You have received a withdrawal request, you have handled it, you keep a record of it. Logically: it is that record which protects you in the event of a dispute. But for how long must you keep it? The practical rule: keep the proof for as long as a dispute remains possible, which commonly means several years (around five is a safe default), then purge it. Neither less (you would be defenceless), nor indefinitely (you would breach the GDPR). Here is the reasoning.
In summary
There is no single duration set by a single text. The right duration is deduced from two lines of logic that converge: the limitation period for actions (the period during which someone can still bring a claim against you or demand something from you) and the evidential value of the document (there is no point keeping proof beyond the period in which it could be useful). In practice, a retention period of around five years covers the ordinary limitation period for civil claims in most member states. Beyond that, the GDPR's data minimisation principle requires deletion or anonymisation.
Why around five years?
The ordinary limitation period for civil claims runs for several years in every EU member state (commonly around five). It is the reference duration during which a dispute connected to the order or the withdrawal may still arise. Keeping the proof over this period gives you the means to respond if it is raised against you. Check the exact limitation period that applies in your own country.
What exactly to keep
A "proof of withdrawal" is not a single file, it is a small, coherent file:
- the request itself, timestamped, as it was received;
- the acknowledgement of receipt sent to the consumer on a durable medium;
- the record of the handling (date of the refund, amount, any depreciation applied).
What gives the whole its strength is integrity: being able to demonstrate that the request received on a given date has not been altered since. A timestamp sealed with a fingerprint (hash) serves exactly this purpose, an electronic record whose evidential value is recognised across the EU under the eIDAS Regulation (EU) 910/2014: an electronic document may not be denied legal effect or admissibility as evidence solely because it is in electronic form, and is admissible before the courts of all 27 member states. We detail the mechanics in proof of withdrawal with evidential value, and a third party can check the integrity of a proof via verify a proof of withdrawal.
The tension with the GDPR
A withdrawal request contains personal data (identity, order, sometimes email). The GDPR imposes two principles that frame retention:
- storage limitation: data is kept only for as long as necessary for the purpose;
- minimisation: only what is useful is kept.
These principles do not conflict with keeping the proof: keeping it in order to defend yourself in court is a legitimate and recognised purpose. But they set its limit: once the limitation period has elapsed, the purpose disappears, and the data must be deleted or anonymised. Keeping a withdrawal request for 15 years "just in case" is not compliant. We go deeper into the subject on the form side in GDPR and withdrawal-button data.
Active retention, not a dead archive
Keeping is not enough: you must also be able to retrieve the proof on the day it is asked for, and demonstrate that it has not changed. An export lost in a mailbox or a spreadsheet without a sealed timestamp has weak evidential value. Retention must be organised, dated and intact.
Who can ask you for this proof?
Three concrete cases justify being able to produce the proof at any time during the limitation period:
- The consumer, in the event of a dispute (they contest a refund, or claim to have withdrawn in time).
- The national consumer regulator (in Ireland, the CCPC), during an inspection, to check that you actually handle requests. The sequence is described in how a consumer-regulator inspection unfolds.
- A mediator or a judge, if the dispute is taken further.
In all three cases, it is the same document that speaks: the timestamped request and its acknowledgement of receipt.
What to remember
Keep the complete file of a withdrawal, timestamped request, acknowledgement of receipt, record of the handling, for 5 years, a duration that covers the ordinary limitation period under civil law. Ensure integrity (a sealed timestamp is worth far more than a simple export), and purge beyond it to respect GDPR minimisation. A compliant mechanism manages this retention for you, dated and verifiable, rather than leaving it to a folder of emails.
You do not yet have a mechanism that archives your proofs?
If you receive withdrawals by email, you alone bear the burden of proof and of keeping it. A compliant button archives every request, timestamped and sealed, for the useful duration. Check whether you are concerned: am I concerned?
This article is general information and does not constitute legal advice. For the exact text, refer to the Consumer Rights Directive (2011/83/EU) and the eIDAS Regulation (EU) 910/2014 on EUR-Lex.
Founder of BackToMe
Art. L.221-21 · 19 June 2026
Ready to install the withdrawal feature?
Install the withdrawal button on your site in five minutes. 7-day free trial: 0 € today, 30-day money-back guarantee.
Start the free trial →