Skip to main content
Privacy Law 8 min read By Adv. Or Elyashiv

How Long Can Tech Companies Retain Personal User Data

Israeli law sets no fixed retention schedule for personal data, but it does impose a binding principle — and companies that ignore it face real regulatory and litigation exposure.

קראו בעברית

When should you actually delete the data you collected?

A typical Israeli SaaS company collects user details at sign-up, keeps accumulating usage data throughout the customer relationship, and often retains all of it for years after the customer has stopped using the service. The question "why is this data still here" usually surfaces in only two scenarios: after a security incident, or when a regulator asks to examine the database.

In both scenarios, "we never got around to deleting it" is not an acceptable answer. Israeli law, particularly the Privacy Protection Law as amended by Amendment 13, imposes an active obligation on companies not only to collect data lawfully, but also to hold it only for as long as there is a substantive justification for doing so.

This article addresses the practical question: how long is retention permitted, and when does the obligation to delete or anonymize data kick in.


The purpose limitation principle under Israeli law

The Privacy Protection Law, 5741-1981, as amended by Amendment 13 (in force as of August 14, 2025), does not set out a fixed, one-size-fits-all retention schedule for personal data. Instead, it rests on a substantive principle: personal data is collected and held for a defined purpose, and once that purpose has been fulfilled or ceases to exist, there is no justification for continuing to retain the data.

This principle is also reflected in the Privacy Protection Regulations (Data Security), 5777-2017, which require database owners to document, in the database definitions document, the purposes for which data is used and the categories of data held, and impose an obligation to periodically review whether retention still corresponds to those defined purposes. In practice, this means a company that collects customer information in order to provide a service cannot continue holding that information indefinitely merely because it "might still be useful."

What this means in practice


Sector-specific retention rules may override the general principle

The general purpose limitation principle does not operate in a vacuum. Many sectors are subject to specific legal regimes that require certain categories of data to be retained for defined periods, and these obligations take precedence, to some extent, over the drive toward early deletion.

Technology companies operating across multiple domains should map which sector-specific obligations apply to them, and confirm that the applicable regulatory framework, as of the date of this article, has not changed.


Users' erasure rights and the consequences of excessive retention

Amendment 13 to the Privacy Protection Law sharpened the standing of data subjects, including with respect to the right of access and erasure. A user whose data is held by a company is, in circumstances defined by law, entitled to request access to that data and even its deletion, particularly once the purpose for which it was collected is no longer relevant.

Beyond that, Amendment 13 added a data breach notification obligation to the law and expanded the enforcement powers of the Privacy Protection Authority. The practical implication: a company holding old, no-longer-relevant data effectively increases its "exposure surface" in the event of a security incident — because notification obligations and their operational and legal consequences apply equally to data that no longer serves any business purpose.

In short, retaining data beyond what is necessary is not merely a theoretical exposure to regulatory scrutiny — it compounds the risk in every future security incident.


The GDPR storage limitation principle and its relevance to Israeli companies

The EU General Data Protection Regulation (GDPR) sets out a parallel and more explicit principle — storage limitation — under which personal data may not be kept in a form permitting identification of the data subject for longer than necessary for the purposes for which it is processed. Israeli companies processing the data of EU residents, or operating in European markets, are directly subject to this principle.

Israel holds an adequacy recognition from the European Union, a status subject to periodic review and potential change. Companies whose operations involve transferring data from the EU should monitor developments in this area, and address the requirements applicable under the data protection laws of the country of origin as well.

In practical terms, a company that aligns its retention policy with the storage limitation principle is, in effect, also well positioned to meet the requirements of Israeli law post-Amendment 13, since the underlying principle is largely the same.


How to build a sound data retention policy in practice

A data retention policy is not a generic legal document — it is the product of an internal mapping process. The following steps are recommended:

  1. Data mapping — identify every category of personal data held by the company, its source of collection, and the purpose for which each category is used.
  2. Set a retention timeline per category — for each data type, define a retention period based on legitimate business purpose and, where relevant, sector-specific legal obligations.
  3. Automated deletion or anonymization mechanism — build automated technological processes, wherever possible, to delete or de-identify data once the retention period expires, rather than relying on manual deletion.
  4. Legal hold mechanism — provide a controlled exception to the retention schedule where litigation, an investigation, or a regulatory demand justifies continued retention.
  5. Periodic review and documentation — document the policy and revisit it as business operations and regulatory requirements evolve.

Companies that have appointed a data protection officer, where such an appointment is required, should involve that officer in developing the policy and in its ongoing review.


The risk of non-compliance and the practical bottom line

Amendment 13 significantly expanded the enforcement powers of the Privacy Protection Authority, and enables the imposition of substantial administrative fines for certain violations, in accordance with the current legal framework and the severity of the breach. Beyond the financial exposure, holding irrelevant data increases a company's exposure surface in any security incident and makes it harder to meet the timeframes prescribed for breach notification.

A clear data retention policy is not merely a compliance tool — it is also an operational asset that reduces storage overhead, simplifies responses to data subject requests, and limits potential damage in the event of a data leak.

Companies that have not yet formalized a retention policy should start by mapping the data they currently hold, not only the data they collect going forward. In most cases, the largest gap lies in "historical" data that has accumulated over the years without ever being properly reviewed.


The information contained in this article is general in nature and does not constitute legal advice. For advice tailored to the specific circumstances of your company, we invite you to contact our firm.

Adv. Or Elyashiv
Written by

Adv. Or Elyashiv

Founder of Or Elyashiv Law Firm, specializing in technology law, privacy protection, intellectual property, and commercial law. Advising tech companies, startups, and international investors. Data Protection Officer (DPO), a graduate of the Tel Aviv University training program for data protection officers, held in cooperation with the Israeli Privacy Protection Authority.

View All Articles

Need to build a compliant data retention policy?

Our firm advises technology companies on developing personal data retention and deletion policies aligned with the Privacy Protection Law post-Amendment 13 and relevant sector-specific requirements. We are glad to review your company's current practices and assist in adapting them.