Why talk about data retention on VAT reports
VAT reports aren’t just numbers: they contain data about customers, sales volumes, channels used, countries served. From a GDPR perspective, they fall under personal data (even when referring to business customers, if traceable to natural persons) and need to be managed with a clear, documented data retention policy.
At the same time, tax and civil law impose long-term retention obligations:
- invoices and accounting records generally must be kept for 10 years;
- VAT ledgers fall under the same long-term logic.
Data retention is therefore a balance between:
- regulatory obligations (data can’t be deleted before these deadlines);
- the GDPR’s minimisation principle (data shouldn’t be kept longer than necessary);
- operational needs (historical analysis, audit trail, internal checks).
Legal basis for retaining tax data
For tax reports, the legal basis for processing isn’t consent, but:
- compliance with legal obligations under civil and tax law;
- possible performance of the contract with the customer;
- legitimate interest in legal defence in case of disputes.
This means that, even if a customer withdraws marketing consent, you can’t delete their data from the tax records, because the retention obligation for accounting purposes prevails.
This distinction needs to come through clearly in your privacy policy and internal procedures.
Retention periods: the 10-year constraint
Under Italian law, tax and civil regulations require invoices and accounting documents to be kept for at least 10 years from the date of the last entry, for tax audit and contractual protection purposes. For derived VAT reports (e.g. exports from VATManager, OSS summaries, per-country reports) the same horizon generally applies, since they’re “derived” from the accounting records.
A typical policy might include:
- 10 years for documents and reports used directly or indirectly for VAT returns, OSS and financial statements;
- shorter periods (e.g. 24–36 months) for log data not needed for tax purposes;
- deletion or anonymisation after expiry, via periodic jobs.
Data retention and OSS/IOSS
With OSS and IOSS, tax documentation also takes on a cross-border dimension. EU VAT rules require anyone using special schemes to keep a record of transactions for at least 10 years, available to the tax administrations of the various member states.
In practice:
- you need to be able to reconstruct sales, rates, countries of consumption and taxes paid over a long time span;
- you need to keep the original marketplace reports (Amazon, eBay, Shopify) and the consolidated reports your returns were based on;
- you need to be able to produce this data to the authorities of any of the countries of consumption in case of an audit.
Minimisation: what you can avoid retaining
The GDPR’s storage limitation principle calls for not keeping data longer than necessary. In the context of tax reports, you can work on two levels:
- minimising identifying data: where possible, use pseudonymised identifiers (customer ID) instead of full names if not relevant for tax purposes;
- separating layers: keep aggregated data by country and rate for the long term, and reduce more quickly the detailed data not needed as tax evidence.
For example, you could keep:
- per-transaction detail reports for 10 years in a secure, low-access-frequency archive;
- detailed application logs (IP, user agent, etc.) for only 12–24 months, if not required for legal purposes.
Security and access controls
A good retention policy also involves controls over who can access the data and under what circumstances. For tax reports:
- limit full access to only the roles that genuinely need it (e.g. management, tax advisors);
- use “read-only” profiles for those who only need to view reports;
- log relevant access and exports (audit log).
Combining retention with access control makes tax report management consistent with the GDPR’s “accountability” principle.
Data retention in VATManager
VATManager is designed to make both tax and privacy compliance easier:
- it allows periodic export of reports in standard formats (CSV, Excel, PDF) that you can feed into compliant archival systems;
- it doesn’t use uploaded data for purposes other than VAT calculation and reporting;
- it allows access to be segmented by role (e.g. operator vs. external consultant);
- it can support anonymisation or pseudonymisation strategies on data no longer needed in clear text.
This way you can keep aligned:
- the ten-year tax retention obligations;
- GDPR principles of minimisation, security and transparency towards data subjects.