Storage limitation is one of GDPR's seven core data processing principles, established in Article 5(1)(e). It requires personal data to be kept no longer than necessary for the purposes it was collected. Organizations must define how long they retain each type of personal data and delete or anonymize it when the retention period expires. For cookie compliance, each cookie's lifespan must reflect only what is genuinely needed — a session cookie persisting for two years likely violates storage limitation. Cookie lifespans must also be disclosed in the cookie policy. This principle is distinct from a data retention policy, which is the document recording these decisions.