Security incident on a Monday. You search IPs in host logs: 7-day retention, automatic purge. Meanwhile CNIL questions logs kept 5 years "for analysis" without legal basis. Two extremes, two non-compliances.
Logs are personal data once they contain IP, user-agent, identifiers. Retention must be limited (Art. 5) and justified by purpose — security, short debug, rare legal obligation.
Typology and indicative durations
| Log type | Purpose | Common duration | Note |
|---|---|---|---|
| Web access (IP) | Security, abuse | 6–12 months | Document in register |
| Admin auth | Security, audit | 12–24 months | Restricted access |
| App debug | Debug | 7–30 days | Disable prod |
| CDN edge | Perf + security | Per CDN — read DPA | Often US |
| Backup logs | Recovery | Aligned backup | Encrypted |
Durations = starting point — your impact assessment sets proportionate.
Host vs application
Host: infrastructure logs (Apache, firewall, hypervisor) — contractual policy, sometimes non-modifiable.
You: application logs, business audit — internal policy, rotation, IP anonymisation.
Align DPA: durations, access, deletion at contract end. Cross-read host register.
Legal hold without drift
At incident: export or snapshot concerned logs to isolated forensic storage, documented incident retention — without indefinitely extending production.
The climax: retention is balance, not max or min
Decide and move forward without blind spots
Inventory all log sources (host, CDN, application). Assign purpose and duration per type in processing register. Automate purge and test forensic restore. Align host DPA with host register and see our compliance guides.
Frequently asked questions
How long to keep web IP logs?
No single CNIL duration — often 6–12 months for security if documented justification; less if limited purpose. Beyond: anonymisation or deletion.
Security logs vs application logs?
Security/access logs: security purpose, proportionate duration. Business logs (user behaviour): strict legal basis and minimization — not "security" by default.
Does the host impose retention?
Often yes on infrastructure (access logs). You set app policy + DPA contract; negotiate durations and export for long audits.
How to reconcile incident investigation?
Minimal operational retention + isolated forensic snapshot at incident + legal hold procedure without systemic extension.
Logs protect what they keep long enough — and respect what they erase soon enough.
