Introduction: leaving doesn't mean disappearing
You cancelled your telecom subscription four years ago. Twice a year you still receive a "special former customer" offer addressed to you, at your old postal address, with a file number that is still live. You closed your account with an online shop: three months later, an email informs you that "your basket is waiting for you." You unsubscribed from a newsletter: you receive nothing more from that sender, but your address is now entered on a suppression list — a list that, by design, holds your email address forever.
There isn't necessarily any ill intent in this. A company has accounting and tax obligations, warranty duties, and the need to prove things in the event of a dispute. The law requires it to keep certain records. But between "what the law requires to be kept" and "what actually remains in the databases because nobody ever scheduled the purge," the gap is considerable.

The GDPR sets out two principles that apply in full at the moment of departure: storage limitation (Article 5(1)(e): data is kept only for as long as necessary for the purpose) and the right to erasure (Article 17, popularised as the "right to be forgotten"). France's data protection authority, the CNIL, has published sector-specific reference frameworks — commercial management, debt recovery, telecoms — that set out the permitted periods precisely.
This guide explains what really survives a cancellation, for how long, which categories of data you can demand be deleted immediately, and how to draft a request that doesn't end up as a closed ticket with no reply.
Part 1 — The three lives of a customer file
To understand what happens to you, you need to know the internal vocabulary of customer databases. A file doesn't go straight from "active" to "deleted." It passes through at least three states.
The active database
As long as the relationship exists, everything is there: identity, contact details, order history, exchanges with customer service, partially masked payment methods, log-in data, sometimes call recordings. That's the normal configuration.
Intermediate archiving
This is the state that surprises people most. Once the contract ends, the file isn't destroyed: it is taken out of the active database and placed in a restricted-access area, consulted only for a specific need (dispute, tax audit, complaint). The CNIL explicitly accepts this mechanism. In practice, your data still exists, but nobody should be able to query it for marketing purposes any more.
In reality, the boundary is porous. Many companies keep a reactivatable "customer ID," precisely so they can recognise you if you come back — and so they can send you win-back offers.
Permanent deletion (or anonymisation)
The final state: either the data disappears, or it is anonymised — irreversibly transformed so it can feed statistics without allowing you to be re-identified. Watch the vocabulary: pseudonymisation (replacing your name with a code) is not anonymisation. Pseudonymised data remains personal data within the meaning of the GDPR.
Remember the question that settles everything: "Using the tables that have been kept, can anyone reconstruct who I was?" If yes, it's still my data, and my rights apply.
Part 2 — How long, legally?
Here are the benchmark retention periods most commonly encountered, as derived from French legislation and the CNIL's reference frameworks. They aren't corporate whims: each has a legal basis.
| Data retained | Usual period | Legal basis |
|---|---|---|
| Invoices and accounting records | 10 years | Commercial Code (art. L123-22) |
| Contracts and proof of performance | 5 years after the contract ends | Civil limitation period (art. 2224 Civil Code) |
| Marketing data (former customer) | 3 years after last contact | CNIL commercial management framework |
| Connection / traffic data (operators) | 1 year | Postal and Electronic Communications Code |
| ID document collected for verification | Duration of the check, then deletion | CNIL guidance |
| Bank details (IBAN) | Until the last payment + chargeback windows | CNIL framework |
| Recording of a call to customer service | 6 months maximum as a general rule | CNIL recommendation |
Two practical lessons follow.
First lesson: the famous "10 years" that advisers invoke to refuse everything applies only to accounting documents. It justifies neither keeping your email address on a marketing list, nor retaining the photo of your ID card, nor storing your exchanges with support.
Second lesson: the three-year limit after the last contact for marketing purposes is the most useful one to know. Once that period has passed, a company no longer has any basis for approaching you commercially. A "special former customer offer" four years after cancellation is therefore, in principle, outside the rules.
Part 3 — Cancelling cleanly: a six-step method
A cancellation that works from a privacy standpoint isn't decided at the moment of the final click, but in the weeks around it.
1. Retrieve your data before you leave
Exercise your right of access (Article 15 GDPR) before closing the account, while you still have a working login. You'll get the list of what is held — and therefore the raw material for your future erasure request. After closure, you can still exercise the right, but it becomes far more cumbersome: you often have to prove your identity by post.
2. Neutralise the payment methods
Delete the IBAN and the saved cards yourself before closing. Then, on the bank's side, revoke the SEPA direct debit mandate: cancelling a contract does not automatically revoke the authorisation to debit your account. This is the most common cause of "phantom" debits several months after leaving.
3. Disconnect before deleting third-party logins
If you signed up via a "continue with…" button, the account sometimes survives in an orphaned form. Revoke the authorisation from the identity provider, then delete the account on the service side. In the opposite order, you leave behind a record you can no longer manage.
4. Empty the stored content
Photos, documents, messages, published reviews, wish lists: delete them one by one before closure. Many platforms separate account deletion from the deletion of published content, which stays online under a pseudonym or the label "deleted user."
5. Send a written erasure request
This is the step almost nobody takes, and the only one that leaves a record you can rely on. See the template in Part 5.
6. Check again three months later
Note the date in your diary. If a marketing email arrives, you have dated proof of a breach — and a solid case for a complaint to the CNIL.

To keep this record without relying on memory, a hardcover notebook is enough: one page per service, the cancellation date, the channel used, the date of the planned follow-up. Paper has a real advantage here — it doesn't sync anything to a cloud.
Part 4 — The special case of newsletters
The "unsubscribe" link works, but not in the way you imagine.
When you click, your address isn't erased: it is transferred to a suppression list, a file whose very purpose is to prevent any further mailings. It's one of the rare situations in which keeping your address protects you. Simply deleting the record would create a risk of accidental re-subscription the next time a file is imported.
What is open to challenge, on the other hand:
- Tracking pixels. Most newsletters contain an invisible image that reports the open, the time, the mail client and an approximate location. Turn off automatic loading of remote images in your mail app: it's the single most rewarding setting in this whole article.
- Tracked links. Every link goes through a redirector that logs your click before sending you on to the destination. Nothing obliges you to click: copy the final domain and type it in yourself.
- Resale or "partner" sharing. Check the wording at the point of sign-up. Once the address has gone, it's beyond your reach.
The disposable address technique
The real defence lies upstream. Create aliases: a different address for each service, all forwarded to your main inbox. The immediate benefits:
- You know who leaked your address when spam arrives at one specific alias.
- You shut down an alias without negotiating with anyone — cancellation becomes unilateral.
- You never hand over your main identifier, which is often built on your name.
The same reasoning applies to the phone. Giving a secondary number for deliveries, after-sales service and sign-ups stops your main line from becoming, as has now become the norm, your de facto national ID. Sending an anonymous SMS also settles those situations where you need to write once, without opening a permanent channel to you.
Part 5 — Drafting an erasure request that gets results
Requests are refused almost always for the same reason: they're vague. "Delete everything" runs straight into accounting obligations, and the ticket is closed. A segmented request, by contrast, is very hard to reject.
Template to adapt
Subject: Erasure request — Article 17 GDPR — file no. [reference]
Dear Sir or Madam,
Following the cancellation of my contract on [date], I request the erasure of the following data, the retention of which is no longer necessary for the original purposes:
- my contact details held in your commercial marketing files, as well as any transfer of them to third parties;
- the copies of identity documents and proof of address submitted when I signed up;
- the recordings of my telephone exchanges with your customer service;
- my bank details, the last payment having been made on [date];
- my online account and the content associated with it.
I acknowledge that accounting records are subject to a statutory retention obligation. My request does not cover these.
I also ask you to tell me, in accordance with Article 19 GDPR, the recipients to whom my data has been disclosed.
I would remind you of the one-month deadline provided for in Article 12(3) GDPR.
Send it to the data protection officer (DPO) where there is one — most large companies publish their contact details in their privacy policy — and keep proof of posting. For sensitive cases, a registered letter remains the strongest evidence: a small pack of window envelopes and a decent pad of paper make the exercise less of a chore than it sounds.
If nothing happens
Once a month has passed without a satisfactory reply, you can file a complaint with the CNIL online. The complaint is free, takes fifteen minutes to complete, and asks only for: the identity of the organisation, a copy of your initial request, proof that you sent it, and the absence or inadequacy of a reply. That is precisely why step 5 in Part 3 matters so much.
Part 6 — The blind spots everyone systematically forgets
Even an exemplary cancellation leaves residue somewhere other than at the company concerned.
- Data brokers. Your file may have been enriched and then shared with aggregators. Article 19 GDPR gives you the right to know the recipients: use it, it's the only way to work back up the chain.
- Default registers. In the event of non-payment, you may appear in an internal file, or even in the Banque de France registers (FICP, FCC). These have their own retention periods and their own removal procedure once your situation is regularised.
- Backups. Deletion from a database doesn't wipe the backup sets, which run on cycles of several weeks to several months. That's lawful, provided those backups aren't put back into use.
- Your own device. Saved passwords, downloaded invoices, cookies, apps still installed. Local housekeeping is part of cancelling. For the paper documents that pile up (contracts, statements, cancellation letters), a cross-cut shredder beats a bin bag: invoices carry your name, address, customer reference and sometimes a partial IBAN.
- Returned or resold devices. Internet box, set-top box, smartwatch, speaker: restore factory settings before returning them, and remove the device from your online account. An antistatic storage case for kit being sent back also avoids disputes over the condition of the product.
Conclusion: cancelling is a privacy move
We treat cancellation as an administrative formality — a form to fill in, a monthly saving to bank. In fact it's one of the rare moments when you hold genuine leverage: you no longer need anything from the company, so you have nothing to lose by insisting the law be applied.
Three habits are enough to change the routine:
- Request your data before you leave, never after.
- Write a segmented erasure request, distinguishing legal obligation from commercial convenience.
- Check back three months later, and complain to the CNIL if the commitment isn't honoured.
And upstream, the most effective trade-off remains this one: don't hand over a permanent point of contact when a temporary relationship will do. An alias, a secondary number, a one-off message with no return channel — all ways of making future cancellation far simpler, because there will simply be less to cancel.
Further reading
- CNIL — factsheets on "Retention periods," "Right to erasure" and sector-specific frameworks (cnil.fr)
- Regulation (EU) 2016/679 (GDPR) — Articles 5, 15, 17, 19 and 21
- Loi Informatique et Libertés of 6 January 1978, as amended
- French Commercial Code, Article L123-22 (retention of accounting records)
- Banque de France — FICP and FCC notices, removal procedures



