Contact Deutsch

ISiCO GmbH
Skip navigation
  • Privacy

    Get a head start with our optimal data protection consultancy

    Secure your competitive advantage with our business-focused data protection expertise.

    • Data Protection Consulting
      • Data Protection Impact Assessment (DPIA)
      • Threat Modelling
      • Data Breaches
      • Records of Processing Activities (ROPA)
      • Communication & Procedures with Authorities
      • Employee Data Protection
      • Data Protection Management System
      • Erasure and Archiving Policies
    • External Data Protection Officer
    • Data Protection Audits
    • EU Representative
    • Whistleblower Protection Act
  • IT Security

    Reliable protection for your company

    Make use of our expertise and customised IT security solutions to protect your digital assets.

    • External Information Security Officer (ISO)
    • ISMS
      • ISMS Service Package
      • ISMS Service Package NIS2
      • ISMS Service Package ISO 27001
      • ISMS Service Package TISAX
    • ISO 27001 Certification
    • Ransomware Protection
    • Risk Management
    • IT Compliance
    • NIS2
    • DORA
    • TISAX Certification
    • IT Forensics
    • Cyber Resilience Act
  • AI Consulting

    Gain a competitive edge with the best AI advice

    Secure your competitive advantage with our business-focused AI expertise.

    • ISO 42001 Certification
    • External AI Officer
  • Data Strategy

    Make the most of your data

    We will show you how to unlock the full potential of your company's data.

    • Develop Data Strategy
    • Maturity Assessment
    • Data Governance
    • Data Product
  • Solutions

    We create solutions for all challenges

    Whether you need advice on data protection management, its implementation, or employee training, we can provide the solution you need as part of a corporate network.

    • Workshops
    • DPO Coaching
    • Privacy Solution Software caralegal
    • E-Learning from lawpilots
  • Company

    Customised, efficient and business-oriented

    ISiCO is one of the top addresses in Germany for management consultancy in data protection, information security, AI and data strategies.

    • About ISiCO
    • Team
    • Offices
    • News
    • Contact
  • Make an appointment

27.08.2026

How to create a GDPR erasure concept: templates, deadlines and practical erasure rules

The GDPR clearly stipulates that personal data may not be stored indefinitely. A structured erasure concept helps implement legal requirements, minimise risks and maintain an overview. Find out how an effective concept is structured, which deadlines apply and what matters in practice.

Arrange a no-obligation initial consultation now
Your ISiCO-Expert:
Jacqueline Neiazy
Partner Data Protection, Managing Director

What is an erasure concept under the GDPR?

An erasure concept under the GDPR is an internal company framework that systematically defines how personal data are erased once their processing is no longer necessary or permissible. It serves to implement the data protection erasure obligations under Article 17 GDPR and the principle of storage limitation under Article 5(1)(e) GDPR in practice.

Purpose and legal basis

Article 17 GDPR requires the erasure of personal data where the purpose of processing no longer applies or other grounds for erasure exist, such as withdrawal of consent.

Article 5(1)(e) GDPR, storage limitation, requires that personal data be stored only for as long as is necessary for the purposes for which they are processed.

Article 5(2) GDPR, accountability, requires controllers to be able to demonstrate compliance with the GDPR. A documented erasure concept contributes to this.

How do you create an erasure concept?

A practical erasure concept under the GDPR consists of several structured components that build systematically on one another. DIN 66398 is, among other things, an established guideline for developing such concepts.

1. Data inventory and categorisation

First, all personal data within the company are fully recorded. They are divided into data types, such as customer data or employee data, and grouped into erasure classes that share common erasure rules and deadlines.

2. Defining erasure periods and start dates

Specific erasure periods are defined for each erasure class, based on statutory retention obligations, such as those under the German Commercial Code, HGB, or Fiscal Code, AO, or on internal policies. The start date of the period, such as the end of a contract or last contact, is clearly determined.

3. Defining erasure rules and implementation measures

Specific erasure rules are defined for each erasure class, including methods for secure data erasure, such as overwriting, shredding or anonymisation, and taking into account different types of data carriers, both digital and physical. Responsibilities for implementing and monitoring the erasure concept are clearly assigned.

4. Integration into data protection management

The erasure concept is integrated into the existing data protection management system, in particular into the record of processing activities under Article 30 GDPR. This ensures consistent application and facilitates proof of compliance vis-à-vis supervisory authorities.

5. Documentation and evidence

All erasure processes are documented, including the time, type of erasure and responsible person. These logs serve accountability purposes under Article 5(2) GDPR and enable transparent traceability.

6. Regular review and updating

The erasure concept is reviewed regularly and updated where necessary to reflect changes in legal requirements or internal processes. This ensures that the concept remains current and effective.

Free expertise in your e-mail inbox

All the important news on data protection, information security, AI and data strategy conveniently delivered to your e-mail inbox once a month - free of charge, of course. (Currently only available in German)

Please calculate 5 plus 5.

By clicking on the button, you consent to receiving our newsletter and to the aggregated usage analysis (opening rate and link clicks). You can revoke your consent at any time, e.g. via the unsubscribe link in the newsletter. More information: Privacy policy.

What is DIN 66398?

DIN 66398 is a German standard entitled “Guideline for the development of an erasure concept with derivation of erasure periods for personal data”. Published in 2016, it provides organisations with a structured approach to creating an erasure concept that meets the requirements of the General Data Protection Regulation, GDPR.

The core components of DIN 66398 are:

  1. Data types: definition of groups of data objects processed for a uniform purpose.
  2. Erasure classes: grouping of data types with identical erasure periods and start dates.
  3. Erasure rules: definition of the erasure period and start date for each erasure class.
  4. Implementation specifications: specific instructions for the technical and organisational implementation of the erasure rules.
  5. Responsibilities: allocation of responsibilities for creating, maintaining and implementing the erasure concept.
  6. Documentation: recommendation for structuring documentation of the erasure concept and erasure processes.

Example of an entry according to DIN 66398

Data type: application documents of rejected candidates, where there is no documented consent for inclusion in the applicant pool.

Erasure class: LK-06M-EV, maximum erasure period: six months from rejection of the applicant or the end of the selection process.

Erasure rule: erasure takes place no later than six months after rejection of the applicant.

Implementation specification: automated erasure of digital application documents in the HR system. Physical documents are destroyed by the HR department.

Responsibility: Human Resources department, HR.

Documentation: erasure processes are recorded in the HR system’s erasure log and reviewed annually.

When must personal data be erased?

The personal data of data subjects must be erased if:

  • the personal data are no longer necessary for the purposes for which they were collected or otherwise processed, Article 17(1)(a) GDPR;
  • consent to data processing has been withdrawn and there is no other legal basis for processing, Article 17(1)(b) GDPR;
  • the data subject has objected to processing, Article 17(1)(c) GDPR;
  • the processing was unlawful, Article 17(1)(d) GDPR;
  • erasure of the personal data is required to comply with a legal obligation under Union or Member State law, Article 17(1)(e) GDPR; or
  • the personal data were collected in relation to the offer of information society services referred to in Article 8(1) GDPR, Article 17(1)(f) GDPR.

Example

A customer gives a company permission to use their email address to send newsletters. However, they have the right to withdraw this consent at any time with effect for the future.

If they do so, the legal basis for processing and storing their personal data no longer applies, Article 17(1)(b) GDPR. The company is then obliged to erase the email address. The same applies if no consent to receive newsletters was given in the first place, Article 17(1)(d) GDPR.

Exceptions under Article 17(3) GDPR

Article 17(3) GDPR provides for exceptions to the right to erasure of personal data. These exceptions apply where processing remains necessary for specific reasons. The GDPR lists the following exceptions:

  • exercising the right of freedom of expression and information;
  • compliance with a legal obligation or performance of a task carried out in the public interest;
  • reasons of public interest in the area of public health;
  • archiving purposes, scientific or historical research purposes or statistical purposes;
  • establishment, exercise or defence of legal claims.

Retention obligations

Statutory retention periods outside the GDPR may also prevent erasure. The following is a brief overview of selected retention periods:

Document type / data type Retention period Legal basis
Commercial and business letters 6 years Section 147(3) AO, Section 257(4) HGB
Application documents, in case of rejection max. 6 months Section 15(4) AGG
Employment contracts, payslips 10 years Section 147(3) AO
Certificates of incapacity for work 5 years Section 6(1) AAG
Time sheets, more than 8 hours on working days 2 years Section 16(2) ArbZG
Documents relating to accidents at work 5 years Section 24(6) DGUV Regulation 1
Documents relating to liability cases, bodily injury 30 years Section 199(2) BGB
Documents relating to liability cases, property damage 10 years Section 199(1) BGB

 

What constitutes erasure?

The term “erasure” is not legally defined in the GDPR. It is only mentioned in Article 4(2) GDPR, where it is listed as a form of processing. It can be inferred that erasure means the complete and irreversible removal of personal data, making restoration impossible with reasonable effort. This includes both digital and physical data.

Technical implementation

Digital data: erasure is carried out using secure methods, such as overwriting the data with random values or physically destroying the storage media.

Physical data: paper files must be disposed of using a document shredder; the protection class and security level are based on the DIN 66399 standard for data carrier destruction.

Anonymisation as an alternative

Instead of erasure, the data may be anonymised by permanently removing any personal reference. However, this is only permissible if the anonymisation is complete and irreversible. In practice, this is often difficult to implement.

Blocking as an interim solution

In cases where immediate erasure is not possible, for example due to statutory retention obligations, the data must be blocked. This means that the data are blocked for further processing and remain accessible only for the intended purpose.

What sanctions may apply for non-compliance with the right to erasure?

The absence of an erasure concept and the resulting failure or delay in erasing personal data constitute infringements of the General Data Protection Regulation, GDPR. This can lead to significant sanctions. Article 83(5)(a) GDPR provides for fines of up to EUR 20 million or up to 4% of worldwide annual turnover, whichever is higher, for infringements of the principles relating to the processing of personal data.

Practical examples of sanctions

Hamburg, 2024: a company in receivables management stored personal data for up to five years despite expired erasure periods. The Hamburg Commissioner for Data Protection and Freedom of Information imposed a fine of EUR 900,000.

Berlin, 2019: Deutsche Wohnen SE was fined EUR 14.5 million because the archive system it used was technically unable to erase data that were no longer required. The data were stored without any review of whether storage remained permissible.

What must be considered for processing by processors in the erasure concept?

Under Article 4(7) GDPR, the controller is obliged to ensure that personal data are erased in due time. This obligation also extends to data processed by processors. This means that the controller must ensure that service providers also erase data within the applicable deadlines.

Under Article 28(3), second sentence, point (g) GDPR, the processor is obliged, after completion of the processing services, either to erase or return all personal data, unless a statutory storage obligation applies. This obligation should be clearly regulated in the data processing agreement.

If the processor breaches erasure obligations, the controller may generally be held liable under Article 82(1) GDPR. It is therefore in the controller’s interest to ensure that the processor properly fulfils the erasure obligations.

How we support you with your erasure concept

A well-designed erasure concept is essential for GDPR-compliant data processing. As specialised data protection consultants, we support you in a practical and legally secure way with the design, implementation and monitoring of your erasure concept.

Our services at a glance

  • Analysis and categorisation of all relevant personal data
  • Development of individual erasure rules in accordance with DIN 66398
  • Derivation and documentation of statutory retention and erasure periods
  • Creation of a company-specific erasure concept including erasure classes
  • Support with integration into the data protection management system, for example ROPA and TOMs
  • Review and optimisation of existing data erasure processes
  • Development of technical and organisational erasure measures
  • Advice on erasure in backup and archive systems
  • Contract review and control of processors, Article 28 GDPR
  • Training and awareness-raising for employees
  • Regular reviews and updating of the erasure concept
  • Support during authority audits and requests for information

Conclusion: GDPR erasure concept – legal certainty through a systematic approach

A GDPR erasure concept is not a one-off document, but an ongoing process consisting of a data inventory, erasure classes and documented erasure rules. ISO/IEC 27555, formerly DIN 66398, provides a recognised structure for this, which can be transferred directly into a company’s own template. Companies that understand the statutory retention periods, formulate erasure rules specifically and document erasure processes in a traceable manner significantly reduce the risk of fines while maintaining an overview of their own data holdings.

Frequently asked questions (FAQ)

#1 Is a GDPR erasure concept legally required?

The GDPR does not expressly require an erasure concept as a standalone document. However, Article 5(2) GDPR requires proof that personal data are not stored for longer than necessary. A documented erasure concept is the most practical way to meet this accountability obligation and implement erasure periods consistently across the company.

#2 What is the difference between erasure and anonymisation?

Erasure removes personal data completely and irreversibly, so that restoration is no longer possible. Anonymisation, by contrast, permanently removes the personal reference from the data while the data themselves remain. Anonymisation is only a permissible alternative to erasure if it is complete and irreversible.

#3 What exactly does ISO/IEC 27555 regulate?

DIN EN ISO/IEC 27555 defines a methodology that enables companies to group data types into erasure classes with a uniform erasure period and a uniform start date. This classification is used to derive specific erasure rules, technical implementation requirements and responsibilities, which together form the erasure concept. In September 2025, the standard replaced the previous DIN 66398, while continuing to follow its methodology.

#4 How long may personal data be stored?

According to Article 5(1)(e) GDPR, personal data may only be stored for as long as required by the respective processing purpose. Additional statutory retention obligations, for example under commercial or tax law, may extend this period and prevent immediate erasure.

#5 What happens if a company does not have an erasure concept?

Without an erasure concept, there is usually no evidence that personal data are erased within the applicable deadlines, which supervisory authorities may consider an infringement of the principles relating to the processing of personal data. Under Article 83(5)(a) GDPR, this may result in fines of up to EUR 20 million or up to 4% of the worldwide annual turnover.

Your solution for the best data protection

Trust is the foundation of every good business relationship. Strengthen your relationships with customers by leveraging our expertise in data protection. This will give your company a strong competitive advantage, allowing you to focus fully on your business.

Book your appointment now

Back to the news overview

Berlin
Köln
München

Ready for the next step?

+49 30 21300285-0
info@isico.de

Directly to get to know us

 

Outstanding work

ISiCO is also an active member of the German Association for Data Protection and Data Security (GDD) and the German Association for Information Technology, Telecommunications and New Media (Bitkom).

Top-Links
Skip navigation
  • External Data Protection Officer
  • Data Protection Management System
  • Data Strategy
  • Data Breaches
  • ISMS
Find out more
Skip navigation
  • About ISiCO
  • Contact

Language

DE EN

© ISiCO GmbH | Contact | Imprint | Privacy | Privacy Settings