Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
This provision states that X may retain the email address, phone number, or other account creation identifiers of users whose accounts are suspended for policy violations for an indefinite period.
This analysis describes what X's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This clause authorizes indefinite retention of personal identifiers following account suspension, which may require evaluation under GDPR's data minimization and storage limitation principles and CCPA's retention disclosure requirements. The provision does not define a maximum retention period or a process for challenging or limiting this retention.
⚠ The terms authorize X to retain the suspended user's email address and phone number indefinitely as described if no challenge or deletion request is submitted
Cross-platform context
See how other platforms handle Data Retention: Suspended Account Identifiers and similar clauses.
Compare across platforms →Monitoring
X has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Where you violate our Rules and your account is suspended, we may keep the identifiers you used to create the account (such as your email address or phone number) indefinitely to prevent repeat policy offenders from creating new accounts.Excerpt from X's Privacy Policy
1) REGULATORY LANDSCAPE: This provision engages GDPR's storage limitation principle, which generally requires that personal data be kept no longer than necessary for the stated purpose. Indefinite retention of personal identifiers may require a documented legitimate interest or legal obligation basis under GDPR. The Irish DPC has authority for EU and EEA users; the FTC and state attorneys general have authority for US users under applicable state privacy statutes. 2) GOVERNANCE EXPOSURE: Medium. Indefinite retention of personal identifiers post-suspension is operationally justifiable as an anti-abuse measure but may face regulatory challenge in GDPR jurisdictions where storage limitation is a core principle. The policy does not describe a proportionality analysis or a review mechanism for assessing whether continued retention remains necessary over time. 3) JURISDICTION FLAGS: EU and EEA users may have a right to request erasure under GDPR Article 17, subject to exceptions for compliance with legal obligations and legitimate interests. X's ability to invoke these exceptions for indefinite identifier retention should be documented. California residents have CCPA rights to request deletion, subject to fraud prevention exceptions that may apply here. 4) CONTRACT AND VENDOR IMPLICATIONS: This provision is unlikely to create direct B2B contract implications but may affect enterprise customers who need to manage data subject deletion requests for employees or users whose X accounts have been suspended. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should assess whether X's retention of indefinite identifiers post-suspension is documented in the company's data retention schedule with a clear legal basis. For EU and EEA deployments, a storage limitation analysis should be conducted, and the policy should disclose whether and how users can request review of their suspended account data.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This clause authorizes indefinite retention of personal identifiers following account suspension, which may require evaluation under GDPR's data minimization and storage limitation principles and CCPA's retention disclosure requirements. The provision does not define a maximum retention period or a process for challenging or limiting this retention.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by X.