import { Callout } from "zudoku/ui/Callout";

# Retention policies for banking data

This page describes how long 365 business Banking keeps bank transactions, EBICS files and SEPA payment imports, and how to set retention periods.

365 business Banking keeps three kinds of data that contain personal or confidential information. This data is not deleted automatically. Without a retention policy, it is kept permanently. You decide how long you must or may keep statements, bank files and payment files. 365 business Banking offers the tables for this in the retention policies of Microsoft Dynamics 365 Business Central.

## Standard functionality in Business Central

**Retention policies** delete a table's records once they are older than a set period, either automatically through the job queue or manually. Only tables that an app releases for this purpose are offered. For more information, see [Define retention policies](https://learn.microsoft.com/en-us/dynamics365/business-central/admin-data-retention-policies) on Microsoft Learn.

## What 365 business Banking adds

Three tables are offered. 365 business Banking does not create a policy for any of them.

| Table | Content | Period counted from | Effect of deletion |
|---|---|---|---|
| **Bank Transaction Detail** | details of every posted bank transaction, including the counterparty's name and IBAN | **Bank Posting Date** | The **Bank Transaction** FactBox on bank, customer, vendor, employee and G/L entries stays empty. Only for PSD2/XS2A via finAPI does Business Central fetch the details again, as long as finAPI knows the transaction, see [Bank account ledger entries](../bank-accounts/bank-ledger-entries.mdx). |
| **EBICS Job** | every order to the bank with request, response and the file sent by the bank, including your statements | **Created At** | The job is deleted with its file. A statement from it can no longer be imported with **Read Statement Again**; you must retrieve the transactions of that period from the bank again. |
| **Payment Import Header** | imported SEPA payment files with all recipients and amounts, which for payroll files means every salary | **Carried Out At** | The import is deleted with its lines. The **SEPA Payment Proof** contains no recipients and remains available as your record. |

### EBICS jobs: only without waiting readers

For **EBICS Job**, 365 business Banking supplies a default: the filter **Awaiting Readers** = *No*, with a period of **one year**. A job whose file a company has not read yet is the only copy of that data, because EBICS delivers every file only once. The filter prevents a policy from deleting such jobs. See [Statements via EBICS](../connections/ebics/statements.mdx).

### SEPA payment imports: only with payment proof

For **Payment Import Header**, 365 business Banking supplies a default: the filter **Payment Proof Printed At** is not empty, with a period of **one year**. The filter is required because an import without a printed payment proof cannot be deleted. A policy without this filter would stop at such an import instead of skipping it. See [Payment proof and retention](../sepa-payment-import/payment-proof.mdx).

### Not stored: the application log

**Check Application** recalculates the **application log** each time and stores no data. A policy is therefore not required. See [Check application](../bank-reconciliation/check-application.mdx).

## Step by step

1. Choose the **Search** icon, enter **Retention Policies** and open the page.
2. Choose **New** and, in the **Table Id** field, one of the three tables.
3. Choose the **Retention Period** so that the policy applies to all records, or set periods for filtered records in the lines. For **EBICS Job** and **Payment Import Header**, use the supplied default.
4. Activate the policy with **Enabled**. If the policy is to run regularly, check the retention policy job queue entry.

## Recommendations

The following values are guidance, not legal advice. Agree the periods with your tax advisor and data protection officer.

| Table | Consideration | Guidance |
|---|---|---|
| **Bank Transaction Detail** | Posted entries and their amounts remain. Only the counterparty details are deleted. These details are needed for queries about payments. | a period matching your internal audits, for example a few years |
| **EBICS Job** | The files are statements. As long as they are kept, you can restore missing transactions without involving the bank. If you archive statements elsewhere in an audit-proof way, a shorter period is sufficient. | the supplied default (one year, only without waiting readers), no shorter than the time needed to detect missing transactions |
| **Payment Import Header** | Salary data should not be kept longer than necessary. The payment proof remains available. | the supplied default: one year after execution, only with printed payment proof |

<Callout type="caution" title="Check before enabling">
An enabled policy deletes everything older than the period on its next run. Before enabling it, use the action for showing the affected records to check which data will be deleted.
</Callout>

## See also

- [Statements via EBICS](../connections/ebics/statements.mdx)
- [Payment proof and retention](../sepa-payment-import/payment-proof.mdx)
- [Security and data protection](../concepts/security.mdx)
