Retention Schedule Conflict Checker
Paste your retention schedule and find rules that contradict each other, overlapping record types with different periods, missing legal bases and categories that no rule covers.
Last reviewed by the Radiatus Cloud team
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
Schedules contradict themselves as they grow
A retention schedule is rarely written once. Rows are added when a new system arrives, when a regulator asks a question, or when a department writes its own. The result is a document in which employee records are kept for six years in one row and permanently in another, and nobody notices because nobody reads the whole thing at once. The contradiction only surfaces during a deletion exercise or a subject access request, which is the worst moment to discover it.
The longest applicable period wins, and that is often accidental
Where two rules cover the same records, an operator faced with the conflict keeps the data, because keeping is reversible and deleting is not. So the effective retention period of your organisation is the maximum across every overlapping rule, not the one written in the policy. A schedule with three stale rows saying "permanent" has an effective policy of permanent retention regardless of what the other two hundred rows say.
Every period needs a stated reason
Storage limitation requires that data is kept no longer than necessary for the purpose, which means each period must trace to something: a statutory period, a limitation period for claims, or a documented operational need. A row with a period and no basis cannot be defended and cannot be safely shortened either, because nobody knows why it was set. Rows without a basis are the ones that never get reviewed.
Related tools
- SOC 2 Evidence Readiness — Interactive checklist to gauge your SOC 2 evidence readiness.
- Privacy Policy Checker — Check if your policy covers standard requirements (GDPR/CCPA basics).
- Compliance Req Finder — Find which standards (ISO, SOC2, HIPAA) apply to your industry/region.
- Audit Readiness Planner — Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
Frequently Asked Questions
Why do overlapping rules matter?
Because an operator facing two periods keeps the data: keeping is reversible and deleting is not. The effective retention period is therefore the maximum across every overlapping rule, not the one in the policy.
What counts as a legal basis for a period?
A statutory retention period, a limitation period for potential claims, or a documented operational need. A row with a period and no stated reason cannot be defended and cannot safely be shortened, because nobody knows why it was set.
Should anything be kept permanently?
Rarely, and only where a statute or an archiving purpose in the public interest requires it. A permanent row is worth challenging every time, because it usually originated as a placeholder.
How does this detect an overlap?
By comparing the record-type descriptions for shared significant words and flagging pairs that overlap but carry different periods. It reports what it found rather than deciding which rule is correct.
Does it decide which period is right?
No. It finds contradictions and gaps; resolving them needs the legal basis behind each row, which only you hold.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Paste your retention schedule to find conflicting rules.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.