Home / Blog

Why deleting tax records after 7 years can still be risky

July 21, 2025 · Personal data

Why deleting tax records after 7 years can still be risky

Many organisations assume they can safely delete tax records, including personal data, after seven years. Legally speaking, that is often correct. But in practice it is more nuanced.

There is a structural gap between what the law prescribes and how the Dutch Tax Administration (Belastingdienst) handles retention periods. Because of filing extensions or late audits, the actual retention obligation can shift without you noticing.

And that means: if you delete too early, you cannot defend yourself during an audit, even if you formally followed the rules.

📅 What the law says: a 7-year retention obligation

Under Dutch tax law (the Algemene wet inzake rijksbelastingen), businesses must keep their records for at least 7 years. Think of:

  • Sales and purchase records
  • Tax returns and assessments
  • Invoices and bank statements
  • Payroll records
  • Personal data in these documents

🕒 The 7 years start after the end of the financial year to which the records relate.
For financial year 2016, the period starts on 1 January 2017 and ends on 1 January 2024.

⚠️ What happens in practice: the period shifts

Although the law is clear, retention periods often shift in practice without anyone noticing. For example:

  • Filing extensions: if you file your 2016 return only in 2018, an audit can take place until 2025.
  • Standard filing dates: these often fall long after the end of the financial year.
  • Additional assessment periods: these only start running after filing, not after the year itself.

So it can happen that the Tax Administration is still auditing while you have already deleted your records.

🚨 Consequence: the burden of proof is reversed

If you no longer have your records during an audit:

  • You cannot substantiate your tax return
  • The inspector may make an estimate
  • You have to prove that estimate is wrong — without evidence

Even if you formally followed the rules, you can still run into trouble.

👁️ And what does this mean for personal data?

Personal data in your records also falls under this tax retention obligation. Think of:

  • Names and addresses on invoices
  • Citizen service numbers (BSN) in payroll records
  • Customer data in your accounting system

Under the GDPR, you must delete personal data as soon as you no longer need it.
But: tax legislation takes precedence. The tax retention obligation is a valid basis for keeping personal data longer than the GDPR would normally allow.

So: never delete personal data from your records too early.

🧾 Practical examples

SituationStatutory periodActual periodRisk if deleted too early
Financial year 2016, filed on time1 Jan 20241 Jan 2024Low
2016 with extension, filed in 20181 Jan 20241 Jan 2025High
2016 filed in April 20181 Jan 2024May 2024Medium
Foreign assets (12 years)1 Jan 20291 Jan 2029Very high

✅ What can you do?

  • Record retention periods per type of data and per purpose
  • Base your periods on the filing date, not just on the year
  • Avoid automatic deletion after 7 years without a check
  • Make sure your privacy policy and tax policy are properly aligned

📌 RealCob helps you manage retention periods smartly and responsibly

RealCob makes it easy to determine per data category what has to be kept, why, and for how long. With automatic alerts, clear records and concrete GDPR tasks, you prevent data from being deleted too early, or kept for longer than necessary.

👉Try RealCob free for 30 days

👉Book a quick demo

← All articles

From reading to fixing.

RealCob checks every GDPR and NIS2 obligation and makes it demonstrable. Try it free for 30 days or book a 20-minute demo.

No credit card required · Prefer to see where you stand first? Take the free GDPR check

Try free for 30 days