Data retention is how long you keep data before deleting it, and the rules that decide that period. In marketing it covers both the legal side, where UK GDPR says personal data must not be kept longer than you need it, and the practical setting in Google Analytics 4 that controls how long event-level data stays available for analysis.
How data retention works
Under the storage limitation principle in Article 5 of the UK GDPR, you decide a retention period for each kind of personal data based on why you hold it, write it down, tell people about it in your privacy notice, and then actually delete or anonymise the data when the period ends. The law sets no fixed periods for marketing data; you have to justify your own.
GA4 has its own retention setting under Admin, Data collection and modification, Data retention. At the time of writing (October 2026), a standard property offers two options for event data, 2 months or 14 months, and Analytics 360 allows longer. Three details catch people out:
- A new property starts on 2 months, and many businesses never change it.
- The setting limits explorations and other analysis of event-level data. Standard aggregated reports are not limited by it, so they still show older totals.
- Changing the setting does not bring anything back. Moving from 2 to 14 months keeps data from that point on; anything already past the old limit has gone.
A separate option, “Reset user data on new activity”, restarts a returning user’s retention clock each time they come back.
Why it matters
Two problems meet here. Legally, your GA4 setting and your privacy notice should agree. If the notice says analytics data is kept for 14 months and GA4 is set to 2, or the other way round, the notice is inaccurate, and UK GDPR requires you to tell people truthfully how long you keep their data.
Practically, a 2-month window cripples analysis. You cannot build an exploration comparing this November with last November, follow a funnel across a long B2B sales cycle, or study how a group of customers behaved over a year. For a UK business with strong seasonality, from Christmas retail to January gym memberships to summer holiday bookings, year-on-year comparison at event level needs the 14-month setting at least.
Retention goes beyond analytics. Form entries stored in a WordPress plugin, enquiry emails in a shared inbox, call recordings and CRM records of people who never became customers all need a period and a routine for clearing them.
Common mistakes
- Leaving GA4 on the 2-month default and finding out only when a year-on-year exploration comes back empty.
- Copying a privacy notice that states retention periods nobody has checked against the real settings.
- Assuming that because standard reports show last year, explorations will too.
- Setting a limit in GA4 while storing raw data indefinitely elsewhere, such as in BigQuery, with no deletion rule.
- Keeping every enquiry form entry forever because the website plugin never deletes anything.
How to act on it
Check your GA4 retention setting today. For most businesses 14 months is the sensible choice, because it supports year-on-year analysis and is still a defined, limited period you can state in a privacy notice. If you need a longer history, the BigQuery export keeps raw events in your own Google Cloud project, where you set your own expiry rules. Tables in the free BigQuery sandbox expire automatically after 60 days, so plan for that before relying on it.
Then list the other places marketing data lives and give each one a retention period: CRM, email platform, form plugin, call tracking and customer lists uploaded to ad platforms. Update the privacy notice so every period matches reality, and review it once a year. Getting settings like this right from the first day is part of the measurement setup I do for performance marketing.
