← Back to news 15.07.2026

Deletion is a process, not a button

The GDPR demands deletion, commercial and tax law demand retention, and both apply at the same time. Whoever deletes by gut feeling is guaranteed to violate one of the two duties. Why a deletion concept needs periods per data type, when a period even starts running, and why proving deletion is half the duty.

"We delete what we no longer need." The sentence sounds reasonable and still is not a deletion concept. Two duties apply at the same time: the GDPR demands that personal data be deleted as soon as the purpose lapses. Commercial and tax law demand that the same records be retained for six, eight or ten years, depending on the document type. Whoever deletes by gut feeling reliably violates one of the two sides: deleted too early, the retention duty; deleted too late, storage limitation.

The tension only resolves per data type

Blanket answers fail here because the right period depends on the data type: application documents have a different one than accounting records, server logs a different one than contracts. This is exactly what the system of deletion classes is for, as established as a guideline with DIN 66398: similar data gets a shared rule made of a period and a starting point. And the starting point is the underestimated half: does the period run from the end of the contract, from last use, or from the annual financial statement? Without a defined start, you do not have a period, you have an assumption.

Proof is half the duty

Alongside the duty to delete, the GDPR has accountability: you must be able to show that deletion happened. The proof itself has to be data-minimal, a log about the deletion process that does not in turn keep copies or details of what was deleted, which would undermine the deletion. An auditor does not only ask whether a concept exists. They ask which rule was applied when to which data set, and how exceptions are handled, for instance when ongoing proceedings suspend a deletion. Without a log, the answer at this point is a shrug.

How isidaten runs the deletion concept

The deletion concept module maps exactly this mechanism: deletion rules per data type with retention periods and a defined starting point, plus the storage locations a rule refers to. Automated deletion runs execute the rules; manual deletion requests, for instance from data subject rights, take the same path. Every deletion is logged in an audit-proof way, and the deletion evidence for the audit shows that the concept does not just exist on paper.

More is shown on the deletion concept module page. How isidaten supports GDPR overall is covered by the GDPR solution page.

Matching solution isidaten for DSGVO

Questions about this update?

Talk to us – we are happy to show you this feature in a demo.