Guide chapters
Retention: How long to store data and evidence
There is no single term 'GDPR = 5 years'. Each data group has its own purpose and basis. The platform implements a retention engine or a regular process that selects the longest applicable term for a specific record, blocks deletion during disputes/incidents, and deletes or anonymizes after the term expires. In MVP, this can be an approved table of terms, periodic export/list of records for deletion, and execution control; an automatic engine is not required.
| Data/Evidence | Hard Rule or Default Policy | What happens after the term expires |
|---|---|---|
| Seller identifiability data from Art. 30 DSA | contractual relationship + 6 months | deletion of data collected solely on this basis; separate DAC7/tax copies remain according to their own basis |
| DAC7 data and evidence | 5 years from the end of the year in which the reporting deadline passed | secure deletion, unless there is an audit/dispute |
| Interface VAT records for relevant e-commerce transactions | 10 years from the end of the transaction year | removal after confirmation of no proceedings and other grounds |
| Operator's accounting and tax documents | according to the specific tax/accounting obligation; calendar approved by accounting | removal after the end of the longest deadline and audits |
| Order snapshot, terms and conditions, complaint, and proof of execution | by default until the end of the period of possible claims and the longer tax obligation; policy approved by legal counsel | anonymization/removal of unnecessary elements; statistics can remain anonymous |
| Marketing consent and its withdrawal | for the duration of use and the period required to defend against claims; recommended starting point: 3 years after withdrawal/last use | removal of evidence data if there is no dispute |
| Rejected seller verification | short period justified by defense against abuse; recommended starting point: 12 months, longer only in case of an incident | removal of documents, retention of a minimal lock entry only with proper grounds |
| Security logs | risk-based period; recommended starting point: 12 months for significant events | rotation; incident subject to legal hold |
| Backups | technical rotation, e.g., 30–90 days, described and tested | data from a deleted record disappears upon rotation and does not return to production after restoration |
Legal hold#
If a complaint, dispute, audit, investigation, product recall, chargeback, breach, or authority proceeding is ongoing, the planned deletion of the data covering it is suspended. In MVP, a permanent flag/note in the existing case and exclusion from the deletion list is sufficient. The lock has an owner, reason, scope, and review date; it cannot become a perpetual 'just in case' storage.
I design multi-vendor platforms with onboarding, payments, moderation, and operational workflows.
Explore marketplace development