Data deletion concept
A data deletion concept is a documented, binding set of rules governing which personal data is deleted, when, and how. It systematically implements the GDPR principles of storage limitation and the right to erasure.
A data deletion concept is a written, binding set of rules that defines which personal data in a company is deleted, when, and in what manner. It translates the abstract requirements of the General Data Protection Regulation (GDPR) – above all the principle of storage limitation (Art. 5(1)(e)) and the right to erasure (Art. 17) – into concrete, traceable deletion rules and retention periods. The goal is that data is not stored for longer than is necessary for the respective processing purpose.
The data deletion concept is one of the central evidentiary documents of operational data protection and is closely linked to the record of processing activities. It names the data types, assigns deletion periods to them, defines the triggering start date, and governs responsibilities as well as the technical implementation. Because personal data in companies arises predominantly in operational systems such as the ERP, the CRM, or the online shop, a deletion concept is barely feasible without a link to these systems.
At a glance
- Documented rules on when and how personal data is deleted – based on GDPR Art. 5 and Art. 17
- The core building blocks are deletion rules (deletion classes) made up of a start date and a deletion period
- DIN 66398 provides the recognized methodology for creating one
- Must be reconciled with statutory retention obligations (HGB, AO)
- Part of the accountability principle – without evidence, there is a risk of fines
What belongs in a data deletion concept?
A data deletion concept is more than a list of retention periods. It links the data types processed in the company with clear rules on when their storage ends, and describes how deletion is carried out in a practical, documented, and repeatable way. This turns the statutory principle of "as short as possible, as long as necessary" into a controllable process.
Deletion rules and deletion classes
The core of a deletion concept is the deletion rules, which group similar data into so-called deletion classes. A deletion rule bundles data that shares the same deletion period and the same triggering start date – for example, "application documents of rejected candidates: deletion six months after the process is concluded". Instead of considering each data field individually, a good deletion concept works with a manageable number of such classes that cover the entire data inventory.
Start date and deletion period
Every deletion rule consists of two components. The start date is the event that triggers the period – for example, the end of the contract, the last order, or the expiry of a consent. The deletion period is the time span that may elapse from this event until deletion occurs. Only the combination of both values produces a concrete deletion date. This separation stems from DIN 66398 and makes deletion rules unambiguous and automatable.
DIN 66398 as a methodological basis
DIN 66398 ("Guideline for the development of a deletion concept with derivation of deletion periods for personal data") is the standard that is authoritative in practice. It was formally withdrawn in 2025 and replaced by DIN EN ISO/IEC 27555; however, its methodology continues to be regarded as a recognized reference in terms of content. The standard does not prescribe specific periods but provides a systematic approach with which companies can derive and justify their own deletion rules. The approach is deliberately designed so that it can be embedded into existing data protection and IT processes.
Methodologically, the data types are first recorded and grouped into deletion classes. For each class, a start date and a deletion period are defined, with statutory retention obligations, limitation periods, and the processing purpose serving as grounds for the derivation. Responsibilities are then assigned: who initiates the deletion, who implements it technically, who monitors it? The standard emphasizes regular review, because purposes, systems, and the legal situation change.
Why a data deletion concept matters
The practical benefit lies first in legal certainty. In Art. 5(2), the GDPR requires accountability: companies must not only ensure compliance with the data protection principles but also be able to demonstrate it. A deletion concept is this evidence for the area of storage limitation. If it is missing, a data protection violation is considerably harder to refute during an audit by the supervisory authority, and there is an increased risk of fines.
In addition, a well-maintained deletion concept reduces operational risks: less unnecessarily stored data means a smaller attack surface in the event of data breaches, lower storage costs, and higher data quality. Data subject rights too – such as an erasure request under Art. 17 – can be processed faster and more completely if it is clearly governed in advance where which data is held and which deletion rule applies. Data protection thus moves from a reactive individual case to a controllable, rule-based process.
The data deletion concept in the ERP system
Because customer, supplier, employee, and order data converge in the ERP system, it is the central place where a deletion concept must take effect. Technical implementation is achieved through automated deletion runs that identify due records based on the stored periods, as well as through functions for blocking, anonymizing, or pseudonymizing data that may not yet be permanently deleted.
Blocking, anonymizing, logging
In practice, immediate deletion is rarely possible because a record often serves several purposes. A customer address belongs to the invoice (subject to retention) and to marketing (subject to deletion once consent ends). The ERP solves this by blocking data for the purpose that no longer applies and only removing it permanently once the last relevant period has expired. Every deletion operation should be logged via an audit trail so that the deletion remains verifiable in an audit-proof manner. Roles and permissions ensure that only authorized persons can initiate or change deletion rules.
Distinction: deletion concept, retention obligation, and GDPR
Deletion concept, retention obligation, and the GDPR interlock but address different questions. With storage limitation and the right to erasure, the GDPR sets the fundamental obligation not to keep data for longer than necessary. The deletion concept is the organizational tool that concretizes and documents this obligation. The retention obligation under commercial and tax law works in the opposite direction: it requires certain documents to be kept for six, eight, or ten years.
A robust deletion concept resolves this tension by adopting the statutory retention periods as the deletion periods of the affected data classes. During the ongoing retention obligation, the data is not deleted but blocked for all other purposes and only removed after the period expires. In this way, the company fulfills both obligations at the same time. The deletion concept differs from the data protection concept or the procedural documentation in that it governs solely the end-of-life point of the data.
DACH specifics
In Germany and Austria, the GDPR applies directly, supplemented by the BDSG and the Austrian DSG respectively. DIN 66398 has established itself as the reference for creating deletion concepts throughout the German-speaking region and is accepted by supervisory authorities as guidance. In Switzerland, the revised Data Protection Act (revDSG) has applied since 1 September 2023; it is largely aligned with the GDPR level and likewise requires a purpose-bound storage duration.
For companies with activities in several DACH countries, a uniform deletion concept is advisable that takes the strictest requirement in each case as the common denominator. Because the specific retention periods can differ from country to country, the derived deletion periods should be coordinated with the tax advisor and the data protection officer, and the derivation should be documented.
Example
Example: online retailer deletes customer data on a rule basis
A mid-sized e-commerce retailer processes customer accounts, orders, newsletter consents, and job applications in the ERP. For each of these data types, the deletion concept defines its own deletion rule. Newsletter data is deleted as soon as the consent is withdrawn; inactive customer accounts three years after the last order; application documents six months after the end of the process.
Order data with an invoice reference, by contrast, falls under the eight-year retention obligation. The ERP blocks these records for marketing and analytics as soon as the customer account is deemed inactive, but keeps them available for accounting and only deletes them after the period expires. An automated deletion run removes the due records monthly and logs every operation. This allows the retailer to demonstrate seamlessly during an audit that no personal data is stored for longer than necessary.
Frequently asked questions
Matching ERP systems
Related services
Sources
Questions about Data deletion concept in your ERP project?
We advise vendor-neutrally – and implement it ourselves on request.