The logic here is the opposite of financial records, which is why people get it wrong by applying one rule to both. Financial records you keep because somebody may ask for them, and the cost of keeping is negligible. Customer data you limit because holding it creates exposure, and every additional year of retained personal information is another year that data could be involved in an incident.
Start by separating what you hold. Contact details and purchase history are ordinary business records with a legitimate ongoing purpose, and keeping them for several years after the last transaction is defensible. Payment details, identity documents, health information, and anything a customer would consider private are a different category and should be held only as long as there is a specific reason.
Payment details in particular should usually not be held at all. Your processor stores them and gives you a token, which is what allows repeat billing without your systems containing card numbers. A business holding actual card details has taken on a compliance obligation and a serious exposure for no benefit.
Set the period against a business reason rather than a number pulled from guidance. How long is somebody realistically a repeat customer in your industry? For a service bought every few years, five years is reasonable. For something bought once, the case for holding contact details for a decade is weak. The reason is what makes the period defensible if anybody questions it.
Understand that customers can ask you to delete their data, and that in several jurisdictions you may be obliged to comply within a defined period. That obligation is easier to meet when you know where the data lives, which is the practical argument for the inventory rather than for the policy itself.
Know the exceptions before deleting, because some records must be kept regardless of a request. Transaction records needed for tax, anything subject to a legal hold, and information required to complete an ongoing obligation. A deletion request does not override those, and the correct response is to delete what you can and explain what you must retain and why.
Write the policy in a few lines rather than a document. What you hold, why, for how long, and what happens at the end. That page costs an afternoon and is what makes the practice consistent, particularly once more than one person is involved.
Then actually delete on the schedule, which is the part almost nobody does. A retention policy that has never resulted in anything being deleted is a document rather than a practice, and an annual pass through old records is what makes the difference. Deleting also reduces what you would have to notify about if anything went wrong, which is the concrete benefit rather than the abstract one.
Know where the copies live as well as the original, because customer data spreads into email threads, exports, spreadsheets, and backups. A deletion that addresses the customer system and leaves five copies elsewhere has not deleted anything, and mapping where data goes is the harder half of any retention policy.
Treat inactive records differently from active ones rather than applying one rule. Moving old customers into an archive with restricted access satisfies most of the purpose of deletion while preserving the ability to answer a question about historical work, and it reduces what is exposed day to day.