Skip to content
Last updated: 2026-04-06
Guide

Retention Policies

Configure data retention periods for processing purposes to comply with GDPR storage limitation requirements.

Overview

Retention policies in Dxtra are defined at the processing purpose level. Each processing purpose specifies:

  • Retention Period -- How long data may be retained
  • Usage Period -- How long data may be actively used

These values inform data lifecycle management and help meet GDPR Article 5(1)(e) storage limitation requirements.

Configuring Retention

Setting Retention on Processing Purposes

When creating or editing a processing purpose in the dashboard:

  1. Navigate to Processing Activities in the dashboard
  2. Select the processing purpose to configure
  3. Set the Retention Period (how long data may be kept)
  4. Set the Usage Period (how long data may be actively used)
  5. Save the processing purpose

Retention and usage periods are stored in seconds. The dashboard displays these as human-readable durations.

Common Retention Periods

Purpose Legal Basis Typical Retention
Marketing Consent Until withdrawal
Order fulfillment Contract 7 years (tax records)
Analytics Legitimate interest 26 months
Support tickets Contract 5 years
Employment records Legal obligation Duration + 6 years

Retention Period Reference

Duration Seconds
1 year 31,536,000
2 years 63,072,000
5 years 157,680,000
7 years 220,752,000

Retention periods should align with the legal basis for processing.

  • Retention ends when consent is withdrawn
  • Grace period for compliance evidence (30 days typical)
  • Consent withdrawal records retained separately (6 years)

Contract-Based Processing

  • Retention tied to contract duration
  • Post-contract retention for warranty/claims
  • Tax and accounting records (7--10 years)

Legitimate Interest

  • Retention must be proportionate
  • Regular review of necessity
  • Clear justification documented
  • Retention per regulatory requirement
  • Varies by jurisdiction and data type
  • May override shorter periods

Data Subject Transparency

Privacy Notice Requirements

Retention information should be included in privacy notices. The Transparency Center widget displays retention information automatically:

  • Purpose descriptions
  • Retention periods in human-readable format
  • Legal basis for each purpose

Integration with Rights Requests

Erasure Requests:

When processing erasure requests, retention policies determine:

  1. Which data can be deleted immediately
  2. Which data must be retained for legal obligations
  3. Documentation requirements for retained data

Data Access Requests:

Include retention information in data exports:

  • Processing purposes
  • Retention periods
  • Expected deletion dates

Best Practices

Policy Design

  1. Document rationale -- Record why each retention period was chosen
  2. Align with legal basis -- Retention must match processing justification
  3. Consider minimum periods -- Legal obligations may set floor
  4. Review regularly -- Audit retention settings quarterly

Implementation

  1. Default conservatively -- Use shorter periods when uncertain
  2. Purpose segregation -- Different retention per purpose
  3. Backup alignment -- Ensure backups follow retention schedule
  4. Third-party coordination -- Sync with data processor retention

Manual Review Required

Dxtra tracks retention settings but does not automatically delete data. Organizations must regularly review data against retention policies, implement deletion procedures, coordinate with integrated systems, and document retention decisions.