Insight
Data retention for CRM and marketing systems: deciding what to keep, for how long, and making deletion actually happen
Most CRM and marketing systems only grow. Old leads, former customers, unsubscribed contacts and applicant data accumulate for years because nobody decided when they should go. The GDPR requires storage limitation, while tax and commercial laws require some records to be kept. A retention schedule reconciles both.
The legal principle
Article 5 of the GDPR requires personal data to be kept in a form which permits identification of individuals for no longer than is necessary for the purposes for which it is processed. This storage limitation principle does not set fixed periods. Organisations must decide and justify them based on purpose, and privacy notices must tell people how long data is kept or the criteria used to determine that period.
Other laws pull in the opposite direction. Tax and commercial codes require invoices, accounting records and business correspondence to be kept for years, and limitation periods for legal claims can justify keeping certain records. Retention decisions have to reconcile these obligations rather than apply one blanket rule.
Examples of statutory retention
Retention periods for business records differ by country and document type, and they change. Germany is a useful example. Under commercial and tax law, books, annual financial statements and certain other records must be kept for ten years, commercial letters for six years, and following changes that took effect in 2025, accounting vouchers such as invoices for eight years. Other countries set different periods, so each market’s rules should be checked with tax advisers.
Statutory retention usually applies to the transaction records, not to all marketing data about the same person. The fact that an invoice must be kept for years does not justify keeping a customer in marketing segments or keeping detailed web tracking data for the same period.
Building a retention schedule
A retention schedule lists categories of data, the purpose for each, the legal basis, the retention period or trigger, and what happens at the end: deletion, anonymisation or restricted storage. It should be specific enough that a system administrator can implement it.
- Unconverted leads
- Often a defined period after last meaningful interaction, such as enquiries that never became customers, then deletion or anonymisation.
- Customers
- Contact data for active relationships; transaction records kept for statutory periods after the relationship ends, separated from marketing use.
- Marketing consent records
- Kept while the consent is used and for a period afterwards to prove consent was given, as far as needed for defence of claims.
- Unsubscribes and objections
- A minimal suppression record kept so the person is not contacted again, which is itself a legitimate reason to retain an email address.
- Job applicants
- A limited period after the recruitment decision to handle possible claims, unless the applicant consents to a talent pool.
- Web analytics and tracking
- Periods configured in analytics tools, aligned with the privacy notice and consent settings.
Where deletion fails in practice
Retention schedules often exist on paper while systems keep everything. The CRM has no deletion rules, the email platform keeps contacts after unsubscribes, spreadsheets exported for campaigns sit on shared drives, and backups contain years of data.
Integrations create copies. A lead exists in the website form tool, the CRM, the email platform, the advertising platform audience list and the data warehouse. Deleting it in the CRM does not remove it elsewhere unless integrations propagate deletions or each system applies the same rule.
Another frequent issue is deleting too much. Removing an unsubscribed contact entirely can lead to them being imported again from an old list and emailed. Suppression lists must be preserved, ideally hashed where the tools allow, while other data is deleted.
Automating retention
Most CRM and marketing platforms support workflows, filters or data management features that can identify records past their retention date. Common approaches include a last activity date field maintained by the system, scheduled workflows that flag or delete inactive leads, automatic anonymisation of closed customer records after defined periods, and data warehouse jobs that remove or aggregate old event data.
Before automating deletion, test on copies of data, involve sales and finance so records needed for open deals or statutory retention are not removed, and log what was deleted and when. Deletion is irreversible, so the rules must be reviewed carefully.
Backups follow their own cycle. Deleted data may remain in backups until they expire, which is generally acceptable if backups are secured, not used for other purposes and expire on a defined schedule, and if restored data is re-processed against deletion records.
Why it is worth doing
Retention is not only compliance. Smaller, current databases improve email deliverability, reduce software costs priced by contacts or storage, make segmentation more accurate and reduce the damage of a security breach. Sales teams also work better with a CRM that reflects real, current relationships.
Start with the largest and riskiest data sets, usually CRM contacts, marketing lists and applicant data, and expand from there. This article is a general overview and not legal advice.
Questions
Does the GDPR set fixed retention periods?
No. It requires data to be kept no longer than necessary for its purpose, and organisations must set and justify periods.
How long must invoices be kept in Germany?
Accounting vouchers such as invoices must be kept for eight years following changes effective in 2025, while books and financial statements remain at ten years.
Can we keep unsubscribed contacts?
A minimal suppression record can be kept to ensure they are not contacted again, while other data is deleted.
How long should we keep unconverted leads?
There is no single rule. Many businesses set a defined period after the last meaningful interaction, documented in their retention schedule.
Do backups need to be deleted immediately?
Generally not, if they are secured, expire on a defined cycle and restored data is re-processed against deletion records.
Why does deletion in the CRM not remove data everywhere?
Integrations copy data to other systems, so deletions must propagate or each system must apply the same retention rules.
What should a retention schedule include?
Data categories, purposes, legal bases, retention periods or triggers, and the action taken at the end of the period.
Where this sits in what we do
This article covers one decision inside a wider engagement. The solution page sets out how that engagement runs, what it includes and what it costs to find out.
- Marketing Automation — CRM, lead capture and automated follow-up built as one system — so nothing arrives in an inbox and nothing depends on someone remembering.
- Quote to cash without re-keying: where the handoffs break
- Product data is the e-commerce growth lever nobody budgets for
- Digital marketing in Albania, Kosovo and North Macedonia: one language area, three different markets
- The Digital Services Act for smaller platforms and marketplaces: the obligations that apply below the big-tech tier
- All insight articles
Is your CRM keeping everything forever?
We turn retention schedules into working rules across CRM, email and data systems, with suppression lists preserved and deletions logged.
Get in touch