The General Data Protection Regulation (GDPR) is looming large on the horizon now, with 25 May edging ever closer. One of the more keenly debated aspects of the regulation is what firms should do with the data that they hold on individuals. Doing nothing is not an option and processes and procedures for data handling, at a minimum, require reviewing. Beyond that, how should data be handled and processed, and when should it be retained or deleted?