Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
This provision states that X may retain account identifiers, including email address and phone number, indefinitely for users whose accounts are suspended for Rules violations, for the stated purpose of preventing creation of new accounts by repeat policy offenders.
This analysis describes what X's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes indefinite retention of personal identifiers for suspended accounts, which may require evaluation under GDPR's storage limitation principle (Article 5(1)(e)) and similar data minimization obligations in other jurisdictions, as GDPR generally requires that personal data be kept no longer than necessary for the purpose for which it was collected.
⚠ Email address and phone number associated with a suspended account may be retained by X indefinitely as stated in the terms
Cross-platform context
See how other platforms handle Indefinite Retention of Suspended Account Identifiers and similar clauses.
Compare across platforms →Monitoring
X has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Where you violate our Rules and your account is suspended, we may keep the identifiers you used to create the account (such as your email address or phone number) indefinitely to prevent repeat policy offenders from creating new accounts.Excerpt from X's Privacy Policy
(1) REGULATORY LANDSCAPE: This provision directly engages GDPR's storage limitation principle (Article 5(1)(e)), which requires personal data to be kept no longer than necessary for the stated purpose, as enforced by the Irish Data Protection Commission. The right to erasure under GDPR Article 17 may be constrained in practice for suspended account holders, though Article 17(3) permits retention where necessary for legal claims or compliance obligations. CCPA and CPRA deletion rights for California residents may also be affected by this provision. (2) GOVERNANCE EXPOSURE: High. Indefinite retention of personal identifiers is facially in tension with GDPR's storage limitation and data minimization principles. The stated purpose (preventing repeat policy offenders) may constitute a legitimate basis for retention, but the absence of any defined retention period or periodic review mechanism may not satisfy GDPR's proportionality requirements. (3) JURISDICTION FLAGS: EU/EEA users have the strongest grounds to challenge indefinite retention under GDPR's storage limitation and erasure rights. California residents may invoke CCPA/CPRA deletion rights, though exceptions for fraud prevention and security purposes may apply. The Irish Data Protection Commission is the lead supervisory authority for EU/EEA challenges. (4) CONTRACT AND VENDOR IMPLICATIONS: This provision may affect enterprise users whose employee accounts are suspended, as organizational contact information used for account creation could be retained indefinitely. Legal teams should assess whether this retention practice is addressed in any enterprise service agreements with X. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should evaluate whether X has documented a proportionality assessment for indefinite retention of suspended account identifiers under GDPR. Users seeking deletion of suspended account data should submit requests to X Internet Unlimited Company (EU/EEA/UK) or X Corp. (US) at the addresses specified in Section 10 and document the response for any subsequent supervisory authority complaint.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes indefinite retention of personal identifiers for suspended accounts, which may require evaluation under GDPR's storage limitation principle (Article 5(1)(e)) and similar data minimization obligations in other jurisdictions, as GDPR generally requires that personal data be kept no longer than necessary for the purpose for which it was collected.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by X.