Seven years of retention and minimal retention: how do they go together?
They cover different data. The seven-year term in Article 52(4) AWR applies only to your business records: invoices, orders, contracts and the correspondence that establishes rights and obligations. All other customer contact falls outside it, and there Article 5 GDPR applies: keep no more than you need, and no longer than you need it. So sort conversations into two piles with two retention periods instead of imposing one rule on everything. Where the retention duty applies, keeping the data is also allowed under the GDPR: complying with a legal obligation is a valid purpose.
Published on
Dutch tax law says: keep it for seven years. The GDPR says: keep as little as possible, and no longer than you need it. As long as customer contact lived in a filing cabinet, you barely noticed the tension. The moment you let an AI assistant handle email, WhatsApp or the phone, both rules end up inside the same system. New conversations arrive every day, they all sit together and fully searchable, and the question becomes unavoidable: does all of this have to stay for seven years, or should you be deleting as much as you can? The answer is neither. The two rules cover different piles of data, and once you keep those piles apart, most of the conflict disappears.
Do the two rules really collide?
At first glance they do. One law forces you to keep things, the other forces you to throw things away. In practice they rarely meet, because they have a different reach.
The retention obligation is a floor on a limited slice. Article 52(4) of the Dutch General State Taxes Act (Algemene wet inzake rijksbelastingen) says that anyone subject to the record-keeping obligation must keep the data carriers for seven years, unless a tax law provides otherwise. That covers your business records, not everything you happen to have stored.
The minimisation principle is a ceiling on everything. Article 5 GDPR requires personal data to be adequate, relevant and limited to what is necessary for the purpose. The same article also says you may not keep data in a form that identifies people for longer than that purpose requires.
Those two overlap only on a small surface. And on that surface there is no conflict either: where the law obliges you to keep something, keeping it is necessary by definition. Complying with a legal obligation is a valid purpose. So the question is never "seven years or delete", but: which piece of data belongs in which pile?
What exactly does the retention obligation cover?
Your business records. That means the record of your financial position and of everything concerning your business: invoices, quotes, order confirmations, contracts, payments, time sheets, and the correspondence that establishes rights and obligations. What matters is whether something records a right or an obligation, not where it happens to be stored.
That means two things at once, and most business owners only know one of them.
The first: the channel is irrelevant. The Dutch Tax Administration states itself that communication tools you mainly use privately, such as a private email address or WhatsApp, can form part of your business records as soon as they are also used for business. A price agreement your AI assistant confirms over WhatsApp is part of your records. The fact that it sits in a chat window changes nothing. Your AI inbox is not a disposable folder.
The second, and this one gets forgotten more often: the retention obligation does not cover the rest. "Are you open on Saturday?" is not a business record. A customer asking for directions establishes no right and no obligation. The same goes for most small talk, for the test messages you sent yourself, and for the countless times someone only wanted to know your opening hours. The seven-year term does not apply there, so only the GDPR is left.
How do you tell whether a conversation is a business record?
This is the only sorting question that really matters, and three checks will answer it. Run through them whenever you are in doubt about a conversation.
- Does money follow from it? A price, a discount, a deposit, a credit note, an outstanding balance. If the answer is yes, it belongs to your records and you are done.
- Does it record an agreement that could later be disputed? A delivery date, a warranty promise, a cancellation, a change to the job. Then it belongs there too, even if no invoice exists yet.
- Would you pull this conversation up if a dispute arose about the job? If so, it is part of the file and you do not delete it just because the chat is filling up.
Three times no means: not a business record. Then you set the retention period yourself, and it may be short. And you do not have to weigh every borderline case one by one. It is far more efficient to write one rule that removes the doubt, for example: every conversation linked to an order or a quote number goes to the accounting system, the rest does not. A rule like that can be automated. A gut feeling cannot.
Why does the GDPR contain no number at all?
Because no lawmaker could invent a single period that works for a dental practice, an installation company and a webshop at the same time. The Dutch Data Protection Authority puts it plainly: the GDPR contains no specific retention period for personal data, organisations decide for themselves how long they keep it, and other laws do contain specific periods that organisations must comply with.
That is both good news and bad news. Good, because you get to choose what fits your business. Bad, because it means you have to be able to explain that choice. "We keep everything just in case" is not a retention policy, it is the absence of one. And "we clear everything out as fast as we can" is equally wrong, because then you are demolishing your own business records.
What you need fits on a single page. For each type of data, write down: what it is, what you use it for, how long you keep it, and what that period is based on. For business records the justification is the law. For everything else the justification is your own reasoning, for example: "our warranty runs on after handover, so we keep service conversations for as long as that warranty runs and no longer".
What are you actually allowed to delete from an AI channel?
More than most business owners think. An AI assistant produces a lot of material that leads nowhere and that you need for nothing:
- conversations that were only about opening hours, addresses or availability;
- raw audio recordings of phone calls, once a summary or transcript exists;
- technical log files and intermediate model output that you only kept for debugging;
- contact forms and chats from people who never became customers;
- duplicate copies of the same email sitting in three systems;
- your own test and demo conversations.
The rule of thumb is simple. If you cannot write down in one sentence which right or obligation follows from a conversation, it does not belong in your business records. Then it falls under your own retention period, and that period may be short.
Which data do you keep, and on what grounds?
The table below is not law, but a way to sort your own channel. The ground in the right-hand column is what you write down when someone asks why you made this choice.
| Type of data | Keep or delete | Grounds |
|---|---|---|
| Invoice, quote or order confirmation from the AI inbox | Keep | Business record; Article 52(4) AWR |
| Chat message with an agreement on price, delivery or discount | Keep, as part of the customer file | Records an obligation, so a business record |
| Complaint that led to a credit note or goodwill gesture | Keep | Touches the financial records |
| Question about opening hours or directions | Delete on your own short period | Not a business record; Article 5 GDPR |
| Audio recording of a phone call | Delete once the summary is finished | Data minimisation; Article 5 GDPR |
| Contact details tied to an ongoing agreement | Keep | Needed for performance, then a business record |
| Contact details of someone who never became a customer | Delete | Purpose has been achieved; Article 5 GDPR |
| Technical logs and model input held by your supplier | Delete, unless it is a business record | Your period applies at third parties too |
| Your own test and demo conversations | Delete | No purpose left, not a business record |
Deleting or anonymising: what is the difference?
Deleting means the data is gone and cannot be retrieved. Not in the recycle bin, not in an export file on someone's desktop, and within a reasonable time not in your backups either.
Anonymising means reworking the data so it can no longer be traced back to a person, not even by adding other information. If you genuinely manage that, it is no longer personal data and the GDPR stops applying to it. That is why anonymising sounds so attractive.
Watch the difference with pseudonymising. If you replace the name with a customer number but a list exists somewhere that takes you from that number back to the name, nothing has been anonymised. It remains personal data and every rule still applies.
Where anonymising genuinely helps: steering on numbers. How many conversations your AI assistant handles per week, how often it hands over to a human, which questions keep coming back. That statistic does not need a name attached. Keep the numbers, delete the conversations.
Where it is not allowed: on anything you must keep because of the retention obligation. An invoice without a customer name is no longer an invoice, and an order confirmation with the address stripped out does not satisfy the record-keeping obligation. Anonymising is an alternative to deleting, not a trick for escaping a statutory retention duty.
How do you keep things separate without building a second system?
Separate storage sounds like two servers, but it is mainly a matter of destination and retention periods. Four steps usually get you there.
- Designate one place where business records land. Usually your accounting or order system. Anything that establishes a right or an obligation has to end up there, even if the conversation started in WhatsApp.
- Give the conversation archive its own short period. Switch on automatic clean-up and pick a period you can explain. Check once with your own eyes that it actually happens.
- Flag the conversations that led to an order, a complaint or an agreement, so the clean-up skips them. Without that flag you are choosing between keeping everything and accidentally wiping your own records.
- Limit who can reach what. Someone processing orders does not need to read full chat logs. Restricting access is a form of minimisation too.
One thing gets structurally overlooked here: data held by someone else is still your responsibility. The Dutch Tax Administration is explicit about this: if you have your records kept wholly or partly by third parties, the data those third parties hold about your business must be retained as well, and that obligation continues after you have wound the business down. Translated to an AI platform: if the only copy of a price agreement sits in your supplier's chat history, and that supplier clears its chat history out periodically, the agreement is gone and you have a problem during an audit. Make sure business records never live only in the AI channel, and make sure you can get them out in a form you will still be able to open later.
A customer asks to be deleted while the retention period is running
This is the scenario where everyone gets stuck. Someone emails or messages: remove everything about me. Article 17 GDPR gives them that right to erasure, and it adds that you must erase without undue delay. But the same article contains exceptions, and one of them is that the right does not apply insofar as processing is necessary for compliance with a legal obligation. The retention obligation is exactly such an obligation.
That is not a licence to simply refuse the request. The right response is to split it.
- Everything that is not a business record goes. Chat history without agreements, call notes, a newsletter subscription, call recordings, contact details you only kept for marketing.
- Everything that touches your business records stays until the statutory period has run out. Invoices, orders, payment data and the correspondence that belongs with them.
- Whatever stays, you put on hold where you can: no longer used for marketing, no longer fed as context to your AI assistant, and accessible only to people who need it.
Then you explain it. Say which part has been deleted, which part stays, why it stays and roughly until when. That last bit matters: a customer who hears "that is not allowed" walks away angry, while a customer who hears "your conversation history is gone, tax law requires us to keep your invoices a while longer and after that they go automatically in the clean-up" usually understands perfectly well. Record the request and your reasoning, including when you partly say no. If a regulator ever asks, that record is your only evidence that you thought about it.
What you can arrange this week
You do not need to start a legal project. Six steps cover most of it.
- List every place customer conversations end up: mailbox, chat platform, telephony, CRM, backups and your supplier's systems.
- Write down one retention period and one reason per place.
- Make sure everything that is a business record automatically lands in your accounting system, and not only in the conversation channel.
- Switch on clean-up for the rest, and check later with your own eyes that something was actually removed.
- Ask your supplier three things in writing: how long do you keep it, what happens when I cancel, and how do I get my data out in a readable form.
- Write one paragraph about retention periods in your privacy statement and one standard reply for erasure requests.
Keeping things for seven years and keeping as little as possible are not opposites. They are two instructions for two different piles. The work is not in choosing between them, but in sorting up front, so your system can handle the rest on its own.