Data Retention Schedule Builder
The retention schedule is the artifact auditors actually ask for — the matrix behind the retention policy. Pick your record categories, edit the periods and triggers to match your obligations, assign owners, and export. Everything runs in your browser; nothing is transmitted or stored.
Pre-filled periods are starting points from commonly cited U.S. federal drivers and GDPR practice. Retention law is jurisdiction- and sector-specific — validate every period with your counsel before adopting the schedule.
1 · Pick your record categories
2 · Edit your schedule
Select categories above to start building.
| Category | Retention period | Trigger | Driver / justification | Disposition | Owner |
|---|
Runs locally in your browser. Nothing is transmitted or stored — export before you leave.
What a retention schedule must contain
Six columns, no exceptions: the record category, a specific period (a number, not "a while"), the trigger date the period runs from (creation, last transaction, separation, account closure — the trigger decides when deletion actually happens), the driver that justifies the period, the disposition method (secure deletion, anonymization, cryptographic erasure, archive-then-delete), and an accountable owner. The retention policy guide covers how the schedule fits into the full policy — legal holds, defensible deletion, and operationalizing across systems — and the retention policy template gives you the surrounding document to drop this schedule into.
Common starting points in the builder
The builder pre-fills each category with a commonly cited baseline — FLSA's three-year payroll minimum, HIPAA's six-year documentation rule for covered entities, PCI DSS's twelve-month audit-trail floor, the seven-year finance-records convention, GDPR's storage-limitation practice for marketing data. These are deliberately conservative starting points, not answers: several categories (medical records most prominently) are governed by state law, sector rules layer on top, and business justification can extend a period beyond the legal minimum if you document why. Edit every cell; own every number.
From schedule to defensible deletion
A schedule you can't enforce is a liability you've documented. Once the matrix is signed off, wire each row into the systems that hold that category — including backups and third-party platforms — and make sure your legal-hold procedure can suspend any row. If you're subject to GDPR, deletion requests interact with the schedule too: the DSAR guide covers how erasure requests override or defer to retention obligations. For the wider regulatory context, the data compliance guide maps the frameworks a multi-jurisdiction schedule has to satisfy.