MiFID II: the seven questions an auditor asks first
Before asking for recordings, the regulator tests whether you can find them, evidence them and retain them. A guide to the questions that decide…
Read article →GDPR
MiFID II asks for five years. The GDPR asks for the opposite. Retaining and erasing at the same time, by channel and by jurisdiction.

Two obligations, pulling in opposite directions, over the same file. MiFID II requires a relevant recording to be kept for five years. The GDPR requires that personal data not be kept beyond what is necessary, and gives the data subject a right to erasure. At first sight this is an unresolvable contradiction: how do you retain and forget at the same time? The paradox only dissolves once you see that the answer is not a single rule but a granular policy, different by channel, by jurisdiction and by type of interaction.
MiFID II and Delegated Regulation (EU) 2017/565 require records of transaction-related communications to be kept for a minimum of five years, extendable to seven at the request of the competent authority. The logic is evidential: the record has to exist in case an order or a decision needs to be reconstructed. DORA reinforces the need to keep records so that incidents can be reconstructed.
The GDPR starts from the opposite principle. Article 5 sets out storage limitation: personal data should only be kept for as long as the purpose that justified its collection requires. Article 17 adds the right to erasure. The purpose of «complying with a legal retention obligation» is legitimate and prevails while the obligation lasts, but when the obligation ends, the basis for retaining disappears with it.
The temptation to settle the conflict with one rule, «we keep everything for five years», fails in both directions. It retains data the GDPR no longer allows you to keep and, at the same time, it may not cover interactions carrying longer obligations. Real compliance means distinguishing, at the moment of capture, the regime that applies to each interaction. There is no correct period; there is the correct period for each case.
There is no «correct» retention period. There is the correct period for each interaction, and the maturity of an archive is measured by its ability to apply many different periods with no manual intervention.
The technical answer to a legal problem of this kind is a configurable retention policy, defined once and applied automatically to each recording according to its attributes. At the moment of capture, the interaction inherits the regime that belongs to it, by channel, by jurisdiction, by type, and the system takes care of keeping it for exactly as long as it is due. When the period expires, erasure happens by rule, not by individual decision. That removes human error on both sides: nothing that must be kept is erased too early, and nothing is held beyond what the GDPR allows.
There is a symmetry many organisations overlook: proving that you erased matters as much as proving that you retained. When a data subject exercises the right to be forgotten, or when a retention period ends, carrying out the erasure has to leave a record, of what, when, under which policy and on what basis. Without that trace, the organisation cannot demonstrate to a data protection authority that it honoured the request, nor distinguish a lawful erasure from the improper destruction of evidence. Documented erasure is the exact mirror of the access audit trail: it evidences an absence instead of a presence.
The paradox dissolves once you stop seeing it as a choice between retaining and forgetting, and start treating it as both capabilities coexisting in the same archive. Retain for as long as MiFID II and DORA require; forget at the moment and to the extent the GDPR compels; and, in both cases, execute by policy and document the outcome. It is not a fragile balance between two laws in conflict, it is the correct application of each one to the case that belongs to it. An archive that can do both at once no longer has a paradox to solve.
Published by the uPlayback team, a Grupês product. Three decades of experience in compliance recording.
Continue reading
MiFID II Before asking for recordings, the regulator tests whether you can find them, evidence them and retain them. A guide to the questions that decide…
Read article →
Sovereignty Where your recordings live has stopped being a technical decision. It is a decision about legal exposure, and it belongs to the board.
Read article →
DORA Since January 2025, operational resilience is a regulatory outcome, not a document. What that demands of every capture pipeline.
Read article →Compliance, integrations and deployment answered live, with your questions on the table and no generic pitch.