In most cases, no. Section 8(7) requires Data Fiduciaries to erase personal data once the purpose for processing has been fulfilled, unless another law requires the information to be retained.
This responsibility also extends to Data Processors handling the data on the organization's behalf. Maintaining clear retention schedules and automated deletion processes helps support ongoing compliance.