Skip to content
DPAFlow

gdpr

What Evidence Should You Retain From Vendor Reviews?

Keeping everything forever and keeping nothing both fail. How to set retention by purpose, why most of this material is not personal data, a workable schedule, and how to dispose of evidence defensibly without erasing former vendors.

Vendor review programmes accumulate evidence quickly: questionnaires, assurance reports, captured disclosures, assessment notes, decision records, and correspondence. Two opposite failures follow. Some organizations keep everything forever, which turns the accountability file into its own compliance problem. Others keep nothing beyond the current version, and discover during a regulator query or a customer audit that they cannot show what the position was when a decision was made.

This article is about the middle course: how long to keep vendor review evidence, on what reasoning, and how to dispose of it defensibly. What constitutes good evidence in the first place is covered in audit-ready vendor evidence; this article assumes you have it and asks how long it should live.

Start from why you hold it

Retention periods follow purpose. Vendor review evidence generally serves four purposes, and each implies a different horizon:

  • Demonstrating accountability under Article 5(2) of the General Data Protection Regulation (GDPR), which means being able to show that a decision was taken on a reasoned basis at the time.
  • Supporting the processing record required by Article 30, which must reflect current processing and is more useful with its history intact.
  • Defending contractual positions, which follows the limitation period applicable to the contract.
  • Supporting your own customers' audits, which follows your commitments to them.

Write the purpose next to each category. A retention schedule without stated purposes is arbitrary, and arbitrary schedules are the ones that get abandoned.

The evidence itself is usually not personal data

An important distinction that simplifies matters: most vendor review evidence is about a company, not about individuals. A captured sub-processor page, an assurance report, or an assessment note is corporate information, and the storage limitation principle in Article 5(1)(e) applies to personal data rather than to it.

Two exceptions matter. Questionnaire responses and correspondence usually contain names, job titles, and contact details of individuals at the vendor and in your own organization. And incident-related material can contain personal data about affected individuals. Those elements are personal data, and they need a retention position of their own.

The practical approach is to set retention by document category, and to treat the contact-detail layer as something you can minimise at disposal time rather than as a reason to delete the whole record.

A workable schedule

The following is a defensible starting point to adapt rather than adopt.

Hold for the life of the relationship, plus the contractual limitation period

  • Decision records, including approvals, conditions, and the accepting owner.
  • Assessment notes and risk ratings, with reasoning.
  • Transfer assessments and any supplementary measures recorded.
  • Captured vendor disclosures relied on at the point of a decision.
  • Objections raised and their outcomes.

These are the artifacts that answer "why did you conclude that, and on what basis" long after the fact. Deleting them at termination is the most common mistake, because questions about a vendor relationship frequently arise after it has ended.

Hold for a defined period after termination

  • Deletion and return confirmations, which should outlive the relationship by enough to cover any later query about where the data went.
  • The final position of the sub-processor chain and transfer mechanisms.

Hold for a shorter period, then review

  • Questionnaire responses superseded by a later round.
  • Superseded assurance reports, once a current one is on file.
  • Routine change alerts that were assessed as immaterial, which can be retained in summary rather than in full.

That last category is worth attention in a monitoring programme, because it generates the most volume and carries the least individual value. A summary record showing that a change was detected, assessed, and judged immaterial, with the date and assessor, preserves the accountability point without retaining every artifact.

Versions matter more than currency

The instinct to keep only the current version is wrong for this material. The point of vendor review evidence is to show what was true when a decision was taken, and the current version cannot do that.

Keep the version you relied on, with the date you captured it, alongside the current one. This is why linking to a vendor page is inadequate as evidence: the link resolves to today's content, and today's content is not what you assessed. Our article on evaluating a sub-processor list makes the same point from the assessment side.

Disposal should be a process, not an omission

Defensible disposal has three characteristics: it happens on a schedule, it is recorded, and it is suspended when it should be.

  • Apply the schedule on a defined cycle rather than when storage runs short.
  • Record what was disposed of and when, at category level. A disposal log is what distinguishes deliberate deletion from a gap.
  • Suspend disposal for material under legal hold, subject to an active regulatory query, or connected to an open incident.

Deleting evidence while a matter is live is considerably worse than keeping it too long, so the hold mechanism should be simple enough to be used.

Do not erase former vendors from the record

When a relationship ends, mark the processing as ended in your Article 30 record with a date rather than removing the entry. Erasing the entry destroys the evidence that the processing was governed properly while it was live. Our article on keeping records accurate as vendors change covers the maintenance discipline, and vendor offboarding covers the closing steps.

Frequently asked questions

Does the GDPR set a retention period for this evidence?

No. It requires accountability under Article 5(2) and storage limitation for personal data under Article 5(1)(e), and leaves the period to be justified by purpose. The obligation is to have a reasoned position, not to hit a specific number.

Can we keep everything indefinitely to be safe?

Not where the material contains personal data, since indefinite retention conflicts with storage limitation. Corporate evidence can be held longer, but unbounded accumulation makes the file harder to search and to defend.

What about evidence held inside a monitoring tool?

The same schedule applies wherever the evidence sits. Confirm what the tool retains, for how long, and whether you can export it, because a retention position that depends on a supplier's default settings is not a position.

Who owns the schedule?

Privacy usually owns it, with records management or legal input. The important thing is that a named function owns it, since unowned schedules are not applied.

Where DPAFlow fits in

Retention only works if the evidence exists in a durable form in the first place. DPAFlow checks vendor sub-processor lists, Data Processing Agreement pages, and trust-center pages on a scheduled, recurring basis, and records what changed with dated evidence including captured page text and change differences, so the version relied on at a decision point is preserved rather than replaced. Detected changes enter a review workflow where your team records its assessment, which is the summary-level artifact this article recommends keeping.

DPAFlow does not set your retention schedule and does not provide legal advice. The evidence model is described on the evidence page.

This article proposes a retention approach. It is not legal advice, and periods should be set with your own counsel and records management function.

DPAFlow · 2026-07-25

Monitor subprocessor changes before they become audit work.

Create a vendor watchlist, receive risk-ranked alerts, and keep Article 28 evidence ready.

View evidence workflow