GitHub keeps your personal data for as long as it needs it for business, legal, or operational purposes, without specifying a fixed maximum retention period.
This new provision establishes a general indefinite retention standard with multiple qualifying factors, replacing the previous vague reference to data retention.
View full change record →GitHub does not commit to specific maximum retention periods for your personal data, meaning your account information, repository activity, and communications could be retained indefinitely as long as GitHub identifies a business or legal purpose.
Cross-platform context
See how other platforms handle Data Retention and similar clauses.
Compare across platforms →The absence of specific retention periods for different data categories means GitHub could retain your data for many years, increasing your exposure to data breaches and unauthorized use over time.
REGULATORY FRAMEWORK: GDPR Art. 5(1)(e) (storage limitation principle — personal data must not be kept longer than necessary); GDPR Art. 13(2)(a) requires disclosure of retention periods or criteria used; CCPA/CPRA does not specify maximum retention periods but requires disclosure of retention practices; UK GDPR mirrors GDPR storage limitation requirements.
Compliance intelligence locked
Regulatory citations, enforcement risk, and due diligence action items.
Watcher: regulatory citations. Professional: full compliance memo.