CRM Data Retention Policy: How Long to Keep Customer Records
A CRM data retention policy gives every type of record a retention period, and that period depends on why you hold the record in the first place. GDPR doesn’t hand you a fixed number of years. You pick the periods yourself and write down why. Is your CRM full of old leads and former customers, with nobody quite sure what can stay? This guide shows you how to set those periods and turn them into a deletion schedule. For the wider rules on security, access and lawful basis, see our guide on storing customer data under GDPR.
Table of Contents
How long can you keep customer data in a CRM?
You can keep customer data as long as one of your stated purposes still applies. Not a day longer. That’s the GDPR storage limitation principle: if you hold personal data longer than your purpose needs, it’s unnecessary by definition, and you probably have no lawful basis to keep it. The law doesn’t set the periods. You do, and you have to be able to defend each one.
And no, “keep it just in case” isn’t a rule. The small chance that an old contact might come in handy someday is not a reason to hold on to it. The ICO guidance on storage limitation says this plainly. (The ICO is the UK regulator and writes about UK GDPR, but the principle reads the same in the EU text.)
What reasons justify keeping a record longer?
Three things usually justify longer retention: a live relationship, a legal or tax obligation, or a real chance of complaints or claims. While a contract or account is open, you obviously need the customer’s data. Once the relationship ends, you can still keep part of it so you can deal with complaints about the work you delivered.
Tax, accounting and audit rules often make you keep invoices and related records, and data kept for that reason doesn’t count as kept too long. The periods vary from country to country, so check your national rules or ask your accountant. Whatever the period, keep only the fields the purpose actually needs. An invoice archive needs the billing name and address. It doesn’t need the full contact card with notes and phone numbers.
Building a simple data retention schedule for your CRM
A data retention schedule is a table: each record type, why you hold it, and how long it stays. I’d build it with these columns:
- Record category: lead, active customer, former customer, invoice data, support tickets, email history.
- Purpose: what you actually use the data for.
- Lawful basis: contract, legal obligation, legitimate interest or consent.
- Trigger: the event that starts the clock, like last contact, contract end or invoice date.
- Retention period: the length you picked and the reason behind it.
- End action: delete, anonymise or review.
The trigger matters more than the number. Honestly. “X months after last contact” is something you can filter and automate. “X years” with no starting point? You can’t. That’s why you need contact history in one place, where the last activity date on every record is easy to find. Very small firms with occasional, low-risk processing may get away without a written policy, but they still have to review their data regularly and delete what they no longer need.
Deleting old leads and former customers without losing what you need
When a period runs out, review the record, then erase or anonymise it unless you have a clear reason to keep it. Leads that never converted are usually the weakest case for long retention. So set a cut-off after the last interaction and stick to it every time.
Want to keep your sales stats? Anonymise instead of deleting. Strip names, emails and phone numbers, and keep just the deal value, stage and source. Aha, and don’t forget the copies. Exports, spreadsheets, mailbox attachments, backups - they all count, so map where customer data is stored before every clean-up. One person’s request is a separate process from scheduled deletion, and our guide to handling a data erasure request walks through it step by step.
Making the schedule run in practice
A schedule only works once it’s a routine with an owner, a date and a filter. Otherwise it just sits in a folder. The ICO points out that automated systems can flag records for review or delete them after a set period, which pays off most when you hold lots of records of the same type. A routine that actually holds up looks something like this:
- make one person responsible for retention;
- run a review every quarter;
- tag each record with its retention category;
- filter by last activity date to see what’s due;
- log each clean-up: date, what went, how many records.
In EpicCRM you can mark retention categories with tags and set a recurring task with email, in-app or Slack reminders, so the review doesn’t depend on someone remembering. The deletion itself stays manual, and someone has to confirm it.
For former customers, EpicCRM’s contract expiry reminders give you the trigger that starts the clock. Before a clean-up, use data export to build the archive the law requires (invoice records, for example) and keep it separate from the live CRM.
Your CRM data retention policy in one page
A CRM data retention policy that works boils down to three moves: list what you hold and why, give each category a trigger and a period, then review and delete on a fixed cycle. My advice? Start with the biggest pile, which in most CRMs is stale leads. After that the rest of the schedule gets a lot easier.
FAQ
Does GDPR say how many years I can keep customer data?
No. GDPR doesn’t set fixed periods. They come from your purposes and from other laws, such as tax and accounting rules, which you’ll need to check for your country.
Can I keep old leads in case they buy later?
Not forever, and not “just in case”. Set a cut-off after the last contact, and once it passes, delete or anonymise the lead.
Is anonymising a record the same as deleting it?
Truly anonymised data isn’t personal data anymore, so it can stay for statistics. Pseudonymised or partly masked data, where extra information could still identify the person, is still personal data and follows the same retention rules.



