Medium · Medium Privacy Policy · View original document ↗

Data Retention Without Fixed Periods

Medium severity Medium confidence Explicitdocumentlanguage Rare · 2 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Medium recorded 3 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for Medium Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Medium keeps your personal data for as long as it considers necessary to run its services, without committing to specific deletion timelines in most cases.

This analysis describes what Medium's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Without fixed retention periods, your data could be held for an extended time after you stop using Medium, and you may need to actively request deletion to ensure your information is removed.

Interpretive note: The absence of specific retention periods creates ambiguity about how long different categories of data are held, and GDPR compliance of this provision depends on whether Medium's internal retention schedules satisfy the storage limitation principle.

Consumer impact (what this means for users)

Medium does not commit to specific timeframes for deleting most categories of your personal data, meaning your account information, reading history, and other data may be retained indefinitely unless you actively request deletion.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Email privacy@medium.com to request deletion of your personal data. Specify your account details and the categories of data you want deleted. Note that some data may be retained where legally required.

How other platforms handle this

Disney+ Medium

We retain personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by applicable law. The criteria used to determine our retention periods include the length of time we have an ongoing relationsh...

Smartsheet Medium

We retain personal data for as long as necessary to fulfill the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements, to resolve disputes, and to enforce our agreements. The criteria used to determine our retention periods include: the length of ...

Windsurf Medium

Slack (Sees no code data): We use Slack for internal communications. We may discuss logs of data for debugging purposes from users that are not using Zero-data retention mode. Google Workspace (Sees no code data): We use Google Workspace for collaboration. We may discuss logs of data for debugging p...

See all platforms with this clause type →

Monitoring

Medium has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We retain personal information for as long as necessary to provide you with our services and for the other purposes set out in this Privacy Policy. In some cases, we may retain personal information for longer periods as required by law or for legitimate business purposes.

— Excerpt from Medium's Medium Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: This provision engages GDPR Article 5(1)(e), which requires that personal data be kept in a form that permits identification of data subjects for no longer than necessary for the purposes for which it is processed (storage limitation principle). The absence of specific retention periods in the policy may be insufficient to demonstrate compliance with this principle. EU data protection authorities have flagged vague retention language as a compliance concern in enforcement actions against other platforms. GOVERNANCE EXPOSURE: Medium to High for GDPR-covered users. The policy's open-ended retention language (as long as necessary) does not give users or regulators a clear basis for assessing compliance with the storage limitation principle. For CCPA purposes, retention of data beyond what is necessary for the stated purpose may also create exposure. JURISDICTION FLAGS: EU/EEA users face the highest exposure given GDPR's storage limitation requirements. UK GDPR imposes similar obligations. California's CPRA introduced a requirement that businesses retain personal information only as long as reasonably necessary, which this policy's language may not satisfy with sufficient specificity. CONTRACT AND VENDOR IMPLICATIONS: Organizations using Medium as a vendor should request a data retention schedule and confirm that data subject deletion requests result in actual deletion from backup systems within a documented timeframe. Vendor assessments should include questions about retention policy implementation. COMPLIANCE CONSIDERATIONS: Legal teams should request Medium's internal data retention schedules and compare them against policy representations. Data mapping should identify which categories of personal data are subject to which retention triggers. Users wishing to limit data retention should submit a deletion request via privacy@medium.com, though the policy does not guarantee immediate deletion in all cases.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has authority over data retention practices that are inconsistent with a company's stated privacy commitments or that constitute unfair data handling practices.
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
UK GDPR
United Kingdom

Provision details

Document information
Document
Medium Privacy Policy
Entity
Medium
Document last updated
May 5, 2026
Tracking information
First tracked
May 10, 2026
Last verified
May 10, 2026
Record ID
CA-P-009555
Document ID
CA-D-00246
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
e35f84d3838ccfa621e04fd336ef96e0cfa20727ba6681f8e3e85c0d285d0b9e
Analysis generated
May 10, 2026 19:54 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Medium
Document: Medium Privacy Policy
Record ID: CA-P-009555
Captured: 2026-05-10 19:54:51 UTC
SHA-256: e35f84d3838ccfa6…
URL: https://conductatlas.com/platform/medium/medium-privacy-policy/data-retention-without-fixed-periods/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Medium's Data Retention Without Fixed Periods clause do?

Without fixed retention periods, your data could be held for an extended time after you stop using Medium, and you may need to actively request deletion to ensure your information is removed.

How does this clause affect you?

Medium does not commit to specific timeframes for deleting most categories of your personal data, meaning your account information, reading history, and other data may be retained indefinitely unless you actively request deletion.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 2 platforms. See the full comparison.

Is ConductAtlas affiliated with Medium?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Medium.