|

How Long Should You Keep DPIA Records?

DPIAs must be documented — but for how long? Here’s what the UK GDPR says about retention.

There’s no legal time limit for DPIA retention, but regulators expect documentation to be available for:

  • The life of the system or project
  • Three years after decommissioning (best practice)
  • Longer in case of incidents or legal claims

Don’t forget: DPIAs should be reviewed if the risk landscape changes. Privacy IQ helps clients set smart DPIA retention and review policies.

Similar Posts