This is not an escape hatch for old files. Recital 158 describes bodies with a legal obligation to acquire, preserve and give access to records of enduring value. A company that keeps closed contracts in case they are useful one day does not qualify.

Why is a redacted contract rarely anonymous?

Say Jane masks the names in John's employment contract. The copy still shows his start date, job title, salary, team and office. Anyone who worked with him can tell who it is. Recital 26 GDPR asks you to consider all the means reasonably likely to be used to identify a person, by you or by anyone else.

The EU's former Article 29 Working Party made the key point in its 2014 opinion on anonymisation. If you keep the original and hand over a version with identifying data removed or masked, that version is still personal data. The opinion names three risks to test: singling out, linking and inferring.

In September 2025, the EU Court of Justice added a nuance (case C-413/23 P, on the parallel rules for EU institutions). For a recipient with no means to re-identify, pseudonymised data may not be personal data. That relief concerns persons other than the controller. For you, keeping the original, the masked copy remains personal data.

How do you build a simple retention schedule?

The ICO describes a retention schedule as a list of the types of record you hold, what you use them for and how long you intend to keep them. A spreadsheet will do. Article 30 GDPR also asks your record of processing to show, where possible, the planned time limits for erasure.

  1. 1List document types, not single files: contracts, invoices, CVs, payslips.
  2. 2Write the purpose of each type in one line.
  3. 3Check tax, company and employment law for a legal minimum. Note the source.
  4. 4Set the period and the event that starts it, such as the end of the financial year.
  5. 5Choose the end-of-life action: delete, restricted archive or anonymise.
  6. 6List where copies live: drives, mailboxes, exports, masked versions.
  7. 7Name an owner. Review the list every year.
  8. 8Give the period in your privacy notice or, if that is not possible, the criteria used to set it (Article 13(2)(a)).

How long should you keep common documents?

DocumentReason to keepAt the end of the period
Invoices and accounting records (UK company)GOV.UK: keep records for 6 years from the end of the last financial year they relate to, sometimes longer.Restricted archive until then, then delete.
John's personnel fileThe ICO: erase or, if possible, anonymise once employment and all legal duties to keep the data have ended.Archive only what a law requires. Delete the rest, masked copy included.
CV of a rejected candidateEvidence if the decision is challenged. The GDPR sets no fixed period: pick a short one and tell candidates.Delete. No masked copy just in case.
A real case reused for trainingThe lesson, not the person.Rewrite it with fictitious details, or truly anonymise it. Then delete the working copy.
Illustrative cases. Periods depend on country, sector and purpose.

If a masked copy is useful, make sure the text is removed, not just covered. A browser-based option is ONYRI Sanitize: it masks a PDF, a Word file or a scan without uploading it, and exports image-only pages with no text under the masks. No tool detects everything, so review each item. And never let a masked copy replace a record the law asks you to keep.

Frequently asked questions

Does the GDPR say how long to keep a document?
No. It sets the principle, not the periods. You decide from the purpose and from other laws that apply, such as tax or employment rules.
If we delete the original, is the masked copy anonymous?
Not automatically. Deleting the original removes one way back, but the content may still point to the person. Test the three risks: singling out, linking and inferring. If a colleague could still say who it is, treat the copy as personal data.
Is pseudonymisation useful for retention at all?
Yes, as a safeguard. Article 89(1) names it for archiving and research, and it limits harm if a file leaks. But it does not stop the retention clock. Under Article 4(5), data only count as pseudonymised if the additional information, such as the original or the token list, is kept separately and protected.
Can a person ask us to delete a document before the period ends?
Yes, for example when the data are no longer necessary (Article 17(1)(a) GDPR). Article 17(3) lists exceptions, such as a legal duty to keep the data or the defence of legal claims. They last only as long as their reason.

Sources & references

Mask a document without uploading it

ONYRI Sanitize finds names, identifiers, bank details and secrets in a PDF, a Word file or a scan, and masks them in your browser. You check the preview, then download a flattened copy.

Read next