Data may be kept in identifiable form for no longer than the purpose needs, and the end of the contract is usually the end of the purpose.
Why it matters when the plan changes
Retention is the obligation most often missed, because deletion is work nobody is scheduled to do, while keeping data requires no action from anyone. Article 5 of the General Data Protection Regulation ties retention to purpose, so identifiable data may be kept only as long as that purpose exists. Assessment data kept after the contract that justified it is data held without a purpose, a breach of that principle and a liability sitting on a server the controller has stopped thinking about.
The tension is with learning. A supplier that improves its method from outcomes wants to keep something after the contract ends. Article 28 requires a processor to delete or return personal data and existing copies at the controller's choice, so continued use needs a separate purpose and basis, usually agreed at the start as aggregation or anonymisation. Silently keeping identifiable data because it might be useful is the version of this that ends badly.
In practice
An contract ends and nobody triggers deletion. Three years later a former employee of the client makes an access request and the supplier discovers it still holds their assessment results with no basis and no controller instruction to keep them. The response is a deletion and a disclosure that should have happened at termination, recorded now against a breach rather than a routine.
Evidence
Personal data may be kept in identifiable form for no longer than is necessary for the purposes it is processed for.
Article 5, General Data Protection Regulation (2016)At the end of the service the processor must, at the controller's choice, delete or return the personal data and delete existing copies.
Article 28, General Data Protection Regulation (2016)
What it cannot tell you
Retention at contract end tells you that identifiable data must be returned or deleted once the purpose ends, not how long that purpose itself should last or what counts as a legal obligation that overrides deletion. It is silent on whether aggregated or anonymised versions of the same data may continue, which needs its own basis.
Questions
The controller decides. Article 28 of the General Data Protection Regulation (2016) requires the processor to delete or return personal data and existing copies at the controller's choice once the service ends, unless law requires retention. That instruction should be written into the agreement rather than negotiated at termination, when the relationship may be ending badly.
Only with a separate basis and purpose agreed at the start, and usually only in aggregated or anonymised form. Article 5 of the General Data Protection Regulation (2016) limits identifiable retention to the original purpose, so keeping assessment results because they might improve a method is a new purpose without a basis.
They are copies and fall under the deletion duty. Most agreements allow a defined period for backup rotation to complete, with the data inaccessible in the meantime. That period and that inaccessibility should be stated, because an indefinite backup is retention by another name.
Longer than the purpose requires. A reforecast may need the previous baseline, so keeping it while the contract is live is justified. Keeping every intermediate output indefinitely is not. Retention periods should be stated per data type rather than as one figure for everything.
Confirmation of what was deleted and when, what was returned, and what if anything is retained under a legal obligation, with the obligation named. A closing statement of that kind is what turns an assumption into a record the controller can produce if asked.