The rule behind retention.
GDPR does not set one fixed number of days or years that applies to every kind of data. Instead it asks a simpler question of any organisation: is there still a genuine reason to keep this record. Once the answer is no, the data is supposed to be deleted or properly anonymised rather than left sitting in a system indefinitely, gathering risk without gathering any further use.
In practice this means two pieces of data collected on the same day, from the same person, can have entirely different lifespans. A marketing preference can be deleted the moment someone unsubscribes, while a narrow accounting record tied to the same transaction may need to stay on file for a defined stretch set by separate tax rules that have nothing to do with GDPR itself.
This distinction trips people up more often than any other part of data protection law, largely because a single account can quietly contain several different kinds of data at once, each one governed by its own rules rather than one blanket answer covering the whole account together.
Why some records outlast others.
The purpose a piece of data was collected for decides its retention period, not the sensitivity of the data itself. A record kept purely to remember a preference has no reason to survive once that preference stops being relevant. A record kept to satisfy a legal bookkeeping obligation has to survive for whatever period that separate law requires, independent of what GDPR alone would otherwise ask for.
This is also why deleting an account rarely means every trace disappears instantly. A business can close an account, stop all marketing contact and remove most fields immediately, while one narrow financial entry tied to a past transaction is kept separately on its own shorter clock, running down quietly on its own schedule.
A retention schedule, in plain terms.
A well-run organisation should be able to describe, in plain language, roughly how long each type of data it holds is kept and why. This does not require a technical background to ask about, and does not require the business to publish anything beyond a general summary in its privacy notice for most everyday purposes.
A vague answer is not automatically a bad sign either. Smaller organisations sometimes describe retention informally rather than with a numbered policy document, and a plain, honest explanation given directly in response to a question is often more useful than a lengthy formal schedule nobody actually reads in full.
How this applies to a discreet booking.
An agency that only ever needs a name to greet you by and a way of reaching you to arrange time with Nora or an evening filed under brunette has almost nothing that needs a long retention period in the first place. Once an overnight in Oud-Zuid is confirmed and complete, there is little reason for contact details to sit around any longer than needed for a possible future booking down the line.
That is the practical upside of collecting little to begin with, the subject of our guide to data minimisation: a shorter retention question is far easier to answer honestly when there was never much sitting in the file to begin with.
Backups complicate the picture slightly.
Deleting a record from a live system does not always mean it vanishes from every backup on the same day. A responsible organisation still deletes data from backups on a reasonable schedule, but a short lag between the two is normal and not, on its own, a sign that a deletion request was ignored.
What matters more than the exact number of days is whether the organisation can explain its backup cycle in general terms when asked, and whether a deleted record is genuinely excluded from active use during that overlap rather than quietly still being referenced somewhere. A short, clearly bounded lag is a reasonable technical reality; an indefinite one, with no end in sight, is worth questioning directly.
What to do if a retention answer seems vague.
A privacy notice that only says data is kept as long as necessary, without any further detail, is common, but a direct follow up question, asking specifically how long a particular category is kept, is a fair one to send. If the record in question has clearly outlived its purpose already, asking for it to be deleted through the right to erasure is the more direct route to take instead.
Where this connects to a wider request.
Retention periods are one of the specific things a business is expected to disclose in response to a formal data request, alongside what is held and who it has been shared with. Our guide to subject access requests covers how that kind of request tends to be phrased and what a complete answer should include.
The short version to remember.
If a piece of data no longer serves the purpose it was collected for, it should not still be sitting in a system somewhere. Whether the record in question relates to the rates page or something entirely unrelated, asking how long a business intends to keep it is a perfectly ordinary question, one most organisations are used to fielding rather than a strange or confrontational one.