Any kind of lending facility, for example, is required, by law, to retain identity documents for an extended period of time - we're talking around five years _post_ account closure.
So most businesses are not permitted to just delete the data.
So most businesses are not permitted to just delete the data.
Security-wise this comes with obvious downsides - but as protection against cyberattack, it's pretty much the gold standard.