Compliance

Data Retention Policy Generator

Build a records retention schedule from your own periods, with calculated disposal dates and structural checks for missing bases, absent trigger events, duplicates and open-ended retention.

Last reviewed by the Radiatus Cloud team

Schedule and checks appear here.

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

A period without a trigger is not a rule

The most common defect in a retention schedule is a period nobody can act on. "Six years" means nothing until it says six years from what: the end of the contract, the last transaction, the closing of the account, or the date of collection. Without that, no system can compute a disposal date and no member of staff can apply the rule consistently. This tool treats a missing trigger as a defect and names the rows that have one, because a schedule that cannot be implemented is a document rather than a control.

No built-in periods, deliberately

Statutory retention periods differ by country, by sector and by record type, and they change. A generator that shipped default periods would be handing you numbers that look authoritative and are frequently wrong for your situation, which is worse than handing you nothing. Every period here is one you supply. What the tool contributes is structure and checking: it finds rows with no stated basis, categories listed twice with conflicting periods, and open-ended retention that would be hard to defend.

Backups are where schedules quietly fail

A record deleted from a live system that persists in a backup for another year has not been retained for the period the schedule states. It has been retained for the backup cycle, and that is the period that is true. Either the disposal method has to account for the backup regime or the schedule has to say plainly that it does not, because the gap between the stated policy and what actually happens is exactly what an audit or a subject access request exposes.

Related tools

Frequently Asked Questions

Does this include the legal retention periods for my country?

No, deliberately. Statutory periods vary by country, sector and record type and they change. Supplying defaults would hand you authoritative-looking numbers that are often wrong. You provide the periods; the tool provides structure and checking.

What does the tool actually check?

Structural gaps: rows with no stated basis, no trigger event or no disposal method, categories listed twice with different periods, open-ended retention, category names suggesting special category data, and long periods with no statutory source named.

Why does a retention period need a trigger event?

Because the clock has to start somewhere. Six years from the end of the contract and six years from the date of collection give different disposal dates for the same record, and without one stated no system can compute a date at all.

What happens when the same record appears in two categories?

In practice the longer period governs, because the surviving copy determines when the data is really gone. The tool flags duplicate categories with conflicting periods for that reason.

Why is indefinite retention flagged?

Because open-ended retention is the hardest position to defend under a storage-limitation principle. "We might need it" is not a purpose. If a specific obligation requires it, the schedule should name that obligation.

Is this legal advice?

No. It formats and structurally checks the schedule you enter. Whether your periods are correct for your jurisdiction and sector is a question for the applicable rules or a qualified adviser.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

List each data category with its period and basis.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.