When to delete users profiles? Privacy law compliance?

Hi Vanilla friends!

I seem to have a lot of users that haven't logged in in donkeys years… (and I love cleaning up…)

So, how long do you keep 'inactive' users profiles?

Do you ever delete old user profiles? If yes, after how much inactive time?

Is there anything about this in GDPR? From what I've understood, you can only hold personal data for as long as you need it - do I really 'need' it if they are inactive?

Thanks for your help!



  • LiselotteP
    @Firmy , any insights on this?

  • Shauna
    Great question and topic for discussion!

    Keeping inactive profiles depends on the reason why you are holding it. Do you have a legitimate business purpose to keep them?, is there a transactional component so the "receipt" needs to be retained, if you have a subpoena, you may need to stop your deletion process of inactive members, etc.

    I think this might be a good discussion with your legal team to determine if you have a legal basis to retain such data to determine if it's needed.

    Curious to see what the rest of the community this here!