Sunday, September 6, 2026
The Data Governor
← All tools

Data Retention Schedule Builder

The retention schedule is the artifact auditors actually ask for — the matrix behind the retention policy. Pick your record categories, edit the periods and triggers to match your obligations, assign owners, and export. Everything runs in your browser; nothing is transmitted or stored.

Updated 2026-08-28 · Free · No sign-up · Not legal advice

Pre-filled periods are starting points from commonly cited U.S. federal drivers and GDPR practice. Retention law is jurisdiction- and sector-specific — validate every period with your counsel before adopting the schedule.

1 · Pick your record categories

HR & Employment
Finance & Tax
Customer & Marketing
Health (if applicable)
IT & Operations

2 · Edit your schedule

Select categories above to start building.

Runs locally in your browser. Nothing is transmitted or stored — export before you leave.

What a retention schedule must contain

Six columns, no exceptions: the record category, a specific period (a number, not "a while"), the trigger date the period runs from (creation, last transaction, separation, account closure — the trigger decides when deletion actually happens), the driver that justifies the period, the disposition method (secure deletion, anonymization, cryptographic erasure, archive-then-delete), and an accountable owner. The retention policy guide covers how the schedule fits into the full policy — legal holds, defensible deletion, and operationalizing across systems — and the retention policy template gives you the surrounding document to drop this schedule into.

Common starting points in the builder

The builder pre-fills each category with a commonly cited baseline — FLSA's three-year payroll minimum, HIPAA's six-year documentation rule for covered entities, PCI DSS's twelve-month audit-trail floor, the seven-year finance-records convention, GDPR's storage-limitation practice for marketing data. These are deliberately conservative starting points, not answers: several categories (medical records most prominently) are governed by state law, sector rules layer on top, and business justification can extend a period beyond the legal minimum if you document why. Edit every cell; own every number.

From schedule to defensible deletion

A schedule you can't enforce is a liability you've documented. Once the matrix is signed off, wire each row into the systems that hold that category — including backups and third-party platforms — and make sure your legal-hold procedure can suspend any row. If you're subject to GDPR, deletion requests interact with the schedule too: the DSAR guide covers how erasure requests override or defer to retention obligations. For the wider regulatory context, the data compliance guide maps the frameworks a multi-jurisdiction schedule has to satisfy.