Privacy policy lacks specific data retention periods
Data retention periods are the specific lengths of time a business keeps different categories of personal information before deleting it. This check looks for those specific periods in the privacy policy, phrases like 'X months' or 'X years' or a named retention schedule. On this site, a privacy policy is present, but no explicit retention period was found for any category of data. GDPR (General Data Protection Regulation) Article 13(2)(a) requires privacy policies to state explicit retention periods, and European regulators have specifically cited missing retention periods as an enforcement finding in 2024 and 2025. A policy that says data is kept 'as long as necessary' without ever defining what that means is treated as incomplete. Your legal team should add explicit periods per data category to the policy, for example 'Customer account data: 7 years post-closure. Marketing data: 24 months.' This requires deciding on actual retention periods for each type of data the business holds first, then documenting them, which typically takes about two hours once those decisions are made.
Why this matters
GDPR (General Data Protection Regulation) Article 13(2)(a) requires privacy policies to state explicit retention periods, and European regulators have specifically cited missing retention periods as an enforcement finding in 2024 and 2025. A policy that says data is kept 'as long as necessary' without ever defining what that means is treated as incomplete.
How to fix it
Your legal team should add explicit periods per data category to the policy, for example 'Customer account data: 7 years post-closure. Marketing data: 24 months.' This requires deciding on actual retention periods for each type of data the business holds first, then documenting them, which typically takes about two hours once those decisions are made.