2026 Edition · Sources checked August 20, 2026 · Independent educational resource · Not legal advice
LGPD Compliance & Implementation

LGPD Data Retention: How Long Should Personal Data Be Kept?

Brazil's LGPD does not give every company one magic retention period such as “five years” or “until the customer asks for deletion.” Retention must be tied to purpose, necessity, legal obligations and the end of the processing lifecycle. Articles 15 and 16 define when processing ends and when data may still be conserved after that point. This guide turns those rules into a practical retention schedule for customers, leads, employees, logs, vendors, backups and deleted accounts.

Published: August 20, 2026 Last reviewed: August 20, 2026 Reading time: ~24 minutes By LGPD Brazil Editorial Team

Quick Answer: How long should personal data be kept under the LGPD?

There is no universal LGPD retention period for all personal data. Article 15 says processing ends when the purpose has been achieved or the data is no longer necessary or relevant, when the processing period ends, when the data subject communicates termination in applicable circumstances including consent withdrawal, or when ANPD orders termination because of a violation. Article 16 says personal data should then be deleted within the scope and technical limits of the activity, but permits conservation for four purposes: legal/regulatory obligations, research-body studies, lawful transfer to a third party, or exclusive controller use when the data is anonymized and inaccessible to third parties. A defensible retention schedule therefore assigns a specific purpose, legal reason and deletion trigger to each category of data.

Key Takeaways

  • The LGPD does not say “keep everything for five years.” Retention depends on purpose and applicable law.
  • Purpose and necessity are the starting point. If the purpose is achieved and no further lawful reason exists, continued identifiable retention becomes difficult to justify.
  • Article 15 defines when processing ends. Article 16 defines what may be conserved after that end.
  • Consent withdrawal is not the same as “delete every record about this person.” Other data may have separate legal bases or retention duties.
  • Legal obligations are record-specific. Tax, accounting, labor, consumer, financial, health or sector rules can impose different periods.
  • Backups are part of the retention architecture. “It is in backup” should not become a permanent exemption from deletion governance.
  • Vendors must follow the lifecycle too. A retention schedule that stops at your own database is incomplete.

The LGPD Does Not Create One Universal Retention Period

This is the most important concept in the entire topic. The LGPD is not a general records-management law that says every customer, employee, marketing or security record must be retained for the same number of years.

Instead, retention is connected to the principles of purpose, adequacy and necessity, and to the end-of-processing rules in Articles 15 and 16.

A useful question is not: “How many years does the LGPD require?”

The useful question is: “For this specific processing purpose, when does the need to keep identifiable data end, and does another lawful reason require or permit continued conservation?”

Do not invent a universal retention number simply to make the policy look precise. False precision can be worse than a well-documented purpose-based rule.

Article 15: When Does Processing End?

Article 15 — Four termination triggers

Personal-data processing ends when: (1) the purpose has been achieved or the data is no longer necessary or relevant to that purpose; (2) the processing period ends; (3) the data subject communicates termination, including through consent withdrawal as provided by the LGPD, while public interest is safeguarded; or (4) ANPD determines termination because the LGPD has been violated.

1. The purpose was achieved

Suppose a company collects an identification document solely to verify a one-time eligibility requirement. Once verification is completed, keeping a full copy indefinitely may not be necessary for that original purpose.

The company should ask whether a separate legal or compliance reason justifies continued retention. If not, deletion, anonymization or a narrower retained record may be more appropriate.

2. The defined processing period ended

Some activities are designed with a defined lifecycle: a promotional campaign, temporary event registration, short-term fraud investigation, recruitment cycle or trial account.

The end date should not be merely decorative. When the processing period expires, the organization should execute the documented disposition rule.

3. The data subject communicates termination or withdraws consent

Consent can be withdrawn at any time through a free and facilitated procedure. The withdrawal affects processing that depends on that consent.

It does not automatically mean every system containing any information about the same person must be erased regardless of other purposes. Order records, tax records, fraud records or legal-claim evidence may be governed by different legal bases and retention logic.

4. ANPD orders termination

If processing violates the LGPD, the Agency can determine termination. A retention schedule therefore cannot override a regulatory order or make unlawful processing lawful simply because an internal policy says “keep for seven years.”

Article 16: What Can Be Conserved After Processing Ends?

Article 16 says personal data should be deleted after the end of processing, within the scope and technical limits of the activities, while permitting conservation for four specific purposes.

Article 16(I) Legal or regulatory obligation

The controller may conserve data when another binding rule requires the record to be kept.

Article 16(II) Research-body study

Conservation is allowed for study by a research body, with anonymization whenever possible.

Article 16(III) Transfer to a third party

Conservation/transfer is permitted where the LGPD's processing requirements are respected.

Article 16(IV) is narrower than “we may keep it for internal use.” It permits exclusive controller use only where third-party access is prohibited and the data is anonymized.

Legal or regulatory obligation

This is one of the most common reasons for retaining records after an operational relationship ends. But the company should identify the actual rule and the actual record.

Different legal regimes can impose different retention requirements for invoices, tax documents, employment records, regulated financial records, health documentation or sector-specific evidence. The LGPD does not replace those rules with one universal period.

Research-body study

Article 16 expressly allows conservation for studies by a research body and instructs that anonymization be guaranteed whenever possible. This is not a general “analytics forever” exception for any commercial organization.

Transfer to a third party

Article 16 includes lawful transfer to a third party as an allowed conservation purpose, but the transfer must respect the LGPD's processing requirements. This should not be read as permission to sell expired databases after the original purpose has ended.

Exclusive controller use with anonymization

The fourth exception can support keeping anonymized information exclusively for the controller, provided third-party access is barred. Whether data is actually anonymized should be analyzed using the LGPD's anonymization standard rather than simply replacing names with IDs.

How to Build an LGPD Retention Schedule

A retention schedule converts Articles 15–16 into system behavior. The schedule should be built from the Data Map and ROPA rather than from generic legal templates.

1

Identify the Processing Activity

Start with one coherent activity: customer support, order fulfillment, recruitment, security monitoring, newsletter delivery, employee administration or another defined purpose.

Source: Data Map + ROPA entry.
2

Identify the Data and Systems

List the relevant data categories and every system that holds them: production database, CRM, email platform, SaaS vendor, data warehouse, logs, backups, spreadsheets and archives.

Output: primary copies + secondary copies + vendor copies.
3

Write the Specific Purpose

“Business use” is not a retention purpose. State why the information is still needed: fulfill an order, resolve support history, comply with a tax duty, maintain fraud evidence, administer employment or preserve a lawful legal claim.

Test: could a reviewer understand why identifiable data is still necessary?
4

Identify the Legal Basis and Any External Retention Rule

Record the applicable Article 7 or Article 11 basis for ongoing processing and identify any law or regulation that independently requires the record to be preserved.

Important: cite the real statute/regulation/policy source rather than writing “legal requirement” without evidence.
5

Choose the Retention Trigger

A schedule needs a clock. Use a measurable event: contract end, account closure, invoice date, employee termination, support-ticket closure, consent withdrawal, last account activity, incident-record date or another defensible trigger.

Output: trigger + period + disposition.
6

Define the Final Disposition

At the end of the period, specify what happens: delete, anonymize, archive under a valid retention exception, return to the controller, or another documented action.

Do not use: “review later” as the permanent disposition.
7

Connect Vendors and Backups

The policy must reach cloud vendors, SaaS tools, subprocessors and backup systems. Otherwise the “deleted” record may remain operationally available elsewhere.

Output: deletion API/workflow, vendor SLA, backup rotation and exception handling.
8

Assign an Owner and Review Trigger

Retention rules change when laws, products, vendors or business purposes change. Assign both business and privacy/legal ownership.

Output: owner, source authority, last review and next change trigger.

What Should a Retention Schedule Contain?

Field What to record Example
Processing activitySpecific processing purpose.Customer support ticket management.
Data categoriesRelevant categories, not actual personal-data values.Email, account ID, ticket text, attachments.
Systems / vendorsEvery location where the rule must execute.Helpdesk SaaS, CRM, export archive, backup.
PurposeWhy identifiable data is still needed.Resolve customer issues and maintain service history.
Legal basisArticle 7/11 basis for continuing processing.Contract/service analysis.
Retention authorityLaw, regulation, contract purpose or internal necessity rationale.Documented service need; separate legal duty if applicable.
TriggerEvent that starts the retention clock.Ticket closure or account termination.
PeriodDefined period or rule.Risk/business-defined period validated by owner.
DispositionDelete, anonymize, archive under lawful rule, etc.Delete active record; backup expires on rotation.
ExceptionLegal hold, investigation or other approved reason.Restricted preservation for active dispute.
OwnerBusiness + privacy/legal owner.Support Operations / Privacy.
EvidenceDeletion logs, vendor confirmation, configuration or workflow.Monthly purge report.

Article 8 allows the data subject to revoke consent at any time through a free and facilitated procedure. Article 18 also gives the data subject the right to request deletion of personal data processed with consent, subject to Article 16.

This creates three separate questions:

  1. Does the organization stop the future processing that depended on consent?
  2. Does the individual request deletion of the consent-based data?
  3. Is some information about the same person still lawfully needed for another purpose or basis?

Newsletter example

A person withdraws newsletter consent. The email platform should stop promotional sending for that consent-based purpose. A minimal suppression record may still be appropriate to prevent accidental re-enrollment, but that record needs its own documented purpose, basis, minimization and retention logic.

If the same person is also a customer, the company may still need order or invoice data under separate purposes. The withdrawal does not retroactively erase the transaction itself.

One person can have multiple retention clocks at the same time. Marketing, support, transaction, fraud and legal records should not be merged into one “customer retention” period.

Legal Claims, Investigations and “Legal Holds”

Businesses often say they need to retain everything “in case we get sued.” That is too broad.

The LGPD separately recognizes the regular exercise of rights as a legal basis under Article 7(VI) and, for sensitive data, Article 11(II)(d). Where a concrete dispute, claim, investigation or defense need exists, that can create an ongoing processing purpose that should be documented.

This is conceptually different from saying Article 16 contains a general “litigation hold” exception. Article 16 does not list one in those words.

A defensible legal-hold process should identify:

  • the concrete claim or legal risk;
  • which records are actually relevant;
  • who authorized the hold;
  • who may access the preserved records;
  • when the hold will be reviewed; and
  • what happens when the dispute ends.
“Possible future litigation” should not become an indefinite universal retention basis. The narrower and more concrete the preservation scope, the easier it is to reconcile with necessity and accountability.

How Should Backups Be Handled?

Backups are one of the hardest operational parts of deletion. Article 16 refers to deletion within the scope and technical limits of the activities, but the LGPD does not create a blanket rule that “backups may always be kept forever.”

A practical backup design can distinguish between:

Active systems Remove from ordinary use

Delete or anonymize expired records from production systems according to the schedule.

Backup copies Expire through a defined lifecycle

Use controlled rotation rather than indefinite accumulation, subject to documented legal or resilience needs.

Restore event Prevent resurrection

If an old backup is restored, reapply deletion/suppression states before returned data becomes ordinary operational data.

Also restrict access to backup copies and prevent them from being used for unrelated analytics, marketing or product development merely because deletion from backup is technically inconvenient.

Inactive Accounts and “We May Need It Later”

Dormant accounts often become the largest source of unnecessary personal data. A company may have millions of accounts that have not been used for years but are retained because no team owns deletion.

A better model distinguishes:

  • active account;
  • inactive but recoverable account;
  • closed account with limited post-closure retention;
  • records retained under legal/regulatory obligations;
  • restricted legal-claim or fraud evidence; and
  • anonymized historical analytics.

The lifecycle should be visible in the Data Map, ROPA and Retention Schedule.

See How to Build an LGPD Data Map and LGPD ROPA: How to Build a Record of Processing Activities.

Cookie Retention

ANPD's cookie guidance recommends limiting the duration of persistent cookies as much as possible, considering the purpose for which they were collected and will be processed. The Agency also treats retention period as information that can form part of a cookie policy.

That means a cookie inventory should not contain only “necessary / analytics / advertising.” It should also include the actual expiration or retention behavior.

“Persistent cookie” does not mean “permanent cookie.” Duration should be connected to the actual purpose and minimized where possible.

See LGPD Cookie Consent Requirements.

Retention Must Flow Down to Vendors

ANPD's own privacy notice provides a useful governance example: when the Agency shares personal data with operators, it states that operators must store data securely, retain it only for the instructed period and not subsequently share it without prior authorization.

A private company should apply the same basic discipline to its vendor chain.

Contract retention periodDoes the DPA or service schedule define retention or deletion obligations?
Deletion after terminationWhat happens to active data when the customer closes the account?
BackupsHow long does residual data remain and under what access restrictions?
SubprocessorsDoes deletion propagate downstream?
Rights requestsCan the vendor locate and act on the relevant data?
EvidenceCan the vendor confirm deletion or provide auditable documentation where appropriate?

See LGPD Vendor Compliance.

One Concrete Five-Year Rule: Security Incident Records

Although the LGPD has no universal five-year retention period, ANPD's current Security Incident Regulation creates a specific one: controllers must keep records of personal-data security incidents—including incidents not reported to ANPD or data subjects— for at least five years from the date of the record, subject to additional longer obligations where applicable.

This is a perfect example of why retention must be record-specific. “Five years” is correct for this particular regulatory incident record, but it would be incorrect to turn that into a general five-year rule for every personal-data category in the company.

See LGPD Data Breach Notification.

Example Retention Matrix

The durations below are intentionally expressed as decision logic rather than universal legal numbers. A company must insert the periods supported by its actual laws, contracts, risk and business model.

Data / activity Retention logic Trigger Final action
Customer accountActive service period + documented post-closure need.Account closure.Delete/anonymize except records with separate lawful retention.
Orders / invoicesApplicable legal, tax, accounting and claim-related requirements.Transaction/document date.Delete after all applicable obligations expire, unless another lawful basis remains.
NewsletterWhile consent or other documented basis remains valid and purpose continues.Withdrawal, opt-out, inactivity or purpose change.Remove from marketing; retain only minimal suppression where justified.
Support ticketsService-history and dispute needs proportionate to product/risk.Ticket closure/account end.Delete or minimize; preserve concrete claim evidence separately if needed.
Security logsRisk-based period proportionate to security purpose.Log event date.Delete or aggregate/anonymize after purpose ends.
Security incident recordAt least five years under Resolution 15/2024.Incident record date.Delete after applicable minimum/additional obligations expire.
Recruitment candidateRecruitment purpose + any separately justified future-opportunity or claim period.Recruitment process ends.Delete unless another documented purpose/basis applies.
Cookie / identifierDuration proportionate to specific cookie purpose.Cookie creation / consent withdrawal / expiration.Expire, delete or stop processing as technically applicable.

Data Subject Requests and Retention Exceptions

ANPD's current rights guidance says people can request deletion of consent-based data subject to Article 16, and can request anonymization, blocking or deletion of data that is unnecessary, excessive or processed unlawfully.

When a deletion request arrives, do not answer with a generic: “Our policy says we keep everything for seven years.”

Instead:

  1. identify each processing purpose involving that person's data;
  2. determine which data can be deleted now;
  3. identify any separate legal/regulatory or ongoing lawful purpose;
  4. restrict retained data to that purpose;
  5. propagate deletion/blocking to relevant processors where required; and
  6. explain the factual/legal reason where immediate action cannot be taken.

See LGPD Data Subject Rights.

Common LGPD Retention Mistakes

“LGPD says keep data for five years.”

Incorrect as a general statement. Specific rules can impose five years for particular records—ANPD incident records are one example—but there is no universal LGPD five-year period.

“We keep everything until the customer asks us to delete it.”

Too broad. Article 15 can end processing because the purpose was achieved or the data is no longer necessary even without a request.

“We delete everything immediately after consent withdrawal.”

Also too broad. Consent-based processing should stop as required, but other records may remain under different purposes, legal bases or Article 16 conservation rules.

“Backups do not count.”

Backups should be part of the lifecycle and governed by defined rotation, access and restoration controls.

“Our vendor decides retention.”

The controller should understand and govern how long operators and subprocessors retain personal data for controller-directed processing.

“Legal claims justify keeping the whole database forever.”

A concrete rights/claim purpose can justify targeted preservation, but indefinite blanket retention is difficult to reconcile with necessity and accountability.

15-Point LGPD Retention Review

1. Every ROPA activity has a retention ruleNo blank or generic “indefinite” fields.
2. The rule has a purposeWhy is identifiable data still needed?
3. The rule has a legal basisDocument the Article 7/11 basis for ongoing processing.
4. External legal requirements are citedName the actual law/regulation where mandatory retention applies.
5. The trigger is measurableAccount closure, invoice date, ticket closure, employment end, etc.
6. The disposition is definedDelete, anonymize, restricted archive or another documented outcome.
7. Consent withdrawal is operationalizedStop the relevant processing and evaluate deletion.
8. Legal holds are narrowConcrete scope, reason, owner and review date.
9. Backups have a lifecycleNo permanent accumulation without reason.
10. Vendors follow the scheduleIncluding subprocessors where relevant.
11. Inactive accounts are reviewedSeparate active service from residual obligations.
12. Cookies have defined durationPurpose-based expiry, not arbitrary persistence.
13. Rights requests can override ordinary workflowsDeletion/blocking processes must reach the right systems.
14. Security incident records meet the specific regulatory minimumAt least five years under Resolution 15/2024.
15. Rules are reviewed when the business changesNew laws, vendors, products, AI and data categories can change the lifecycle.

Turn Retention Into a System Rule, Not a Policy Sentence

The Brazil LGPD Compliance Playbook — 2026 Edition includes a dedicated Retention Schedule, plus the Data Mapping Worksheet, Processing Inventory / ROPA, Legal-Basis Decision Record, Vendor Privacy and Security Review, Data-Subject Request tools, International Transfer Review, Security Incident Assessment, 100-point compliance audit and 30-day implementation roadmap.

Retention Schedule Data Mapping Worksheet Processing Inventory / ROPA Data-Subject Request Tools
Get the Brazil LGPD Compliance Playbook · $47

Frequently Asked Questions

How long can a company keep personal data under the LGPD?

The LGPD does not set one universal retention period. Retention depends on the purpose, necessity, applicable legal obligations and the end-of-processing rules in Articles 15 and 16.

Does the LGPD have a general five-year retention rule?

No. There is no general five-year period for all personal data. Specific laws and regulations can impose record-specific periods. One concrete example is ANPD Resolution 15/2024, which requires controllers to keep security-incident records for at least five years.

What are the Article 16 retention exceptions?

Article 16 permits conservation after processing ends for legal/regulatory obligations; research-body studies with anonymization whenever possible; lawful transfer to a third party; or exclusive controller use where third-party access is prohibited and the data is anonymized.

Does consent withdrawal require immediate deletion of everything?

No. Consent-based processing must be addressed, and Article 18 gives a deletion right for consent-based data subject to Article 16. But information about the same person may remain under another valid purpose and legal basis.

Can a company retain data to defend a legal claim?

The regular exercise of rights is a legal basis in Article 7(VI), and Article 11 contains an equivalent sensitive-data basis. A concrete dispute or claim can support targeted preservation, but this should be documented and proportionate rather than used as a blanket indefinite-retention justification.

Do backups have to be deleted immediately?

The LGPD does not provide a universal backup-specific deletion deadline or blanket backup exemption. A practical program defines backup rotation, restricts ordinary access, prevents deleted data from being reactivated after restoration, and removes expired copies through the normal lifecycle where technically appropriate.

Can we keep anonymized data indefinitely?

Article 16 allows exclusive controller use after termination where third-party access is prohibited and the data is anonymized. Whether data is truly anonymized depends on the LGPD standard and the reasonable means available to reverse the process. “Pseudonymized” should not automatically be treated as “anonymous.”

Should vendors follow our retention schedule?

Yes for processing they perform on your instructions. Contracts and operational controls should address retention, deletion, subprocessors, backups and end-of-service handling.

Should retention periods be disclosed in a privacy notice?

Article 9 gives data subjects the right to information about the form and duration of processing. Public notices should therefore accurately explain retention duration or the criteria used to determine it at an appropriate level of detail.

How often should a retention schedule be reviewed?

The LGPD does not set one universal review interval. Review when laws, products, purposes, vendors, systems or risks materially change, and periodically validate the schedule as part of privacy governance.

Official Sources Used for This Guide

Editorial note: This article is an independent educational resource, not legal advice. It was reviewed against the current compiled LGPD and official ANPD materials available on August 20, 2026. The LGPD does not create one universal retention period for all personal data. The example schedules and lifecycle controls in this article are operational frameworks, not statutory retention periods. Organizations must identify the specific Brazilian or foreign laws, regulations, contractual obligations and litigation requirements that apply to each record category before setting final retention periods.