Quick Answer: How long should personal data be kept under the LGPD?
There is no universal LGPD retention period for all personal data. Article 15 says processing ends when the purpose has been achieved or the data is no longer necessary or relevant, when the processing period ends, when the data subject communicates termination in applicable circumstances including consent withdrawal, or when ANPD orders termination because of a violation. Article 16 says personal data should then be deleted within the scope and technical limits of the activity, but permits conservation for four purposes: legal/regulatory obligations, research-body studies, lawful transfer to a third party, or exclusive controller use when the data is anonymized and inaccessible to third parties. A defensible retention schedule therefore assigns a specific purpose, legal reason and deletion trigger to each category of data.
Key Takeaways
- The LGPD does not say “keep everything for five years.” Retention depends on purpose and applicable law.
- Purpose and necessity are the starting point. If the purpose is achieved and no further lawful reason exists, continued identifiable retention becomes difficult to justify.
- Article 15 defines when processing ends. Article 16 defines what may be conserved after that end.
- Consent withdrawal is not the same as “delete every record about this person.” Other data may have separate legal bases or retention duties.
- Legal obligations are record-specific. Tax, accounting, labor, consumer, financial, health or sector rules can impose different periods.
- Backups are part of the retention architecture. “It is in backup” should not become a permanent exemption from deletion governance.
- Vendors must follow the lifecycle too. A retention schedule that stops at your own database is incomplete.
The LGPD Does Not Create One Universal Retention Period
This is the most important concept in the entire topic. The LGPD is not a general records-management law that says every customer, employee, marketing or security record must be retained for the same number of years.
Instead, retention is connected to the principles of purpose, adequacy and necessity, and to the end-of-processing rules in Articles 15 and 16.
A useful question is not: “How many years does the LGPD require?”
The useful question is: “For this specific processing purpose, when does the need to keep identifiable data end, and does another lawful reason require or permit continued conservation?”
Article 15: When Does Processing End?
Personal-data processing ends when: (1) the purpose has been achieved or the data is no longer necessary or relevant to that purpose; (2) the processing period ends; (3) the data subject communicates termination, including through consent withdrawal as provided by the LGPD, while public interest is safeguarded; or (4) ANPD determines termination because the LGPD has been violated.
1. The purpose was achieved
Suppose a company collects an identification document solely to verify a one-time eligibility requirement. Once verification is completed, keeping a full copy indefinitely may not be necessary for that original purpose.
The company should ask whether a separate legal or compliance reason justifies continued retention. If not, deletion, anonymization or a narrower retained record may be more appropriate.
2. The defined processing period ended
Some activities are designed with a defined lifecycle: a promotional campaign, temporary event registration, short-term fraud investigation, recruitment cycle or trial account.
The end date should not be merely decorative. When the processing period expires, the organization should execute the documented disposition rule.
3. The data subject communicates termination or withdraws consent
Consent can be withdrawn at any time through a free and facilitated procedure. The withdrawal affects processing that depends on that consent.
It does not automatically mean every system containing any information about the same person must be erased regardless of other purposes. Order records, tax records, fraud records or legal-claim evidence may be governed by different legal bases and retention logic.
4. ANPD orders termination
If processing violates the LGPD, the Agency can determine termination. A retention schedule therefore cannot override a regulatory order or make unlawful processing lawful simply because an internal policy says “keep for seven years.”
Article 16: What Can Be Conserved After Processing Ends?
Article 16 says personal data should be deleted after the end of processing, within the scope and technical limits of the activities, while permitting conservation for four specific purposes.
The controller may conserve data when another binding rule requires the record to be kept.
Conservation is allowed for study by a research body, with anonymization whenever possible.
Conservation/transfer is permitted where the LGPD's processing requirements are respected.
Legal or regulatory obligation
This is one of the most common reasons for retaining records after an operational relationship ends. But the company should identify the actual rule and the actual record.
Different legal regimes can impose different retention requirements for invoices, tax documents, employment records, regulated financial records, health documentation or sector-specific evidence. The LGPD does not replace those rules with one universal period.
Research-body study
Article 16 expressly allows conservation for studies by a research body and instructs that anonymization be guaranteed whenever possible. This is not a general “analytics forever” exception for any commercial organization.
Transfer to a third party
Article 16 includes lawful transfer to a third party as an allowed conservation purpose, but the transfer must respect the LGPD's processing requirements. This should not be read as permission to sell expired databases after the original purpose has ended.
Exclusive controller use with anonymization
The fourth exception can support keeping anonymized information exclusively for the controller, provided third-party access is barred. Whether data is actually anonymized should be analyzed using the LGPD's anonymization standard rather than simply replacing names with IDs.
How to Build an LGPD Retention Schedule
A retention schedule converts Articles 15–16 into system behavior. The schedule should be built from the Data Map and ROPA rather than from generic legal templates.
Identify the Processing Activity
Start with one coherent activity: customer support, order fulfillment, recruitment, security monitoring, newsletter delivery, employee administration or another defined purpose.
Identify the Data and Systems
List the relevant data categories and every system that holds them: production database, CRM, email platform, SaaS vendor, data warehouse, logs, backups, spreadsheets and archives.
Write the Specific Purpose
“Business use” is not a retention purpose. State why the information is still needed: fulfill an order, resolve support history, comply with a tax duty, maintain fraud evidence, administer employment or preserve a lawful legal claim.
Identify the Legal Basis and Any External Retention Rule
Record the applicable Article 7 or Article 11 basis for ongoing processing and identify any law or regulation that independently requires the record to be preserved.
Choose the Retention Trigger
A schedule needs a clock. Use a measurable event: contract end, account closure, invoice date, employee termination, support-ticket closure, consent withdrawal, last account activity, incident-record date or another defensible trigger.
Define the Final Disposition
At the end of the period, specify what happens: delete, anonymize, archive under a valid retention exception, return to the controller, or another documented action.
Connect Vendors and Backups
The policy must reach cloud vendors, SaaS tools, subprocessors and backup systems. Otherwise the “deleted” record may remain operationally available elsewhere.
Assign an Owner and Review Trigger
Retention rules change when laws, products, vendors or business purposes change. Assign both business and privacy/legal ownership.
What Should a Retention Schedule Contain?
| Field | What to record | Example |
|---|---|---|
| Processing activity | Specific processing purpose. | Customer support ticket management. |
| Data categories | Relevant categories, not actual personal-data values. | Email, account ID, ticket text, attachments. |
| Systems / vendors | Every location where the rule must execute. | Helpdesk SaaS, CRM, export archive, backup. |
| Purpose | Why identifiable data is still needed. | Resolve customer issues and maintain service history. |
| Legal basis | Article 7/11 basis for continuing processing. | Contract/service analysis. |
| Retention authority | Law, regulation, contract purpose or internal necessity rationale. | Documented service need; separate legal duty if applicable. |
| Trigger | Event that starts the retention clock. | Ticket closure or account termination. |
| Period | Defined period or rule. | Risk/business-defined period validated by owner. |
| Disposition | Delete, anonymize, archive under lawful rule, etc. | Delete active record; backup expires on rotation. |
| Exception | Legal hold, investigation or other approved reason. | Restricted preservation for active dispute. |
| Owner | Business + privacy/legal owner. | Support Operations / Privacy. |
| Evidence | Deletion logs, vendor confirmation, configuration or workflow. | Monthly purge report. |
Consent Withdrawal, Unsubscribe and Deletion
Article 8 allows the data subject to revoke consent at any time through a free and facilitated procedure. Article 18 also gives the data subject the right to request deletion of personal data processed with consent, subject to Article 16.
This creates three separate questions:
- Does the organization stop the future processing that depended on consent?
- Does the individual request deletion of the consent-based data?
- Is some information about the same person still lawfully needed for another purpose or basis?
Newsletter example
A person withdraws newsletter consent. The email platform should stop promotional sending for that consent-based purpose. A minimal suppression record may still be appropriate to prevent accidental re-enrollment, but that record needs its own documented purpose, basis, minimization and retention logic.
If the same person is also a customer, the company may still need order or invoice data under separate purposes. The withdrawal does not retroactively erase the transaction itself.
Legal Claims, Investigations and “Legal Holds”
Businesses often say they need to retain everything “in case we get sued.” That is too broad.
The LGPD separately recognizes the regular exercise of rights as a legal basis under Article 7(VI) and, for sensitive data, Article 11(II)(d). Where a concrete dispute, claim, investigation or defense need exists, that can create an ongoing processing purpose that should be documented.
This is conceptually different from saying Article 16 contains a general “litigation hold” exception. Article 16 does not list one in those words.
A defensible legal-hold process should identify:
- the concrete claim or legal risk;
- which records are actually relevant;
- who authorized the hold;
- who may access the preserved records;
- when the hold will be reviewed; and
- what happens when the dispute ends.
How Should Backups Be Handled?
Backups are one of the hardest operational parts of deletion. Article 16 refers to deletion within the scope and technical limits of the activities, but the LGPD does not create a blanket rule that “backups may always be kept forever.”
A practical backup design can distinguish between:
Delete or anonymize expired records from production systems according to the schedule.
Use controlled rotation rather than indefinite accumulation, subject to documented legal or resilience needs.
If an old backup is restored, reapply deletion/suppression states before returned data becomes ordinary operational data.
Also restrict access to backup copies and prevent them from being used for unrelated analytics, marketing or product development merely because deletion from backup is technically inconvenient.
Inactive Accounts and “We May Need It Later”
Dormant accounts often become the largest source of unnecessary personal data. A company may have millions of accounts that have not been used for years but are retained because no team owns deletion.
A better model distinguishes:
- active account;
- inactive but recoverable account;
- closed account with limited post-closure retention;
- records retained under legal/regulatory obligations;
- restricted legal-claim or fraud evidence; and
- anonymized historical analytics.
The lifecycle should be visible in the Data Map, ROPA and Retention Schedule.
See How to Build an LGPD Data Map and LGPD ROPA: How to Build a Record of Processing Activities.
Cookie Retention
ANPD's cookie guidance recommends limiting the duration of persistent cookies as much as possible, considering the purpose for which they were collected and will be processed. The Agency also treats retention period as information that can form part of a cookie policy.
That means a cookie inventory should not contain only “necessary / analytics / advertising.” It should also include the actual expiration or retention behavior.
See LGPD Cookie Consent Requirements.
Retention Must Flow Down to Vendors
ANPD's own privacy notice provides a useful governance example: when the Agency shares personal data with operators, it states that operators must store data securely, retain it only for the instructed period and not subsequently share it without prior authorization.
A private company should apply the same basic discipline to its vendor chain.
One Concrete Five-Year Rule: Security Incident Records
Although the LGPD has no universal five-year retention period, ANPD's current Security Incident Regulation creates a specific one: controllers must keep records of personal-data security incidents—including incidents not reported to ANPD or data subjects— for at least five years from the date of the record, subject to additional longer obligations where applicable.
See LGPD Data Breach Notification.
Example Retention Matrix
The durations below are intentionally expressed as decision logic rather than universal legal numbers. A company must insert the periods supported by its actual laws, contracts, risk and business model.
| Data / activity | Retention logic | Trigger | Final action |
|---|---|---|---|
| Customer account | Active service period + documented post-closure need. | Account closure. | Delete/anonymize except records with separate lawful retention. |
| Orders / invoices | Applicable legal, tax, accounting and claim-related requirements. | Transaction/document date. | Delete after all applicable obligations expire, unless another lawful basis remains. |
| Newsletter | While consent or other documented basis remains valid and purpose continues. | Withdrawal, opt-out, inactivity or purpose change. | Remove from marketing; retain only minimal suppression where justified. |
| Support tickets | Service-history and dispute needs proportionate to product/risk. | Ticket closure/account end. | Delete or minimize; preserve concrete claim evidence separately if needed. |
| Security logs | Risk-based period proportionate to security purpose. | Log event date. | Delete or aggregate/anonymize after purpose ends. |
| Security incident record | At least five years under Resolution 15/2024. | Incident record date. | Delete after applicable minimum/additional obligations expire. |
| Recruitment candidate | Recruitment purpose + any separately justified future-opportunity or claim period. | Recruitment process ends. | Delete unless another documented purpose/basis applies. |
| Cookie / identifier | Duration proportionate to specific cookie purpose. | Cookie creation / consent withdrawal / expiration. | Expire, delete or stop processing as technically applicable. |
Data Subject Requests and Retention Exceptions
ANPD's current rights guidance says people can request deletion of consent-based data subject to Article 16, and can request anonymization, blocking or deletion of data that is unnecessary, excessive or processed unlawfully.
When a deletion request arrives, do not answer with a generic: “Our policy says we keep everything for seven years.”
Instead:
- identify each processing purpose involving that person's data;
- determine which data can be deleted now;
- identify any separate legal/regulatory or ongoing lawful purpose;
- restrict retained data to that purpose;
- propagate deletion/blocking to relevant processors where required; and
- explain the factual/legal reason where immediate action cannot be taken.
Common LGPD Retention Mistakes
“LGPD says keep data for five years.”
Incorrect as a general statement. Specific rules can impose five years for particular records—ANPD incident records are one example—but there is no universal LGPD five-year period.
“We keep everything until the customer asks us to delete it.”
Too broad. Article 15 can end processing because the purpose was achieved or the data is no longer necessary even without a request.
“We delete everything immediately after consent withdrawal.”
Also too broad. Consent-based processing should stop as required, but other records may remain under different purposes, legal bases or Article 16 conservation rules.
“Backups do not count.”
Backups should be part of the lifecycle and governed by defined rotation, access and restoration controls.
“Our vendor decides retention.”
The controller should understand and govern how long operators and subprocessors retain personal data for controller-directed processing.
“Legal claims justify keeping the whole database forever.”
A concrete rights/claim purpose can justify targeted preservation, but indefinite blanket retention is difficult to reconcile with necessity and accountability.
15-Point LGPD Retention Review
Turn Retention Into a System Rule, Not a Policy Sentence
The Brazil LGPD Compliance Playbook — 2026 Edition includes a dedicated Retention Schedule, plus the Data Mapping Worksheet, Processing Inventory / ROPA, Legal-Basis Decision Record, Vendor Privacy and Security Review, Data-Subject Request tools, International Transfer Review, Security Incident Assessment, 100-point compliance audit and 30-day implementation roadmap.
Frequently Asked Questions
How long can a company keep personal data under the LGPD?
The LGPD does not set one universal retention period. Retention depends on the purpose, necessity, applicable legal obligations and the end-of-processing rules in Articles 15 and 16.
Does the LGPD have a general five-year retention rule?
No. There is no general five-year period for all personal data. Specific laws and regulations can impose record-specific periods. One concrete example is ANPD Resolution 15/2024, which requires controllers to keep security-incident records for at least five years.
What are the Article 16 retention exceptions?
Article 16 permits conservation after processing ends for legal/regulatory obligations; research-body studies with anonymization whenever possible; lawful transfer to a third party; or exclusive controller use where third-party access is prohibited and the data is anonymized.
Does consent withdrawal require immediate deletion of everything?
No. Consent-based processing must be addressed, and Article 18 gives a deletion right for consent-based data subject to Article 16. But information about the same person may remain under another valid purpose and legal basis.
Can a company retain data to defend a legal claim?
The regular exercise of rights is a legal basis in Article 7(VI), and Article 11 contains an equivalent sensitive-data basis. A concrete dispute or claim can support targeted preservation, but this should be documented and proportionate rather than used as a blanket indefinite-retention justification.
Do backups have to be deleted immediately?
The LGPD does not provide a universal backup-specific deletion deadline or blanket backup exemption. A practical program defines backup rotation, restricts ordinary access, prevents deleted data from being reactivated after restoration, and removes expired copies through the normal lifecycle where technically appropriate.
Can we keep anonymized data indefinitely?
Article 16 allows exclusive controller use after termination where third-party access is prohibited and the data is anonymized. Whether data is truly anonymized depends on the LGPD standard and the reasonable means available to reverse the process. “Pseudonymized” should not automatically be treated as “anonymous.”
Should vendors follow our retention schedule?
Yes for processing they perform on your instructions. Contracts and operational controls should address retention, deletion, subprocessors, backups and end-of-service handling.
Should retention periods be disclosed in a privacy notice?
Article 9 gives data subjects the right to information about the form and duration of processing. Public notices should therefore accurately explain retention duration or the criteria used to determine it at an appropriate level of detail.
How often should a retention schedule be reviewed?
The LGPD does not set one universal review interval. Review when laws, products, purposes, vendors, systems or risks materially change, and periodically validate the schedule as part of privacy governance.
Official Sources Used for This Guide
- Law No. 13,709/2018 — LGPD, current compiled text Primary source for Articles 6, 8–9, 15–16, 18, 37, 46 and 50.
- ANPD — Data Subject Rights Current official guidance on deletion, blocking, consent withdrawal and Article 16 conservation exceptions.
- ANPD — Frequently Asked Questions Official explanation of when deletion rights apply and the Article 16 conservation purposes.
- ANPD — Privacy Notice Current 2026 example of purpose-based elimination, applicable retention tables, and operator retention limited to the instructed period.
- ANPD — Cookies and Personal Data Protection Guidance Official guidance recommending that persistent-cookie duration be limited as much as possible according to purpose.
- ANPD — Resolution No. 15/2024 Security Incident Regulation Official source confirming the specific minimum five-year retention period for personal-data security incident records.