Skip to content
Last updated: 2026-04-06
Guide

Data Retention Management

Dxtra tracks data retention policies through configurable fields on processing purposes and data processor configurations.

Documentation Only

Retention periods in Dxtra are for documentation and compliance tracking. Automated deletion enforcement is not currently implemented. Organizations must implement their own deletion processes.

Retention Configuration

Processing Purpose Retention

Each processing purpose in the dashboard includes:

Setting Description
Retention period Maximum data retention duration
Usage period Active processing duration
Essential flag Whether processing is essential for service

Data Processor Retention

Each configured data processor includes processor-specific retention and usage periods.

Common Retention Periods

Duration Typical Use
30 days Temporary/log data
90 days Short-term processing
13 months Transaction data
1 year Standard retention
5 years Financial records
7 years Tax compliance
11 years Advertising data
50 months Analytics data
While active While service relationship is active

Pre-configured Processor Retention

Dxtra includes retention defaults for common data processors:

Processor Retention Usage Notes
Stripe 5 years 13 months AML/KYC requirements
Shopify While active While active While merchant active
WooCommerce 30 days 30 days Server logs
Eventbrite While active While active While account active
SurveyMonkey While active While active Customer controlled
Mailchimp While active While active While account active
Klaviyo 90 days 90 days Post-deletion period
Customer.io While active While active As long as necessary
QuickBooks While active While active Legal/business obligations
Google Ads 11 years 180 days Advertising data retention
Google Analytics 50 months 180 days Configurable 2-50 months
Sabre While active While active Service provision

Configuring Retention

Set Processing Purpose Retention

  1. Navigate to Purposes in the Dxtra dashboard
  2. Select or create a processing purpose
  3. Set the retention period and usage period
  4. Mark whether the processing is essential
  5. Save the configuration

Set Processor Retention

  1. Navigate to Processors in the Dxtra dashboard
  2. Select a configured processor
  3. Review and update retention and usage periods
  4. Save the configuration

Common regulatory retention requirements:

Regulation Data Type Retention Notes
GDPR Personal data As needed for purpose No longer than necessary
CCPA Consumer data No specific minimum Delete on valid request
Tax (US) Financial records 3-7 years Varies by jurisdiction
SOX Financial communications 7 years Public companies
PCI DSS Cardholder data Minimum needed Subject to PCI requirements

Legal Exceptions

Retention policies may be overridden by: active legal holds, ongoing investigations, contractual obligations, or industry-specific regulations.

Deletion Requests

Processing Erasure Requests

When handling GDPR Article 17 or CCPA deletion requests:

  1. Verify identity -- Confirm the requester's identity
  2. Assess legal basis -- Verify no legal basis prevents deletion
  3. Identify scope -- Review processing activities for the data subject
  4. Process deletion -- Delete data from systems manually
  5. Notify processors -- Contact integrated processors for deletion
  6. Document -- Update request status to completed

Data Controller Account Deletion

Dxtra supports scheduled deletion for data controller accounts. When account deletion is scheduled and the date passes, the account and associated data are eligible for deletion.

Best Practices

Setting Retention Periods

  1. Identify legal requirements -- Research applicable regulations
  2. Document business need -- Justify retention beyond legal minimum
  3. Configure in Dxtra -- Set retention and usage periods in the dashboard
  4. Establish deletion process -- Create manual deletion procedures
  5. Regular review -- Audit retention compliance periodically

Handling Conflicts

When legal requirements conflict with deletion requests:

  1. Apply the longest required retention period
  2. Document justification in the processing purpose
  3. Inform data subject of legal basis for extended retention
  4. Delete when legal requirement expires

When processor retention differs from your policy:

  1. Document processor retention in the Processors dashboard
  2. Include processor retention in privacy notices
  3. Request deletion from processor when your retention expires
  4. Track deletion confirmation

Common Questions

What happens when retention period expires?

Nothing automatic. Organizations must implement deletion processes and manually remove data when retention periods expire.

Can retention periods be extended?

Yes. Update the retention period on the processing purpose in the dashboard. Document the business or legal justification for the extension.

How do we handle indefinite retention?

"While active" retention indicates data retained while the service relationship is active. Define what triggers the retention period start (e.g., account closure).

What about data in backups?

Backup retention should align with primary data retention. Document backup deletion procedures separately.