There is a genre of content in this industry consisting of a table of Member States and a number of years. It is popular because it answers the question people ask. It is unreliable for three reasons that are worth understanding before trusting any version of it, including a version you might build yourself.

The first is that the VAT Directive does not set the period. It requires invoices to be stored and leaves it to each Member State to determine how long, which means there are as many answers as there are jurisdictions and each can change independently.

The second is that the tax period is frequently not the longest obligation attaching to the same piece of paper. Commercial and company law impose their own. So do sectoral rules, grant conditions and public contracts. The number that governs is the largest of them, and a table of VAT periods does not contain it.

The third is that the period is usually expressed as a duration from a reference point that is not the invoice date, so the effective retention is longer than the stated figure by up to a year.

Work out the rule, not the number

The durable question is not "how long in Poland?" It is "which rules attach to this document, for this entity, and which of them runs longest?"

The categories of rule that can set a retention period, and where each one is read from
Category of ruleWhat it governsWhich documents it catchesWhere the actual period is published
National VAT lawStorage of invoices for indirect tax purposesSales and purchase invoices, credit notes, and the data supporting themThe Member State's tax administration, and the Commission's taxes in Europe database as a starting point
General tax procedure lawAssessment and limitation windows for tax generallyAccounting records, ledgers, supporting documentationThe national tax procedure code, usually separate from the VAT act
Commercial or company lawBooks and records of a trading entityAccounts, ledgers, correspondence, and often invoices as accounting vouchersThe national commercial code or companies act, not the tax administration
Sectoral regulationRecords specific to an industryWhatever the sector rule names, frequently longer than taxThe sector regulator
Grant, subsidy and public contract termsDocuments evidencing funded expenditureInvoices charged to the funded activityThe funding agreement itself, which almost nobody rereads
Limitation periods for civil claimsEvidence you may need to defend or bring a claimAnything evidencing the contract and its performanceNational civil law; this is a commercial decision, not a compliance one
Live audit, appeal or litigationDocuments relevant to the matterWhatever is in scope of the proceedingsNot published; it is a decision you make and record

That table is the answer this page can honestly give, and it is more useful than a list of numbers because it keeps working after the numbers change.

Why the reference point matters

A period stated as a number of years rarely runs from the date on the invoice. It commonly runs from the end of the calendar year, the end of the accounting period, or the end of the period in which the return covering the transaction was filed.

The practical effect is that an invoice issued in January is retained materially longer than one issued in December of the same year, and that a deletion process keyed to the invoice date will delete some documents early. That is the kind of error that is invisible in testing, because it only affects documents at the edge of the window, and it is one of the more common defects in automated retention schedules.

The remedy is dull and reliable: key the schedule to the period end that the national rule actually specifies, not to the document date, and have somebody who has read the rule confirm which it is.

Events that stop the clock

Ordinary retention assumes nothing is happening. Several things suspend that assumption.

An open audit or assessment covering a period means the documents for that period stay, regardless of the ordinary expiry. So does a live appeal, and so does litigation where the documents are relevant. In several jurisdictions a correction or an amended return restarts a limitation period, which extends retention for the transactions affected.

None of this is exotic and all of it is missed by schedules designed as pure calendars. A retention process needs a hold mechanism — a way to mark a class of documents as not-for-deletion pending an event — and somebody with the authority to set and release it. Businesses that discover this need during an audit discover it by having deleted something.

The ceiling on the other side

Retention obligations set a floor. Data protection law sets a ceiling, and they are usually reconciled badly.

The principle is that personal data is not kept for longer than is necessary for the purposes it is processed for. A legal retention obligation is a purpose, and it justifies keeping the data for exactly as long as the obligation runs. What it does not justify is keeping everything that happened to be stored alongside the invoice for the same period — correspondence, contact records, transmission logs beyond what evidences the transaction — simply because separating them was inconvenient.

So the schedule has two edges rather than one. It has to hold until the longest obligation expires and it has to actually delete afterwards, and an archive with no working deletion is as much a finding as one that deletes early. How that boundary is drawn, and what justifies keeping what, is examined in invoice data as personal data.

The provider whose retention is shorter than yours

A service provider offering to hold your documents will hold them for the period in the contract, which was negotiated on commercial terms and not against your longest legal obligation. Where the two differ, the obligation is still yours and the documents are not. This is worth checking against the actual contract rather than the sales material, and it is the reason exit terms matter more than price.

It is the whole trail, not just the invoice

One consequence follows from everything above and is regularly missed. The retention obligation is about the invoice, but the evidence that makes the invoice defensible lives in other records — the order, the delivery note, the remittance, the transmission receipt.

Those records sit in systems with their own retention schedules, set by people solving different problems. A purchasing system that purges closed orders after three years is behaving reasonably by its own lights and is quietly destroying one end of your audit trail. The invoice survives; the link from it to the supply does not.

The fix is organisational rather than technical: the retention schedule has to be agreed across the systems that hold the trail, not set for the archive alone. That is also why the archive design question is bigger than choosing where to put the files.

What to write down

One page per entity. Which jurisdictions it is established or registered in, which categories of rule from the table above apply to it, which is the longest, what the reference point is, what triggers a hold, and where each figure came from — with the date it was checked and a note to check it again.

That last part is the difference between a retention policy and a retention decision. The numbers move. A document that says where they came from can be updated in an afternoon. A document that just states them has to be researched from nothing every time somebody asks whether it is still true.