Law & jurisdiction

What is Data retention?

Definition

Data retention laws require communications providers to store connection metadata for a defined period so that authorities can obtain it later. The EU's original Data Retention Directive was invalidated by the Court of Justice in 2014, and Romania struck its national law down twice on constitutional grounds.

Why Data retention matters

The EU's original Data Retention Directive was invalidated by the Court of Justice in 2014, and Romania struck its national law down twice on constitutional grounds. Several offshore jurisdictions impose no such obligation at all.

Data retention in practice

When you run a server, data retention is about what you store and how long you keep it. Look at your logs, backups, and connection metadata: what do you actually hold? If you log everything indefinitely, you become a richer target for subpoenas. Change your log rotation to fit your real needs, and keep backups long enough to recover, not longer. Getting it wrong cuts both ways: over-retention invites legal requests; under-retention can lose evidence you need to defend yourself.

What people get wrong about Data retention

People think data retention is a legal rule telling them what to keep, so they store everything out of fear. In most offshore jurisdictions without retention mandates, the risk is keeping data you have no obligation to hold. You want to know exactly what your provider logs — connection logs here are kept for 0 days — and configure your own systems to retain as little as possible.

Data retention — common questions

How long does OnionVPS keep connection logs?

We retain connection logs for 0 days. That means we do not keep metadata about who connects to our services, such as source IPs or timestamps. If you run your own server, check your application logs; they are your responsibility, not ours.

Does data retention affect me if I host in an offshore jurisdiction?

Possibly, but the onus is usually on you, the customer. Several offshore jurisdictions impose no data retention obligation at all, so you control what logs you keep. We recommend storing the minimum needed for operations and security. Your provider's policies matter too — pick one that does not retain connection logs.

More from law & jurisdiction

Warrant canary
A warrant canary is a regularly republished statement that a provider has not received a secret legal demand; its disappearance implies that one has arrived.
KYC
KYC is the set of identity-verification duties imposed on regulated financial institutions before providing services.
No-KYC hosting
No-KYC hosting is server hosting that requires no identity verification — no government ID, billing address, phone number or payment card.
Offshore hosting
Offshore hosting means placing a server in a jurisdiction other than your own, typically one outside the Fourteen Eyes alliances and outside EU data-retention rules.
Five Eyes
The Five Eyes is a signals-intelligence sharing alliance between the United States, United Kingdom, Canada, Australia and New Zealand.
Fourteen Eyes
The Fourteen Eyes is the widest of the signals-intelligence sharing groupings, comprising the Five Eyes plus Denmark, France, the Netherlands, Norway, Belgium, Germany, Italy, Spain and Sweden.
MLAT
An MLAT is a treaty through which one country formally requests another to gather evidence on its behalf.
DMCA
The DMCA is United States copyright statute whose notice-and-takedown procedure and safe harbour apply to service providers situated in the United States.