What a data retention policy is and why it is needed
A data retention policy is an internal document that defines, for each category of data, for how long the data are stored, by which criterion the period is determined and what happens after its expiry. This is not an administrative formality: the Georgian Law on Personal Data Protection establishes storage limitation among the principles of processing, and the policy is precisely the instrument through which the organisation demonstrates compliance with that principle.
Unlike other pages, here we deal precisely with the policy document — and not with statutorily mandated retention cases, physical destruction or consultation on storage. The policy unites all of these elements in a single governance framework.
The legal foundation: the storage limitation principle
The relevant subparagraph of the first paragraph of Article 4 of the law establishes: data may be stored only for the period necessary to achieve the corresponding legitimate purpose. Once the purpose has been achieved, they must be deleted, destroyed or stored in depersonalised form. There is only one exception: where the processing is determined by a law or a subordinate normative act issued in accordance with the law and storage is a necessary and proportionate measure for the protection of superior interests in a democratic society.
This principle determines every subsequent element of the policy: the period is derived from the purpose, not from habit, opinion or technical comfort. The phrase "perhaps we should not delete yet" must not exist in a policy unless it has a lawful ground.
Periods comprehensible to the subject: the information requirement
The policy must also be visible from outside. Under the relevant subparagraph of the first paragraph of Article 13 of the law, the data subject has the right to demand from the controller, free of charge, information on the storage period of the data, and where determining a specific period is impossible — on the criteria for determining the period. This means that "indefinite storage" is not lawful in a policy: either a specific period must be indicated or a clear criterion by which it is calculated.
The second paragraph of Article 13 also sets the deadline for providing this information: the subject receives an answer no later than 10 working days from the request, and in special cases, with proper substantiation, this period may be extended by no more than a further 10 working days, of which the subject is notified immediately. The policy must provide for the procedure for these two deadlines in advance.
Deletion requests and the policy's connection to them
Under the first and second paragraphs of Article 16, upon a subject's request the processing must cease or the data be deleted or destroyed no later than 10 working days, or the subject must be notified of a substantiated ground for refusal. The policy plays a decisive role here: if the period is correctly defined in the policy, the organisation knows whether at the moment of the request the purpose has not yet expired — and accordingly the refusal rests on a lawful ground — or, conversely, the period has expired and deletion is prescribed.
In the event of a refusal, the entry in the policy becomes the document that confirms the ground. The policy must therefore not be a collection of general formulations: for each category the purpose, the period or criterion, and the action after the period must be indicated.
Records: reflecting the policy in documentation
Under the first paragraph of Article 28, the controller must ensure the recording of information related to processing, which includes, by the relevant subparagraph of the law, information on the storage periods of the data, and where determining a specific period is impossible — on the criteria for determining it. In other words, the policy and the records must mirror each other: the period indicated in the records derives from the policy.
In addition, the recorded information must be provided to the State Audit Office immediately upon the corresponding request, but no later than 3 working days — and the existence of the policy is precisely what makes a fast and complete answer to that request possible.
The sequence is as follows. First: describing the processing operations — which categories of data exist in the organisation. Second: formulating the purpose of each category. Third: studying and separating the storage periods established by legislation — this part is the mandatory retention block. Fourth: setting the period or criterion for the remaining categories in the frame of proportionality to the purpose. Fifth: defining the action after expiry — deletion, destruction or depersonalisation. Sixth: reflecting all of this in the records and in a form comprehensible to the user.
Frequently Asked Questions
What is a data retention policy?
An internal document defining, for each category of data, the storage period or the criterion for determining it, and the action after expiry. It rests on the storage limitation principle.
Must the subject be informed of the storage period?
Yes. Upon a subject's request this information is provided no later than 10 working days; in special cases the period may, with substantiation, be extended by a further 10 working days at most.
How is the policy connected to deletion requests?
An answer to a subject's request must be given within 10 working days. If the period is correctly defined in the policy, the organisation knows exactly whether the purpose has expired — and accordingly whether to delete or to refuse with substantiation.
How We Help on Legal.ge
A data-retention policy is part of the foundation on which responsibility for every request stands. The Legal.ge team helps compile the policy, define categories and deadlines, and harmonize it with the records of processing. Contact us — a correctly written policy shapes the answer to each request in advance.
