Questionnaire answers · Privacy and data · Article 19(1) · Article 18(1)

How to answer data retention and deletion questions in a supplier questionnaire

The short answer

Say how long each kind of data is kept and when it is deleted, and show the setting or the policy that does it. The GDPR keeps personal data no longer than its purpose needs (GDPR Article 5(1), point (e)). For a high-risk AI system the AI Act sets periods of its own for logs and documentation (Articles 18, 19 and 26(6)). Complipath (complipath.io) keeps the record these answers rest on.

What they usually ask

  1. Q1“How long do you keep our data?”
  2. Q2“How long do you keep the AI system's logs?”
  3. Q3“Can we have our data deleted?”
  4. Q4“What happens to our data when the contract ends?”

An example answer, part by part

An illustration for an invented product, not a real supplier's answer, to the question: What happens to our data when the contract ends?

Direct answerYes, partly or no first
We delete it, or return it first if you ask, after the contract ends.
ControlWhat you actually do
Deletion runs from the account owner's request in the admin settings, and the confirmation email names what was deleted.
ScopeWhich AI systems
Your workspace data and the AI feature's logs. Invoices we must keep by law are kept.
EvidenceWhat you can show
The deletion clause in the data processing agreement and one deletion confirmation, dated 3 September 2026.
ExceptionsBe honest
Backups expire on their own schedule, which the security documentation states.

Example. Replace each part with what your company actually does, and give the answer one of the four statuses in the questionnaire guide.

What counts as proof

  • The retention schedule: each kind of data, how long it is kept and why.
  • For a high-risk system, the setting or the procedure that keeps the logs for the period Articles 19(1) and 26(6) require.
  • The deletion or return clause in your data processing agreement (GDPR Article 28(3), point (g)).

Common mistakes

  • Answering for the company. Article 6 classifies systems, not companies.
  • "Yes" with no evidence. If you cannot attach it, the status is Partially implemented or Planned.
  • A policy title as the control. It says nothing about what happens to an output.
  • Mixing up the roles. Article 50(1) is a provider duty; Article 26 is the deployer's. Which one you are is set per system: see provider or deployer.
  • Not applicable with no reason. The reason is the classification.
  • Dropping the exception. The summary that leaves out "unless" is the one that is wrong.

What the law says

  • GDPR Article 5(1), point (e): personal data are kept in a form which permits identification of data subjects for no longer than is necessary for the purposes; longer storage is allowed solely for archiving in the public interest, scientific or historical research or statistical purposes under Article 89(1), with the safeguards the GDPR requires ('storage limitation').
  • Under Article 5(2) the controller is responsible for, and must be able to demonstrate, compliance.

GDPR Article 28(3), point (g): at the choice of the controller, the processor deletes or returns all personal data after the end of the services and deletes existing copies, unless Union or Member State law requires storage.

Article 19(1) for providers and Article 26(6) for deployers of high-risk systems: the automatically generated logs under their control are kept for a period appropriate to the intended purpose, of at least six months, unless Union or national law provides otherwise, in particular on the protection of personal data.

Article 18(1)
  • for 10 years after the high-risk system is placed on the market or put into service, the provider keeps the technical documentation, the quality management system documentation and the EU declaration of conformity at the authorities' disposal.
  • Where applicable, the same holds for the changes approved by notified bodies and for their decisions and other documents.
Read Article 18 on EUR-Lex ↗
  • Articles 18, 19 and 26 are in Chapter III, Sections 2 and 3, which apply from 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III and from 2 August 2028 under Article 6(1) and Annex I (Article 113, third paragraph, point (c), as replaced by Regulation (EU) 2026/1744).
  • The GDPR articles were read from its Official Journal text (OJ L 119, 4.5.2016) on 9 October 2026.

What Complipath does

  • Evidence management A file linked to the requirements it proves, with the passage and its page
  • Audit log Who did what, and when. No one can edit or delete a line, an owner included; only deleting the whole workspace removes it
  • Export (PDF, JSON, spreadsheet) The whole register as a spreadsheet, as JSON or as a PDF, with the exact law texts it was assessed against
  • Obligations per system Confirming a classification creates the obligations that follow from it, each with an owner, a status and a place for evidence

Rules decide. AI only drafts. A person confirms.

What it does not do yet

  • Customer questionnaires (audit room) Coming soon Coming soon: answering a customer's AI questionnaire from your own register.
  • Post-market monitoring (Article 72) Not supported We found no support for this in what we have built. MVP searched 245 shipped source files, 44 migrations, 14 obligation templates, 15 export columns and 12 Annex IV limbs, on the article number and on the provision's own words: nothing on any of the five.

Questions

Do the AI Act's log periods override the GDPR?

No. Articles 19(1) and 26(6) set a period appropriate to the intended purpose, of at least six months, unless Union or national law provides otherwise, in particular on the protection of personal data. Where data protection law provides otherwise, the questionnaire answer names that law and the period it sets.

Who keeps the technical documentation, and for how long?

The provider of the high-risk system, at the disposal of the national competent authorities, for 10 years after the system is placed on the market or put into service (Article 18(1)). A deployer keeps the logs under its control under Article 26(6) instead; the documentation duty under Article 18(1) is the provider's.

Read next
Answer your next questionnaire with proof.No account needed. Every answer cites the article it rests on.