Old job applications in the recycling bin, dusty databases, or forgotten cloud backups — when it comes to data destruction, many companies overlook how important the "correct" handling of personal data really is. Under the GDPR, data may only be stored for as long as it's genuinely needed — after that, it must be deleted or destroyed. But what does that mean in practice?
In this article, you'll learn when data destruction is necessary, which methods are GDPR-compliant, and which mistakes you should absolutely avoid. With practical tips, a checklist, and guidance on deletion concepts, you'll be perfectly prepared — both digitally and on paper.
What Happens to Your Data When It's "Gone"?
Whether it's customer data on an old laptop, application documents in the recycling bin, or cloud backups — data is quickly stored, but "properly" deleting it is often forgotten. And it's not just about tidiness or storage space. If personal data is deleted incompletely or improperly, you risk serious data protection violations.
The GDPR stipulates that personal data may only be stored for as long as it's needed for a legitimate purpose. As soon as that purpose no longer applies, the data must be deleted or destroyed — in a way that's GDPR-compliant, traceable, and demonstrable.
Many companies, however, fail at exactly this point: backups are overlooked, paper files remain in the archive, or outdated databases are ignored. Yet data destruction is a central component of an effective data protection management program.
What Does the GDPR Say About Data Destruction?
The General Data Protection Regulation (GDPR) obligates companies to practice data minimization and storage limitation (Art. 5(1) GDPR). As soon as data is no longer needed for its original purpose, it must be deleted — securely.
Right to erasure (Art. 17 GDPR):
Data subjects have the right to request the deletion of their data if:
- the purpose of processing no longer applies,
- consent has been withdrawn,
- data was processed unlawfully,
- or a legal obligation to delete the data exists.
Key Terms Explained Simply
- Deletion: data can no longer be found or reconstructed.
- Destruction: data is physically or technically destroyed so that it can no longer be recovered (e.g., through shredding or secure deletion software).
- Anonymization: data is altered so that it can no longer be attributed to any individual.
Simply deleting data is often not enough — for particularly sensitive data or physical media, destruction is required.
When Must Data Be Destroyed?
There are various situations in which the GDPR requires the complete deletion or destruction of personal data. Here are the most important ones explained in detail:
1. After statutory retention periods expire
Much data, particularly from accounting, must be stored for a specific period for tax or commercial law reasons (e.g., 6 or 10 years). Once these periods expire, there's not only no longer an obligation to retain the data — there's actually an obligation to delete it. Continuing to store the data is a violation of the GDPR.
2. When consent is withdrawn
If a data subject has given consent to the processing of their personal data, they can withdraw it at any time. From that point on, the data may no longer be processed and must — unless another legal basis applies — be deleted or destroyed.
3. When the purpose no longer applies
Once data has fulfilled its original purpose — for example, after a project or job application has concluded — its continued storage is no longer justified. It must therefore be deleted or destroyed. Good data management ensures such cases are regularly identified and processed automatically.
4. Upon a successful access request or deletion request
Data subjects have the right to request information about their stored data and demand its deletion (Art. 15 and 17 GDPR). If such a request is granted, companies must completely and securely delete or destroy the data in question — including from backups, where technically feasible.
5. When switching data processing service providers
When switching a cloud service, HR software, or another external provider, personal data at the previous provider must be deleted or destroyed. Important: this should be regulated in the Data Processing Agreement (DPA) and documented in a verifiable way.
GDPR-Compliant Methods for Data Destruction
1. Physical media (paper, USB drives, hard drives):
- Shredding according to DIN 66399
- Degaussing
- Thermal destruction
2. Digital data:
- Secure deletion software (e.g., according to BSI standards)
- Complete deletion of backups
- No simple "deleting" via the recycling bin or formatting
3. Cloud services & external providers:
- Contractual provisions for data deletion (DPA)
- Choosing GDPR-compliant providers
Common Mistakes in Practice
1. "Deleting" without true irretrievability
Many companies rely on simply pressing "delete" or moving files to the recycling bin. But such methods aren't sufficient to destroy data in a GDPR-compliant way. In many cases, data can be recovered with little effort — a real risk in the event of data breaches or audits.
2. No documentation of the deletion process
The GDPR requires companies to handle personal data in a traceable way. Without traceable documentation of when, how, and by whom data was deleted, proof of compliance is often missing in case of doubt — a common criticism during data protection audits.
3. Data remnants in backups or shadow IT
Backups are often forgotten — even though personal data is stored there too. If data is deleted from the live system but remains in backup copies or uncontrolled systems (e.g., spreadsheets on personal devices), this constitutes a violation of the GDPR's storage limitation principle.
4. No clearly defined deletion concept
Without structured processes and clear responsibilities for data destruction, gaps emerge in data protection management. A deletion concept defines standards, responsibilities, and deletion deadlines — without one, data destruction quickly becomes a gray area within the company.
Deletion Concept & Documentation: Why It's So Important
The GDPR requires traceability and demonstrability. You should therefore document:
- which data was deleted and when
- which methods were used
- who is responsible
- whether deadlines were met
A deletion concept helps you implement all requirements systematically.
Checklist: 5 Steps to GDPR-Compliant Data Destruction
- Identify data: What personal data exists, and where?
- Check retention periods: Which data may or must be destroyed?
- Choose the appropriate method: Paper, hard drive, or cloud?
- Document deletion: Time, method, person responsible
- Review regularly: Is your deletion concept up to date and effective?
FAQ
What happens if I don't destroy the data in time?
What happens if I don't destroy the data in time?
You risk fines and legal warnings, especially in the event of security incidents or subject access requests.
Is simply deleting data enough?
Is simply deleting data enough?
No. In many cases, data must also be made technically or physically inaccessible (destruction).
What is a deletion concept?
What is a deletion concept?
A deletion concept is a documented plan for how, when, and by whom data is destroyed in a GDPR-compliant way.
How often do I need to carry out data deletions?
How often do I need to carry out data deletions?
Regularly — ideally through automated deletion periods and internal audits.
Can heyData support me with implementation?
Can heyData support me with implementation?
Yes. From analysis and tools to deletion, we guide you through the entire process in a legally compliant way.







