Contract trap · Privacy policy
Indefinite data retention
Retention is defined only as 'as long as necessary', 'for as long as your account exists and thereafter' or 'indefinitely'; deleted data 'may remain in backups'; consent is 'бессрочно'; and personal data (including genetic, health or financial data) is listed as a transferable asset in a merger, acquisition, reorganization, bankruptcy or sale of assets to a successor who may not be bound by the current policy.
- Severity
- Serious
- How often it turns up
- Almost always
- Holds up?
- Often void
- Clause phrases
- 22
What it looks like in a contract
Redline matches these phrases against your document verbatim. Drafters rarely invent new wording — they copy it, which is why the same sentences turn up across unrelated contracts.
In English-language contracts
- for as long as necessary
- as long as your account is active and thereafter as needed
- we may retain your information indefinitely
- residual copies may remain in our backup systems
- deleted content may persist
- retain for as long as we deem appropriate
- in the event of a merger, acquisition, reorganization, bankruptcy or sale of all or a portion of our assets
- your personal information may be among the assets transferred
- successor or acquirer
- subject to the acquirer's privacy policy
In Russian-language contracts
- бессрочно
- согласие действует бессрочно
- до достижения целей обработки
- в течение неограниченного срока
- Оператор вправе хранить данные после удаления аккаунта
- в архивных и резервных копиях
- в течение срока, определяемого Оператором
- в случае реорганизации, продажи бизнеса или его части
- правопреемнику Оператора
- персональные данные могут быть переданы приобретателю
- в случае банкротства
- база данных может быть отчуждена
Check your own contract
Paste a clause, a page or the whole document. Nothing leaves your browser: the matching runs here, on this page, against the phrases above.
Why it bites
Data you gave for one transaction sits forever waiting for the breach, the subpoena, the acquisition or the AI-training pivot (children's voice recordings and browsing histories were kept for years under such language); your data is sold to a stranger exactly when the company has stopped caring about reputation (Toysmart, RadioShack, 23andMe).
Is it enforceable where you are
The same clause can be routine in one country and void in another. What follows is what the law says where you are — not advice on your particular contract.
In the EU and the UK, the GDPR governs the legal basis, the retention period and your right to erasure; in the US, state privacy laws (CCPA/CPRA and its successors) give an opt-out of sale and sharing.
United States
Generally enforceable; COPPA requires retention only 'as long as reasonably necessary' (Amazon Alexa $25M) and the 2025 rule mandates a written retention policy; FTC orders increasingly require retention schedules (Avast, 1Health 180-day destruction); FTC (Toysmart 2000, RadioShack 2015) demands that data not be sold standalone, the buyer be in the same line of business and bound by the old policy, and material changes require opt-in; Bankruptcy Code §363(b)(1)(A) consumer privacy ombudsman.
- Cited
- COPPA
- FTC
European Union
GDPR Art 5(1)(e) storage limitation and Art 13(2)(a): period or criteria must be stated — 'as long as necessary' alone is insufficient per DPAs; Art 17 erasure; transfer to a successor needs a lawful basis and Art 13/14 information, purpose limitation binds the acquirer and DPAs can block transfers of special-category data.
- Cited
- GDPR Art 5(1)
United Kingdom
UK GDPR same; ICO treats indefinite retention as a standalone Art 5 breach; ICO guidance on data in M&A; CMA37 on assignment clauses.
- Cited
- CMA37
- GDPR
- ICO
Russia
Ст. 5 ч. 7 152-ФЗ: хранение не дольше, чем требуют цели; ст. 21 ч. 4-5: уничтожение в течение 30 дней после достижения цели/отзыва согласия; РКН: согласие может быть бессрочным, но отзыв прекращает обработку; правопреемство не отменяет требования согласия и целей (ст. 5, 6, 9), новый оператор уведомляет РКН (ст. 22) и соблюдает локализацию; субъект вправе отозвать согласие и требовать уничтожения (ст. 21).
- Cited
- 152-ФЗ
- ст. 21 ч. 4
- ст. 22
- ст. 5
Where this has actually happened
Regulator actions, court rulings and the contracts they were fought over.
- FTC/DOJ v. Amazon (May 2023) — Alexa kept children's voice recordings and geolocation indefinitely by default
- FTC v. Avast (2024) — browsing data 'stored indefinitely' before sale; FTC v. 1Health.io (2023) — DNA samples retained beyond promised deletion, order requires destruction after 180 days
- FTC v. Toysmart (2000) — sale of customer list in bankruptcy blocked despite 'never shared' promise; RadioShack bankruptcy (2015) — sale of 117M customer records limited to a same-line buyer bound by the old policy
- 23andMe Chapter 11 (Mar 2025) — California AG alert urging deletion; acquired by TTAM Research Institute (July 2025) with privacy commitments
- FTC COPPA Rule amendments (Jan 2025) — written data retention policy, no indefinite retention
What to do
In order, from the thing that takes a minute to the thing that takes a letter.
- Ask for the retention schedule in writing (GDPR Art 13(2)(a)/15
- 152-ФЗ ст. 14 within 10 рабочих дней)
- Request deletion and withdraw consent — RU operator must destroy within 30 days (ст. 21 ч. 5)
- Check whether the transfer clause binds the successor and promises notice/choice
- For genetic/health services delete your data at the first sign of financial distress (AGs advised 23andMe users to in 2025)
- EU/UK: object and request erasure before a transfer closes
- RU: the new operator needs its own basis — demand deletion under ст. 21.
Traps that travel with it
Drafters who use one of these usually use several.