3 min readUpdated: Category: Compliance & Regulations
What Must Be Retained
The authoritative part is the structured data component. For XRechnung, this is the XML file; for ZUGFeRD, the embedded XML inside the PDF. This part must be preserved in its original format — unaltered, complete, and machine-readable throughout the entire retention period. A printout, a screenshot, or a regenerated PDF is insufficient because machine readability is lost.
The statutory retention period for invoices is eight years. It begins at the end of the calendar year in which the invoice was issued. For documents that are part of ongoing matters — such as tax audits or legal disputes — the effective retention period may be longer.
Implementing Immutability in Practice
The GoBD requires that once an entry or document is captured, it can no longer be modified unnoticed. Technically, this can be achieved in several ways: immutable storage in an archive system, checksums over the original data record, versioning with change logs, or a combination thereof. The crucial factor is not the specific method chosen, but that it is documented and actively enforced in operational practice.
A frequent weak point in projects is intermediate transit: file shares, email inboxes, or integration staging directories where invoice data resides prior to archiving and can be modified or deleted. This pipeline segment belongs in the process documentation and requires the same rigor as the archive itself.
Audit Trail and Process Documentation
A robust audit trail answers four questions: Where did the document originate, what validations were performed on it, who processed or approved it and when, and where is it stored today. In SAP landscapes, this information is typically generated across distributed systems — in the integration layer, in the accounting document, and in the archive system. These records must be reconcilable; otherwise, the audit trail cannot be demonstrated during an inspection.
Process documentation is not a mere formality. It describes the actual workflow, including responsibilities, error handling, and system changes over time. Keeping it up to date significantly shortens audit durations.
Aligning Retention and Data Privacy
Tax retention mandates and data privacy deletion obligations are not mutually exclusive, but they must be aligned. Invoice data can and must be retained for the statutory period; however, personal data extending beyond this — such as contact details in free-text fields — requires a dedicated deletion concept.
In practice, automated deletion runs that execute upon expiry of the retention period, log all actions, and support legal holds for ongoing audits have proven effective. An archive without a deletion policy becomes a liability over time rather than a safeguard.
Our Approach
OXORY assesses the entire archiving pipeline alongside your e-invoicing solution: where the original record is created, where it is stored immutably, what metadata accompanies it, and how access is managed. The result is a concise assessment with actionable steps — not an abstract policy paper.
If you want to validate your existing storage architecture against compliance requirements, get in touch; an initial assessment typically takes less than a week.
More articles
— AMS & support
In-House Team or Outsourced AMS? Decision Matrix for SAP Support
— AMS & support
How to Calculate SAP AMS Costs
— Shoring
SAP Shoring or Nearshore? Model and Cost Comparison
