Obligation
Data retention rules require a Data Fiduciary to erase personal data once consent is withdrawn or the specified purpose is no longer served, unless a law requires keeping it.
A Data Fiduciary shall, unless retention is necessary for compliance with any law, erase personal data upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier, and cause its Data Processor to erase such data.
The default is deletion, not indefinite storage. Once the purpose is done or consent is withdrawn, the fiduciary must erase the data and make its processors do the same.
The purpose is deemed no longer served if the person neither approaches the fiduciary for it nor exercises any rights for a prescribed period, which the Rules set for different classes of fiduciaries.
After a used-car listing sells and the sale concludes, the marketplace should no longer retain the seller's data, unless a law requires it.
When must data be erased?
When consent is withdrawn or the specified purpose is no longer served, whichever is earlier, unless a law requires retention.
Who sets the time periods?
The Rules prescribe them, and they can differ for different classes of fiduciaries and purposes.