Avv. Alessandro Del Ninno took part as a speaker in the Paradigma workshop series devoted to the drafting of GDPR procedures, contributing in particular to the session held on 10 March 2026 on the data retention procedure. The workshop focused on the rules governing the retention, archiving and deletion of personal data, with a practical approach aimed at translating GDPR principles into organisational, technical and documentary measures that can be effectively implemented within corporate processes.
During his presentation, Avv. Del Ninno first clarified the distinction between retention and deletion of personal data, explaining that these are two separate stages in the lifecycle of data, each with its own purpose, safeguards and operational requirements. On the one hand, retention requires defined criteria, differentiated access rights, enhanced protection, archiving rules and lifecycle management; on the other hand, deletion requires effective and demonstrable measures ensuring that, once the retention period has expired or the legal basis has ceased to exist, the data subject can no longer be identified or re-identified.
He then examined the main GDPR provisions relevant to this area, with particular attention to the storage limitation principle, transparency duties in privacy notices, the right to erasure, the relationship with records of processing activities, and the need to regulate correctly—also in contracts with processors—the return or deletion of data at the end of the service. He also stressed that data retention cannot be defined in an abstract or uniform way, but must be determined case by case, depending on the purposes of processing, the legal basis, applicable statutory obligations, limitation periods and defence or accountability needs.
A key part of the presentation was devoted to the practical structure of a corporate data retention procedure. Avv. Del Ninno explained the importance of setting up a retention schedule linked to actual processing activities, IT applications, archives and third-party providers hosting or managing the data. In this perspective, the procedure was presented as a governance tool that must not only be compliant, but also executable and auditable, through verifiable evidence such as deletion logs, operational tickets, supplier attestations, versioned rules and periodic compliance checks.
Finally, the session also addressed the most sensitive practical issues, including the distinction between archiving and backup, the handling of residual copies, deletion in satellite systems, irreversible anonymisation as an alternative to destruction, and the allocation of internal responsibilities for implementing the procedure, from the controller to business functions, IT, security and external processors. Through this session, Avv. Alessandro Del Ninno provided participants with a concrete methodology for structuring an effective data retention policy capable of managing privacy risk throughout the entire lifecycle of personal data.