A company data retention policy is an internal rule that sets out how long each category of personal data may be kept before it must be deleted or destroyed. It isn’t just a paperwork exercise, since it becomes the reference point for deciding what data still needs protecting and what’s overdue for disposal.
The trouble is that the rules governing how long data must be kept often pull in opposite directions. Indonesia’s Tax Law requires bookkeeping documents to be kept for 10 years, while the PDP Law pushes companies to delete data as soon as its processing purpose is served.
Building a proper company data retention policy means reconciling both interests, rather than picking whichever rule is easier to follow. This article walks through how, starting with the legal basis and ending with the practical steps.
What Is a Data Retention Policy?
A company data retention policy is typically a document that maps every category of personal data an organisation holds, how long it can be kept, and what triggers its deletion or destruction. It gives everyone a shared reference, so the decision to delete or keep something doesn’t depend on one team member’s memory or personal judgment.
The Legal Basis Under Indonesia’s PDP Law
The legal basis sits in Article 16(2) of Indonesia’s Law No. 27 of 2022 on Personal Data Protection (the “PDP Law”), which makes deletion after the retention period ends one of 8 mandatory principles for any personal data processing. As with the PDP Law’s other obligations, this applies extraterritorially, so a foreign company processing the personal data of people in Indonesia is bound by the same principle even without a local entity.
This obligation isn’t purely internal either. Article 21(1)(d) of the PDP Law requires controllers to disclose the retention period to data subjects when obtaining consent, which means the retention period has to be decided upfront rather than worked out later when it’s needed.
Read also: Data Compliance: A Must-Have Strategy to Avoid Regulatory Fines
Why Retention Gets Complicated: Competing Rules
Retention gets complicated mainly because the PDP Law isn’t the only rule governing how long data can be kept. The table below compares how the PDP Law and 3 other Indonesian rules treat the same underlying question.
| Type of Data or Document | Governing Rule | Retention Period |
|---|---|---|
| Personal data in general | Article 16(2) of the PDP Law | As long as needed for the processing purpose, then must be deleted |
| Personal data in electronic systems | MOCI Regulation No. 20 of 2016 | Minimum 5 years from when the data subject stops using the system |
| Bookkeeping documents (including payroll and client invoices) | Article 28(11) of Indonesia’s Tax Law | 10 years |
| Financial services customer records | Article 35 of OJK Regulation No. 39/POJK.05/2015 | 10 years from when the business relationship ends |
Indonesian legal expert Adhi raised this exact tension directly at a public discussion hosted by SafeNet and reported by NU Online on 21 November 2025. He explained that the PDP Law requires data to be deleted once its storage period ends, while national archival rules can require some of that same data to be kept for decades.
5 Steps to Build a Company Data Retention Policy
Building a company data retention policy follows 5 steps in order: inventory data categories, check other sector rules, set a retention period per category, disclose it in your privacy policy, then automate deletion. Each step is explained below.
1. Inventory Data Categories and Their Processing Purpose
Group the personal data your company holds by purpose, such as employee data for payroll, customer data for transactions, or applicant data for recruitment. Without this grouping, a retention policy ends up as a single number forced onto every kind of data.
2. Check for Sector Rules That Require Longer Retention
For each category of data, check whether a rule outside the PDP Law, such as tax, financial services, or employment regulation, requires a longer retention period. This step gets skipped most often, even though it’s usually what actually determines the correct retention period.
3. Set a Retention Period for Each Data Category
Once the sector rules are identified, set a specific retention period for each category rather than applying one figure across the board. Payroll data can reasonably have a different retention period from marketing data, even though both count as personal data.
4. Disclose the Retention Period in Your Privacy Policy
Add the retention period for each data category to your privacy policy or consent form. This step satisfies the disclosure requirement in Article 21(1)(d) of the PDP Law while also building transparency with customers.
5. Automate Deletion and Review Regularly
The UK’s ICO recommends periodically reviewing the data you hold, then deleting or anonymising it once it’s no longer needed. Relying on manual deletion usually means data quietly piles up for years because no one gets around to acting on it.

Common Mistakes When Building a Retention Policy
There are at least 5 mistakes that most often undermine a company’s data retention policy. Recognising the pattern helps avoid repeating it.
- Setting one retention period for every type of data instead of distinguishing between categories.
- Not checking sector rules, such as tax or financial services regulation, that can require longer retention than the PDP Law alone.
- Keeping data with no clear processing purpose, just in case it becomes useful later.
- Leaving the retention period out of the privacy policy shown to users.
- Having no automated process to delete data once its retention period ends, relying instead on manual deletion that often gets missed.
Conclusion
A good company data retention policy doesn’t stop at one rule, since it has to reconcile the PDP Law’s deletion principle with retention obligations from other areas of Indonesian law, including tax and financial services regulation. Inventorying data by category, checking sector rules, and automating deletion are what decide whether a policy actually gets followed or just sits as a document no one refers to.
The more categories of data a company manages, the harder it gets to stay consistent without some system tracking it automatically. Manual checks tend to look fine right up until years of accumulated data reveal that no one was actually keeping up with it.
Ready to Manage Privacy Compliance as a Business Risk?
See how GRC helps map personal data risks, monitor compliance with the PDP Law, and prepare companies for audits without complicated manual processes.
FAQ
No. The PDP Law only requires data to be deleted once its retention period ends, while the specific length is determined by the processing purpose and any applicable sector rules.
The request still needs to be considered, unless the data must legally be kept under another rule, such as tax law. In that case, the company should explain the legal basis for not deleting it yet.
Yes, at minimum the retention period needs to appear in the privacy policy or consent form. This is part of a controller’s transparency obligation under the PDP Law.
Usually the compliance team or data protection officer, with input from legal and whoever owns the relevant business process. Involving the process owner matters because they best understand how the data is actually used day to day.
The company risks being found in breach of the PDP Law’s processing principles, though that doesn’t automatically mean a penalty follows. The risk grows considerably if that excess data is later breached or misused.
Yes. The PDP Law applies extraterritorially, so a foreign company processing the personal data of people in Indonesia is bound by the same retention principle regardless of where it’s based.




