Replace GRC spreadsheets
A GRC migration starts with fields, responsibilities and data quality. This sequence moves from the existing workbook through a trial run to business acceptance.
Bank data has no single retention period. A deletion policy connects record type, legal basis, start date and justified exceptions with the data actually held.
A customer file may contain business correspondence, accounting vouchers, identification records and other personal data. Sharing one storage location does not give them the same retention period. Current HGB section 257(4) requires ten years for accounting vouchers of the listed KWG institutions, insurers and investment firms. The general eight-year rule for vouchers therefore cannot simply be applied to banks.
This overview covers central German rules. Also assess the actual document, additional obligations and application or transitional provisions.
| Record | Standard period | Starting point / qualification |
|---|---|---|
| Books, inventories, financial statements and related organisational documents | 10 years under HGB section 257 | End of the calendar year of the event specified by law |
| Accounting vouchers at institutions under HGB section 257(4), second sentence | 10 years | End of the calendar year in which the voucher arose |
| Received and sent business correspondence | 6 years under HGB section 257 | End of the calendar year of receipt or dispatch |
| AML records under GwG section 8(1)–(3) | 5 years unless a longer statutory period applies | Business relationship: year-end of termination; other cases: year-end of determination |
| Other personal data without a statutory retention requirement | No general period | Assess necessity for the purpose and legal basis |
AO section 147 has its own periods and can postpone expiry while records remain relevant to taxes whose assessment period has not expired. GwG section 8 generally requires destruction of its records after no more than ten years. Simply choosing the longest imaginable period does not resolve such conflicts. Assess the particular records, purposes and legally justified holds. Give each hold a reason, owner and review date so it cannot silently become permanent.
The GDPR requires storage limitation. Article 17(3) provides exceptions to erasure, including legal obligations and establishing, exercising or defending legal claims. Continued retention does not authorise unlimited reuse. Limit archive access and permitted purposes accordingly. Formal restriction under Article 18 applies only when its own conditions are satisfied, not automatically whenever a retention obligation exists.
Working example: a letter classified as business correspondence is received on 15 June 2026. Its six-year period begins at the end of 31 December 2026 and expires at the end of 31 December 2032. Deletion from 1 January 2033 may be appropriate if no other applicable obligation or justified hold remains. An accounting voucher from the same bank and year may have a different deletion date because of the ten-year rule.
A practical register includes the data class, authoritative system, copies, purpose, provision, trigger, period and deletion procedure. Include exports, document stores and recovery procedures. For backups, document when data expires and how overdue deletions are reapplied after restoration. A verification record shows scope, exceptions and outcome without unnecessarily storing the deleted content again.
Do not assume so. HGB section 257(4), second sentence, specifies ten years for the institutions it covers. Assess record type, application rules and other obligations.
No. For the business relationship addressed in GwG section 8(4), it starts at the end of the calendar year when the relationship ends. Other cases relate to the year in which the information was determined.
The request must be processed and assessed for the data concerned. Retention duties for particular records do not justify a blanket refusal to erase all other data.
A GRC migration starts with fields, responsibilities and data quality. This sequence moves from the existing workbook through a trial run to business acceptance.
T-NEX advises banks and insurers on software projects and GRC processes, with functional specifications, technical planning and an agreed implementation scope.
Explore serviceBring a concrete task. Together, we will define what the application needs to do.
Discuss your project