...
Know what personal data they hold onto and why they need it.
Must be able to justify how long they keep the personal data.
have a policy with standard retention periods.
regularly review the information and erase or anonymise anonymize the whole or part of personal data they no longer need.
...