Storage Limitation
Storage limitation is a data protection principle that says organisations should not keep personal data for longer than they actually need it. Organisations are expected to decide on, and be able to justify, how long they retain different types of personal information, and to remove or anonymise it when it is no longer required. It concerns how long identifiable personal data is held, not the technical storage capacity of a device.
Storage limitation is one of the core data protection principles under the GDPR framework (including the UK GDPR), commonly referred to as principle (e). It generally requires that personal data be kept in a form permitting identification of data subjects for no longer than is necessary for the purposes for which it is processed. In practice this obliges controllers to define, document, and justify retention periods, and to erase or anonymise personal data once it is no longer needed. Limited exceptions may apply, for example where personal data is retained for longer periods when processed solely for archiving purposes in the public interest, subject to the applicable safeguards. This entry describes the principle qualitatively; specific retention obligations are fact-specific and depend on purpose, data category, and applicable law, and readers should verify against the current official text of the relevant regulation and competent authority guidance. Note that this is distinct from the colloquial or hardware sense of 'storage limitation' meaning the byte or bit capacity of a storage medium, which is not the data protection concept.
Why it matters
Storage limitation addresses one of the most persistent and under-managed risks in data protection: personal data that outlives its purpose. Every additional day that identifiable data is retained beyond genuine need expands an organisation's exposure — a larger volume of retained data means a larger attack surface in the event of a breach, more records subject to access or erasure requests, and greater difficulty demonstrating accountability. The principle reframes retention as a deliberate decision that must be justified, rather than a default of keeping everything indefinitely.
Under the GDPR framework, including the UK GDPR, storage limitation (principle (e)) generally requires that personal data be kept in a form permitting identification of data subjects for no longer than is necessary for the purposes of processing. This is not merely good hygiene; it is a legal obligation that competent authorities can examine. Because obligations are fact-specific and depend on purpose, data category, and applicable law, organisations are expected to set, document, and be able to justify retention periods rather than point to a single universal timeframe.
It is worth distinguishing this concept from the unrelated hardware sense of the same phrase — the byte or bit capacity of a storage medium such as an SD card or hard drive. That colloquial meaning is not the data protection principle and should not be confused with it. Application of storage limitation to any specific dataset requires professional judgment, and readers should verify requirements against the current official text of the relevant regulation and competent authority guidance.
Who it's relevant to
Inside Storage Limitation
Common questions
Answers to the questions practitioners most commonly ask about Storage Limitation.

