Deletion concept

Data protection glossary · 1 minute read

A deletion concept sets out in a binding manner which personal data is deleted when, how and by whom.

Why a deletion concept?

The GDPR requires data to be deleted as soon as it is no longer needed, and requires this to be demonstrated. Without a systematic concept, this obligation can hardly be met in IT landscapes that have grown over time.

Components

  • overview of data types and systems
  • retention periods and when they start, derived from purposes and retention obligations
  • deletion rules and responsibilities
  • technical implementation and logging
  • handling of backups and archives

In Germany, the DIN 66398 standard is often used as guidance. The time limits for erasure also belong in the record of processing activities.

Art. 5(1)(e) GDPR
Principle of storage limitation.
Art. 17 GDPR
Right to erasure.
Art. 30(1)(f) GDPR
Time limits for erasure as mandatory content of the record of processing activities.
Art. 5(2) GDPR
Accountability.

Last updated: September 2026

Questions about this topic?

Dr. Georg Schröder, LL.M. · Managing Director, Lawyer, Data Protection Officer

Book a consultation

In 20 minutes you will know where you stand.

We clarify where action is needed on data protection, AI and information security - and what you should do next.