Skip to main content
ESSV Log in
Book my call

GDPR for small businesses: how long to keep customer data

GDPR sets no single retention period. Spanish periods for invoices, working-hours records and CCTV by article, how to block data and what to define.

Héctor Redondo, CEO and founder of BAI Business CEO and founder of BAI Business

Published on Reviewed on 7 min Regulation

GDPR for small businesses: how long to keep customer data
Contents
  1. The principle and where the periods come from
  2. Periods set by a rule, one by one
  3. When a customer asks you to delete their data
  4. Data with no legal period: you decide
  5. Common mistakes
  6. Where BAI fits
  7. Frequently asked questions
  8. How long can I keep a customer's data?
  9. How long do invoices have to be kept?
  10. What do I do if a customer asks me to delete their data?
  11. How long can I keep camera footage?
  12. You may also be interested in
  13. Sources

GDPR doesn't give a single period for keeping your customers' data: it requires you not to keep it for longer than necessary for its purpose. The specific number comes from the laws that oblige you to keep certain documents and from what you declare when you collect the data.

Reviewed on 2026-10-10. BAI Business offers a CRM and publishes this article. This is general guidance, not legal advice: for your case, consult a lawyer or your data protection officer.

The principle and where the periods come from

Article 5(1)(e) of Regulation (EU) 2016/679 (GDPR) requires data to be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes of the processing (source: EUR-Lex, accessed on 2026-10-10). It is a principle, not a number. The specific periods come from two places:

  1. The laws that oblige you to keep. There is data you must keep for a minimum time even if the customer asks for it to be deleted.
  2. The purpose you declared. For the rest, you keep the data while it serves that purpose and delete it afterwards.

In addition, Article 13(2)(a) of the GDPR obliges you to inform people, when collecting the data, of the period for which it will be stored or, where that is not possible, of the criteria used to determine it. Your privacy policy must say so.

Periods set by a rule, one by one

What Period Rule Source
Books, correspondence, documentation and business vouchers, such as invoices and contracts Six years from the last entry in the books Article 30(1) of the Commercial Code (Código de Comercio) BOE
Limitation period of the tax authority's right to assess the tax debt Four years Article 66 of the General Tax Act (Ley General Tributaria) BOE
Daily record of employees' working hours Four years Article 34(9) of the Workers' Statute (Estatuto de los Trabajadores) BOE
Video surveillance images One month from capture, except images that evidence acts against people, property or premises Article 22(3) of the LOPDGDD BOE

Accessed on 2026-10-10. For the rest of the data, such as leads, subscribers or CVs, we have not found a single legal period: you define it, document it and comply with it.

When a customer asks you to delete their data

Article 17 of the GDPR recognises the right to erasure, and Article 12(3) sets the time to reply: one month from the request, extendable by a further two months if necessary because of the complexity or the number of requests (accessed on 2026-10-10). Article 17(3)(b) makes an exception for processing necessary for compliance with a legal obligation, such as keeping invoices.

When you can't delete, you block. Article 32 of the LOPDGDD defines blocking as identifying and reserving the data, with technical and organisational measures that prevent its processing, including its display, except to make it available to judges, courts, the Public Prosecutor's Office or the competent authorities, and only during the limitation period of the liabilities. After that period the data must be destroyed. If your system does not allow blocking, the law provides for a secure copy with evidence of the date and that it was not tampered with (accessed on 2026-10-10).

In practice, when you receive a request:

  1. Check whether there is a legal obligation to keep part of the data.
  2. Delete what you don't have to keep and block what you do.
  3. Reply in writing to the requester, saying what you have deleted and what you have blocked and why.
  4. Keep the request and your reply.
  • Leads and contacts who didn't buy. Define how long without active contact you keep them and delete or anonymise them afterwards. A yearly review of the CRM avoids accumulating contacts nobody manages.
  • Newsletter subscribers. Article 21(2) of the GDPR recognises the right to object at any time to processing for direct marketing purposes (accessed on 2026-10-10). An unsubscribe must apply to all lists, not just the one used for the last mailing.
  • CVs. Set a period, tell the candidate and renew or delete the CV when it expires.

Common mistakes

  • Using the same legal basis for everything. Article 6 of the GDPR lists several; legitimate interest requires a balancing test that you must be able to document.
  • A privacy policy with no periods. Saying that you keep the data "as long as necessary" does not satisfy Article 13(2)(a).
  • Forgetting the old CRM. Contacts from years ago accumulate risk without adding value.
  • Believing that company data is not personal. The email name@company.com identifies a natural person and is personal data.

Where BAI fits

BAI Business is a management platform for the self-employed and small businesses. According to the sheet for its CRM solution, each customer, supplier or company has a record with its history, its tags and who looks after it. With that you can mark the status of each contact, but the legal basis and the periods are defined by you as the controller. You can see the CRM on the CRM for your business page.

Frequently asked questions

How long can I keep a customer's data?

The GDPR doesn't set a number: Article 5(1)(e) requires keeping it no longer than necessary for the purposes of the processing. The specific period comes from the sector law that obliges you to keep it, such as the Commercial Code for business documentation, and from the purpose you declared when collecting it.

How long do invoices have to be kept?

Article 30(1) of the Commercial Code obliges you to keep books, correspondence, documentation and business vouchers for six years from the last entry in the books (accessed on 2026-10-10). The General Tax Act sets the limitation period of the tax authority's right to assess the tax debt at four years (Article 66).

What do I do if a customer asks me to delete their data?

You must reply within one month of the request, extendable by two more months in complex cases (Article 12(3) of the GDPR). You don't have to erase what you must keep because of a legal obligation (Article 17(3)(b)); in that case you block it under Article 32 of the LOPDGDD (accessed on 2026-10-10).

How long can I keep camera footage?

Article 22(3) of the LOPDGDD says it must be deleted within a maximum of one month from capture, unless it has to be kept to evidence acts that threaten the integrity of people, property or premises (accessed on 2026-10-10).

You may also be interested in

Sources

Keep reading