Retention policies for banking data
This page describes how long 365 business Banking keeps bank transactions, EBICS files and SEPA payment imports, and how to set retention periods.
365 business Banking keeps three kinds of data that contain personal or confidential information. This data is not deleted automatically. Without a retention policy, it is kept permanently. You decide how long you must or may keep statements, bank files and payment files. 365 business Banking offers the tables for this in the retention policies of Microsoft Dynamics 365 Business Central.
Standard functionality in Business Central
Retention policies delete a table's records once they are older than a set period, either automatically through the job queue or manually. Only tables that an app releases for this purpose are offered. For more information, see Define retention policies on Microsoft Learn.
What 365 business Banking adds
Three tables are offered. 365 business Banking does not create a policy for any of them.
| Table | Content | Period counted from | Effect of deletion |
|---|---|---|---|
| Bank Transaction Detail | details of every posted bank transaction, including the counterparty's name and IBAN | Bank Posting Date | The Bank Transaction FactBox on bank, customer, vendor, employee and G/L entries stays empty. Only for PSD2/XS2A via finAPI does Business Central fetch the details again, as long as finAPI knows the transaction, see Bank account ledger entries. |
| EBICS Job | every order to the bank with request, response and the file sent by the bank, including your statements | Created At | The job is deleted with its file. A statement from it can no longer be imported with Read Statement Again; you must retrieve the transactions of that period from the bank again. |
| Payment Import Header | imported SEPA payment files with all recipients and amounts, which for payroll files means every salary | Carried Out At | The import is deleted with its lines. The SEPA Payment Proof contains no recipients and remains available as your record. |
EBICS jobs: only without waiting readers
For EBICS Job, 365 business Banking supplies a default: the filter Awaiting Readers = No, with a period of one year. A job whose file a company has not read yet is the only copy of that data, because EBICS delivers every file only once. The filter prevents a policy from deleting such jobs. See Statements via EBICS.
SEPA payment imports: only with payment proof
For Payment Import Header, 365 business Banking supplies a default: the filter Payment Proof Printed At is not empty, with a period of one year. The filter is required because an import without a printed payment proof cannot be deleted. A policy without this filter would stop at such an import instead of skipping it. See Payment proof and retention.
Not stored: the application log
Check Application recalculates the application log each time and stores no data. A policy is therefore not required. See Check application.
Step by step
- Choose the Search icon, enter Retention Policies and open the page.
- Choose New and, in the Table Id field, one of the three tables.
- Choose the Retention Period so that the policy applies to all records, or set periods for filtered records in the lines. For EBICS Job and Payment Import Header, use the supplied default.
- Activate the policy with Enabled. If the policy is to run regularly, check the retention policy job queue entry.
Recommendations
The following values are guidance, not legal advice. Agree the periods with your tax advisor and data protection officer.
| Table | Consideration | Guidance |
|---|---|---|
| Bank Transaction Detail | Posted entries and their amounts remain. Only the counterparty details are deleted. These details are needed for queries about payments. | a period matching your internal audits, for example a few years |
| EBICS Job | The files are statements. As long as they are kept, you can restore missing transactions without involving the bank. If you archive statements elsewhere in an audit-proof way, a shorter period is sufficient. | the supplied default (one year, only without waiting readers), no shorter than the time needed to detect missing transactions |
| Payment Import Header | Salary data should not be kept longer than necessary. The payment proof remains available. | the supplied default: one year after execution, only with printed payment proof |
Check before enabling
An enabled policy deletes everything older than the period on its next run. Before enabling it, use the action for showing the affected records to check which data will be deleted.
