risk-nexus/docs/regulatory/policies/RISK-POL-0009-commercial-and-tax-retention.md

83 lines
3.8 KiB
Markdown
Raw Normal View History

---
id: RISK-POL-0009
type: legal-policy
title: "Commercial and tax retention"
regime: "HGB §257, AO §147"
status: active
activates_when: "the estate keeps commercial books or issues and receives invoices — already true"
owner: risk-nexus
written: "2026-08-20"
cadence: 1h
clean_streak: 1
last_checked: "2026-09-22T06:26:01Z"
next_check: "2026-09-22T07:26:01Z"
checked_by: "worsch"
---
# RISK-POL-0009 — commercial and tax retention
**Active now.** This is the one policy in the set that does not wait for a
context: the estate already invoices, holds bank records and keeps books.
## What the sources require
| Class | Period | Source |
| --- | --- | --- |
| Books, inventories, opening balance sheets, annual accounts, management reports | 10 years | §257(1) no. 1, (4) HGB; §147(1) no. 1, (3) AO |
| Accounting vouchers (*Buchungsbelege*) | **8 years** | §147(3) AO, shortened from ten by the Fourth Bureaucracy Relief Act with effect from 2025 |
| Commercial and business letters received and sent | 6 years | §257(2), (4) HGB; §147(1) nos. 2–3 AO |
Periods run from the **end of the calendar year** in which the last entry was
made or the document created — not from the document's own date. That detail
is the one most often got wrong, and it always extends the period rather than
shortening it.
**The eight-year figure was confirmed on 2026-09-22** (see `RISK-REG-0001`). It
comes from BEG IV, promulgated 2024-10-29, and has applied since 2025-01-01,
including to vouchers whose period had not run out by then. This rests on
secondary sources and the published §147 AO text, not on a qualified review.
Books and annual accounts stay at ten years.
## What it requires of systems
- Records in these classes must be **retrievable for the whole period**, not
merely undeleted. A backup nobody can restore from does not satisfy a
retention duty — the same standard `RISK-F-0006` applies to `apps-pg`.
- Immutability of content: they must not be silently rewritable.
- Deletion must be **possible and deliberate** at the end of the period.
Retention duty is a floor, not a licence; `RISK-POL-0002` supplies the
ceiling.
## Where it collides
With erasure (`RISK-POL-0002`, `RISK-F-0008`). An erasure request touching a
record inside a statutory retention period does not defeat the duty — Art
17(3)(b) GDPR covers exactly this. But **the exemption is per record, not per
system**: it covers the invoice, not the entire event log the invoice passed
through.
That distinction is where "we keep audit because it is audit" fails, and it is
why `RISK-REG-0001` states periods per category rather than one figure.
## Evidence that would show this is met
A retention schedule per record class; a demonstrated restore from the oldest
retained period; a deletion routine that actually runs at expiry.
None of those exist yet. This policy is `active` in the sense that the duty
applies, not in the sense that it is demonstrably satisfied — and the register
says which.
**2026-09-22 review.** Some new evidence exists but it does not satisfy the
duty. Restores are now proven for `apps-pg` from the Scaleway primary and for
Forgejo from the Nextcloud secondary (RPF-WP-0029, RPF-WP-0038). Neither is a
restore from the oldest retained period, and neither lane holds books or
vouchers as a named record class. The secondary lane's 10 GiB quota holds about
two archives, which is far short of an eight-year horizon. There is still no
retention schedule and no expiry deletion routine, so the position above is
unchanged.
## Reviews
- **2026-09-22** — clean check: Position unchanged: duty applies, not demonstrably met; eight-year voucher period confirmed; new restore evidence (apps-pg, Forgejo) does not cover book/voucher classes or the oldest period. Cadence instant → 1h (1 clean in a row); next check 2026-09-22 07:26Z.