How Long Should You Keep DPIA Records?
DPIAs must be documented — but for how long? Here’s what the UK GDPR says about retention.
There’s no legal time limit for DPIA retention, but regulators expect documentation to be available for:
- The life of the system or project
- Three years after decommissioning (best practice)
- Longer in case of incidents or legal claims
Don’t forget: DPIAs should be reviewed if the risk landscape changes. Privacy IQ helps clients set smart DPIA retention and review policies.
