Originally Published: 5 Oct 2026
On September 21, 2026, Ireland’s Data Protection Commission (DPC) fined Google €403 million over its processing of location data. One of the infringements concerned data retention. In the announcement, Deputy Commissioner Graham Doyle said: “The retention of users’ location data for longer than necessary aggravated this loss of control.”
A data retention policy decides how long each type of information is kept.

When a retention period expires, the data has to be erased or archived. By then, copies have often been downloaded or exported, and the system that holds the original record can’t reach them.
A retention policy only works if organizations can identify data when its retention period expires, locate the copies that still exist, securely remove them and verify that the erasure was carried out. Compliance decides how long data should be kept, while IT needs a practical way to find it and prove it was removed.
In this article, we cover:
- What a data retention policy is
- What should happen when a retention period expires
- Why expired data survives on endpoints
- Why deleting expired files isn’t enough
- Selective erasure vs. full-disk erasure
- How to apply retention rules on every endpoint
- How to prove expired data was erased
- How to enforce a data retention policy with BCWipe, step by step
What Is a Data Retention Policy?
A data retention policy sets how long each category of data is kept and what happens to it when that period ends. Organizations use one to meet legal requirements and to limit how much data they have to protect. Under the GDPR, the storage limitation principle allows personal data to be kept “for no longer than is necessary” for its purpose. Recital 39 adds that “time limits should be established by the controller for erasure or for a periodic review.”
There is no universal retention period. Periods vary with:
- The type of data and purpose it was collected for
- National laws, such as the labor and tax rules the European Commission cites as examples
- Contracts with customers and suppliers
- Business needs the organization can justify
Periods have to be set category by category. In the European Data Protection Board’s 2026 coordinated enforcement report on the right to erasure, one organization couldn’t match its retention periods to the right data, so it applied the longest one to everything.
What Should Happen When a Retention Period Expires?
Retention policies should already say whether the data is erased, anonymized, moved to an archive or kept under a documented legal hold. Whatever the outcome, actions should be recorded.
For some categories, expiry happens more than once. Data stays in active use for a period, with protection such as encryption if the regulation calls for it. It then moves to archive storage for a longer period and is only erased at the end. Each move is a retention event with its own date and its own action.
| Outcome | When It Applies | What to Check |
| Erase | The data has no remaining legal or business purpose | Every copy is removed, including recoverable remnants |
| Anonymize | The data still has statistical value, but identities are no longer needed | The result can’t be linked back to individuals |
| Archive | Law or contract requires keeping the data, but it’s no longer in active use | The archive is encrypted and has its own end date |
| Legal hold | Litigation or an investigation requires the data | The reason is recorded and the hold is reviewed when the matter closes |
Why Does Expired Data Survive on Endpoints?
Retention rules are often enforced inside the system that holds the original record, so copies made outside that system are left behind. An HR system can delete an application automatically on its expiry date. It can’t reach the CV a hiring manager downloaded or the spreadsheet someone exported for a meeting.
On endpoints, copies of expired data usually survive in places like these:
| Location | How the Copy Got There |
| Desktop and documents folders | Files saved locally for convenience instead of in the system of record |
| Downloads folders | Attachments and reports downloaded from email and business systems |
| Exports | Spreadsheets exported from CRM or HR systems for analysis |
| Duplicate files | The same document saved under several names or in several folders |
| Temporary files | Copies applications create automatically while a file is open |
| Archived copies | ZIP files and old project folders kept “just in case” |
| Deleted files | Copies users deleted normally, still recoverable from free space |
Most of this data sits outside what anyone actively manages, as I describe with the data iceberg. Temporary files are a common example: they can hold fragments of document content and stay on the disk when an application doesn’t remove them.
Copies that outlive their purpose become ROT data: redundant, obsolete or trivial. ROT is what the data minimization principle in GDPR Article 5 is meant to prevent, and it grows with every retention cycle that isn’t enforced. Each extra copy also widens the search when someone asks for their data to be erased and adds to what a breach can expose.
Is Deleting Expired Files Enough?
No, not for sensitive data. Deleting a file removes the reference the operating system uses to find it. The contents stay on the drive until something overwrites them, and widely available recovery tools can bring them back.
For a retention policy, a file deleted at expiry may still be recoverable data kept past its retention period. The same applies to copies users deleted months earlier, whose remnants can remain in free space and file slack. Our post on data erasure vs. deletion explains what happens on the disk.
Secure data deletion, also called data erasure, overwrites the data itself so it can’t be recovered, and erasure software can record that the overwrite happened.
Should You Erase Selected Files or Wipe the Whole System?
Erase selected files when the device stays in service, and wipe the whole system when it leaves service. Retention periods attach to categories of data rather than to devices, so a laptop can stay in use for years while the files on it reach the end of their retention periods at different times.
Wiping the entire laptop to remove one expired folder would also destroy data that is still inside its retention period, along with the working system. Selective erasure removes only the expired files and their remnants. Full-disk erasure belongs at the end of the device’s life, as part of a hardware decommissioning process.
| Selective Erasure | Full-Disk Erasure | |
| When it applies | Data reaches the end of its retention period on a device that stays in use | The device is retired or reassigned |
| What is removed | Selected files and folders, plus remnants in free space and file slack | Everything on the drive, including the OS |
| The device afterwards | Stays in service with other data intact | Blank drive, ready for reuse or disposal |
| How often | Every retention cycle | Once, at the end of the device’s life |
| Evidence | Certificate of Erasure for the selected files | Erasure report for the whole drive |
| Jetico tool | BCWipe | BCWipe Total WipeOut |
How Do You Apply the Same Retention Rules on Every Endpoint?
Apply them centrally, so the same search and the same erasure method run on every machine. Manual cleanup depends on how thoroughly each employee searches, and it leaves no record of what was removed.
| Manual Cleanup By Each User | Central Enforcement | |
| Finding the copies | Each employee searches their own device | One search runs across all endpoints |
| Removing them | Normal deletion, often recoverable | Secure erasure with a defined wiping scheme |
| Consistency | Varies from person to person | The same rules apply on every machine |
| Record | Usually none | Search and erasure reports in one place |
Automation keeps enforcement running between reviews. With BCWipe’s central management, wiping policies can be assigned to individual computers or in bulk, and wiping tasks can run on a schedule. Transparent Wiping also erases files and free space in the background as people work, so files deleted between reviews don’t stay recoverable.
How Do You Prove Expired Data Was Erased?
You keep a record created at the time of erasure. Under the GDPR’s accountability principle, organizations must be able to demonstrate compliance, and Article 30 asks controllers to record “where possible, the envisaged time limits for erasure” in their records of processing. In its recommendations on deletion from backups, the EDPB asks controllers to “verify that erasure has been carried out and be able to demonstrate such erasure.”
A useful erasure record shows:
- The retention rule and data category the action applied to
- The search criteria and date cut-off used to find the data
- The files found, with the computer and path for each
- The action taken and the wiping method or standard used
- The result, with a date and a certificate or log entry
Our post on data wipe software with certificates covers proof of erasure for audits in more detail.
How Do You Enforce a Data Retention Policy with BCWipe?
Each retention rule becomes a repeatable search that finds expired data on every endpoint. The results are then erased or archived, and the record is kept. The steps follow the data retention best practices in the ICO’s storage limitation checklist: know what personal data you hold, justify how long you keep it, set standard retention periods and review data regularly.
Take applications from unsuccessful job candidates as an example. Say your policy keeps them for a set period after a recruitment closes and then erases them. The applicant tracking system can delete its own records on schedule, but the CVs that hiring managers downloaded or saved from email need the steps below.
- Start with an inventory. Run one broad search across endpoints for everything that is sensitive or falls under a retention rule, whatever its category. This step is optional, but it shows where data really sits before the categories are fixed so the policy doesn’t leave blind spots.
- Map each category to its stages and dates. For each category, decide how long it stays in active use and whether it needs protection there, as well as when it moves to an archive and when it’s erased. Then decide which file date starts the clock: creation, last modification or last access. For the CVs, there is no archive stage and the trigger is the date each file was created.
- Build a search for each category. BCWipe Search can find exact matches such as names or reference numbers, types of information through templates and predefined categories, content that resembles sample files and exact duplicates of a known file. For the CVs, uploading a few example CVs lets the AI-powered classification recognize others by their content, even when file names give nothing away. The classification runs locally, so file contents aren’t sent to an outside service.
- Narrow the results by date. Add a date filter that matches the retention trigger, such as files created before the cut-off date. Running the same search with each stage’s cut-off separates data still in active use from data due for archiving or erasure.
- Erase or archive what has expired. Erase the expired files with BCWipe using a recognized wiping scheme. Where the policy calls for long-term storage instead, the files can be copied to an encrypted archive before BCWipe erases them from the endpoint. That second part is easy to overlook. If recoverable traces stay on the laptop, moving the data to cold storage hasn’t reduced what the laptop holds.
- Record the result and repeat. Keep the search report and the erasure report as the record for that retention cycle. Then run the search again at a fixed interval, such as monthly, with the cut-off date moved forward so newly expired files are caught.
Close Out Every Retention Period
The erasure date is often years away when a retention policy is written, and by the time it arrives the data has spread to devices the policy never listed. Setting up the search and the erasure process now means each retention period can end with the data removed and a record of the removal.
Ready to see how BCWipe and BCWipe Search can handle expired data on your endpoints? Try out our data wiping software for free or talk to our Data Protection Specialist.
Frequently Asked Questions (FAQs)
A data retention policy sets how long each category of data is kept. A data deletion policy covers what happens at the end of that period, including the erasure method and how the result is recorded. Many organizations combine both in one document. The GDPR’s accountability principle applies to both, and erasure tools such as BCWipe can produce a Certificate of Erasure as evidence.
The GDPR doesn’t set fixed retention periods. Article 5 allows personal data to be kept only as long as necessary for its purpose, so each organization sets its own periods by category. The European Commission notes that national laws, such as labor and tax rules, can require some data to be kept for a defined period. Controllers also record the envisaged time limits for erasure in their records of processing under Article 30, where possible.
No. Archived data is still held, so the GDPR still applies to it. The UK’s Information Commissioner’s Office (ICO) notes that storing personal data offline reduces the risk of misuse, but it is still processing. An archive therefore needs protection such as encryption and its own end date. When files move from an endpoint to an archive, the copies left on the endpoint should be securely erased with a tool like BCWipe, so the archive holds the only copy.
Yes. Backups hold copies of the same personal data and fall under the same storage limitation principle. In the European Data Protection Board’s coordinated enforcement report on the right to erasure, published in February 2026, half of the responding supervisory authorities raised concerns about how controllers delete personal data from backups. Our breakdown of the report covers practical approaches, such as recording erasure dates and reapplying erasure if an older backup is restored.