Direct Answer
GDPR sets no single retention period for former employee data; it must be deleted once the employment purpose ends, unless another law requires otherwise. In Germany, that means tiered periods: 3 years for employment documents, 6-10 years for tax and accounting records, and up to 30 years for pension data.
Key Takeaways
There is no blanket "GDPR 7-year rule" for employee data; the 7- or 10-year periods apply only to specific tax and accounting records under German fiscal law, not to contracts, emails, or device data.
German retention obligations are tiered: 3 years for general employment documents (§195 BGB), 6 years for commercial correspondence (§257 HGB), and 10 years for tax-relevant accounting records (§147 AO), with pension claims stretching up to 30 years.
IT accounts, email inboxes, and device access that linger after offboarding create both a GDPR compliance risk and a cybersecurity exposure; every orphaned account is data you must account for if a former employee files a subject access request.
Automated offboarding workflows can revoke access on the employee's last day while preserving exactly what the company is legally required to retain, and where.
Picture this: an employee left your company six months ago, yet their Google Workspace account is still active, a laptop backup sits untouched on a shared drive, and payroll records are scattered across three different tools. If you're an HR manager, office manager, or founder at a small or mid-sized company in the DACH region, this scenario probably feels familiar. Many guides cite a blanket "GDPR 7-year rule" for employee records. That number applies to a narrow slice of financial records under German tax law, not to most of what you're storing. The reality is more nuanced, and the consequences of getting it wrong are growing.
Germany reported 27,829 personal data breach notifications in the 12-month period from January 28, 2024, to January 27, 2025, the second highest count in Europe after the Netherlands (DLA Piper). A significant portion of these breaches trace back to access that was never revoked or data that was never deleted. This article breaks down what GDPR actually requires you to keep versus delete, the specific German retention periods that apply to different categories of employee data, and how to close the gap between legal obligation and IT reality, especially if you don't have a dedicated legal or GDPR IT compliance team.
What does GDPR actually require after an employee leaves?
GDPR does not prescribe a single retention period for employee data. Instead, it establishes two principles that work in tandem: purpose limitation and data minimization. Under Article 5(1)(b), personal data may only be kept for the specific purpose it was collected. Article 5(1)(e) adds that data must be stored in a form that permits identification only for as long as necessary to fulfill that purpose. Once the employment relationship ends, the original purpose for processing most of that data disappears.
This means you need to ask two separate questions for every category of data you hold on a former employee. First, are you still allowed to keep it? And second, are you required to keep it by another law? GDPR explicitly acknowledges that national legislation (tax codes, social security regulations, labor law) can mandate retention beyond the end of the employment relationship. That's where it gets complicated, because "allowed" and "required" are not the same thing.
If you keep data longer than necessary without a legal basis, you're violating the data minimization principle. European supervisory authorities issued GDPR fines totaling approximately EUR 1.2 billion in 2025 (DLA Piper). On the other hand, if you delete payroll records that German tax law requires you to retain for ten years, you'll have a different problem during your next audit. The job is to thread the needle between these two obligations.
The "7-year rule" myth
Search online for "GDPR employee data retention" and you'll find dozens of posts referencing a blanket 7-year rule. This is misleading. The 7-year figure loosely corresponds to the 6-year retention period for commercial letters and business correspondence under §257 HGB (German Commercial Code), sometimes rounded up. The actual 10-year period under §147 AO (German Fiscal Code) applies to booking receipts, annual financial statements, and tax-relevant accounting documents. Neither rule covers all employee data. Performance reviews, internal chat logs, personal email content, and device data have no automatic 7-year safe harbor. If you're holding onto a former employee's Slack history "just in case" and citing the 7-year rule, you're likely in breach of GDPR's data minimization principle with no legal ground to stand on.
Which retention periods apply under German law?
German law creates a tiered system of retention obligations. Each tier applies to specific document types, not to "employee data" as a lump category. Here's a practical breakdown.
General employment documents (3 years, §195 BGB)
The standard limitation period (Verjährungsfrist) under German civil law is three years, starting at the end of the calendar year in which the employment relationship ended. This covers most claims an employee could bring: disputes over the employment contract itself, reference letters (Arbeitszeugnisse), overtime claims, or unused vacation pay. Once those three years pass and no claim is pending, the legal basis for retaining these documents expires.
Practically, this means you should keep the signed employment contract, any amendments, the termination letter, the reference letter, and records of outstanding entitlements for three years after the employee's departure. After that, GDPR's minimization principle kicks in and those documents should be deleted or anonymized.
Wage tax and accounting records (6 to 10 years, §41 EStG, §257 HGB, §147 AO)
This is where the longer retention periods apply, but only for specific financial records.
6 years (§257 HGB): commercial correspondence, including letters related to employment that have business relevance.
10 years (§147 AO / §41 EStG): wage tax records (Lohnsteuerunterlagen), payroll accounting documents, booking receipts, and annual financial statements. If a payroll record is relevant for tax purposes, it falls here.
These periods begin at the end of the calendar year in which the last relevant entry was made or the document was created. A payroll slip from December 2024 triggers a retention obligation that runs until the end of 2034.
Keep in mind: this does not mean you keep the employee's entire HR file for ten years. It means you keep the specific financial documents for that period and delete everything else according to its own, shorter timeline. If you're unsure how to map your data residency and GDPR obligations, a structured audit of where each record type lives is the first step.
Company pension and titled claims (up to 30 years)
This is the exception most SMBs don't expect. If your company offers a pension scheme (betriebliche Altersvorsorge), the data backing those entitlements must be kept until the obligations are fully settled, which can mean 30 years or longer under §18a BetrAVG. Similarly, if a court has issued a judgment (a "titled claim") related to a former employee, the limitation period for enforcement is 30 years under §197 BGB.
For most growing companies in the DACH region, this category affects only a small subset of records. But if it applies to you, it's critical to flag these documents and store them separately from general HR data so you don't accidentally purge them during a routine cleanup.
One more thing worth noting: under §38 BDSG (German Federal Data Protection Act), companies with 20 or more employees regularly involved in automated processing of personal data are required to appoint a Data Protection Officer (DPO). If you've crossed that threshold, your DPO should be involved in setting retention schedules and IT compliance policies.
Where does IT data fit in: devices, accounts, and access logs?
Legal retention guides typically focus on contracts and payroll. They rarely address the IT artifacts that pile up after offboarding: email accounts, SaaS licenses, device backups, access logs, and chat histories. These are all personal data under GDPR, and they need a clear policy too.
Email and messaging accounts
A former employee's email inbox and Slack or Teams history contain personal data, both theirs and potentially that of customers, partners, and other employees. Keeping these accounts active "in case someone needs something" is one of the most common mistakes SMBs make. It creates three problems at once.
First, an active account is an attack surface. 53% of IT leaders identify the risk of a cybersecurity attack via an unmanaged account as their top concern when an employee is not properly deprovisioned (Gartner). Second, it violates data minimization: there's no legitimate purpose for keeping a full inbox accessible indefinitely. Third, under Article 15 GDPR, a former employee can file a subject access request (SAR) at any time. Every account you kept "just in case" is data you now have to locate, review, and disclose or justify. The more accounts that remain active, the more expensive and time-consuming that process becomes.
The practical approach: on the employee's last day, forward essential business emails to a shared mailbox or manager, export any records required for legal retention, and then deactivate and eventually delete the account. For AI tools like ChatGPT on company devices, the same logic applies: revoke access immediately and check whether query histories contain sensitive data that needs to be purged.
Devices, backups, and access logs
Company laptops and mobile devices often contain local copies of files, cached credentials, browser histories, and VPN configurations. If you return a wiped device to your inventory without first extracting legally required records (and deleting everything else), you risk either losing data you need or retaining data you shouldn't.
Access logs present a subtler challenge. Audit trails showing who accessed what systems, and when, may be necessary for IT security policy investigations or regulatory audits. But they also contain personal data. A reasonable retention period for access logs is typically 6 to 12 months, unless a specific incident or legal proceeding requires you to hold them longer.
The global average cost of a data breach reached USD 4.99 million in 2026, a 12% increase over the prior year (IBM). A significant share of breaches involve compromised credentials, and orphaned accounts from former employees are one of the most common vectors. Between January 2025 and January 2026, the average number of daily GDPR breach notifications rose by 22%, exceeding 400 per day for the first time since 2018. Cleaning up IT data after offboarding isn't just a compliance task; it's a security imperative.
How to reduce compliance risk with automated offboarding
If you're managing offboarding with a spreadsheet checklist and a series of reminder emails, you're relying on human memory for something that demands precision. The gap between "we meant to revoke access" and "we actually did" is where breaches happen.
Why manual processes fail
Manual offboarding typically involves HR notifying IT (sometimes days after the employee's last day), IT working through a list of accounts one by one, and someone eventually remembering to collect the laptop. Each handoff introduces delay and the chance that a step gets skipped. In a company using 15 to 30 SaaS tools, it's easy to forget that the departing employee also had access to a design tool, an analytics dashboard, or an AI tool that processes company data.
The global average cost of a data breach reached USD 4.88 million in 2024, a 10% increase from 2023 (IBM). Organizations that used AI and automation extensively in their security workflows saved USD 1.9 million on average per breach compared to those using none. The math is clear: automation pays for itself, and speed is the single most important variable in limiting exposure after someone leaves.
What automated offboarding looks like in practice
An automated offboarding workflow connects your HR system (the source of truth for the employee's last day) to your identity provider and device management platform. On the scheduled date, it revokes access across all connected accounts, triggers device lock or wipe commands, archives records that must be retained to a designated location, and generates an audit trail documenting every action taken.
This is exactly the kind of problem that IT management platforms are built to solve. deeploi, for example, connects to your HR system and workspace tools to run automated offboarding on the employee's last day: accounts are deactivated, devices are wiped remotely, and an audit log records every step. Because the platform stores data in ISO 27001-certified EU data centers, the retention and deletion process itself stays GDPR-compliant. When the offboarding is complete, personal data is deleted or anonymized according to the retention terms agreed with the employer.
The key principle is to separate what gets deleted from what gets archived, and to automate both. Tax-relevant payroll records go to your accounting system for ten years. The employment contract goes to a secure archive for three years. Everything else, including the email account, Slack messages, device data, and cached credentials, gets purged on schedule. Thinking about offboarding in the age of AI means extending this logic to API keys, co-pilot integrations, and shadow AI tools as well.
Frequently asked questions
Can I keep a former employee's email account active "just in case"?
Only briefly, and with a documented purpose. GDPR's data minimization principle requires you to delete or deactivate accounts once the purpose for processing has ended. Forward essential business emails to a shared mailbox, export anything legally required, and deactivate the account within days of the employee's departure, not months.
Do GDPR retention rules differ across the DACH region?
Yes. Germany follows GDPR supplemented by the BDSG and specific fiscal retention laws (AO, HGB, EStG). Austria also falls under GDPR and has its own Datenschutzgesetz (DSG), with broadly similar retention logic. Switzerland, however, is not subject to GDPR at all. It follows the revised Federal Data Protection Act (revFADP, also called nDSG), which came into force in September 2023. If you operate across all three countries, you'll need separate retention schedules for Swiss employee data.
What should I do if a former employee files a subject access request?
You have one month to respond under Article 15 GDPR. You must disclose what personal data you still hold, why you hold it, and how long you intend to keep it. This is exactly why cleaning up data promptly matters: the less you retain, the simpler and cheaper it is to respond. If you've already deleted data in line with your retention schedule, document that the deletion occurred and the legal basis for it.
How do I document my retention schedule in an audit-proof way?
Create a written retention policy that maps each data category (contracts, payroll, access logs, device data) to its legal basis and retention period. Record when data was created, when the retention clock starts, and when deletion is due. Store this documentation alongside your Record of Processing Activities (Verzeichnis der Verarbeitungstätigkeiten), which is required under Article 30 GDPR. Automated IT management tools can generate audit logs that serve as evidence of timely deletion.
Is there really a 7-year GDPR rule?
Not as a general rule. GDPR itself does not specify any fixed retention period. The "7-year" figure commonly cited online is a rough reference to the 6-year commercial correspondence retention period under §257 HGB, often rounded up. The actual periods range from 3 years for general employment documents to 10 years for tax records and, in rare cases, up to 30 years for pension-related data. Applying a blanket 7-year rule to all employee data will leave you non-compliant in both directions: keeping some things too long and deleting others too soon.
Conclusion
Employee data retention under GDPR isn't a single rule you can memorize. It's a set of layered obligations that vary by data type, legal basis, and jurisdiction. The good news is that once you've mapped your retention schedule, the execution can be almost entirely automated. Revoke access on the last day. Archive what the law requires, in the right place, for the right duration. Delete everything else on schedule. The goal is compliance by default, not by memory. And if your current offboarding process depends on someone remembering to disable a Google account three weeks after a departure, it's time to fix the system, not the person.










