Data Retention Schedule Builder

Published August 28, 2026

Privacy laws require you to state how long you keep each type of personal data, but they rarely hand you a number. This tool does the lookup for you: select the data types your app or website collects, the jurisdictions your users are in, and your business model, then get a retention schedule table with recommended periods, the legal basis for each, and a ready-to-paste paragraph for your privacy policy's retention section.

How to Use This Tool

Start by checking every data type your app or website collects. Next, select the jurisdictions where your users are located — if you are unsure, run the privacy law applicability checker first to find out which regulations apply to you. Pick your business type from the dropdown, then hit “Generate Retention Schedule.” The tool cross-references a built-in lookup table to find the shortest binding constraint and any statutory minimums across your selected jurisdictions, then outputs a table you can reference internally and a ready-to-paste paragraph for your policy. Once your retention periods are set, generate your full privacy policy to build a compliant document around them.

Why Every Privacy Policy Needs Retention Periods

Regulators treat vague retention language as a compliance gap. In January 2022, France's CNIL fined Google €150 million (Deliberation SAN-2021-023) in part because Google Analytics cookies persisted far beyond any disclosed retention period; the authority cited the absence of a defined storage duration as a standalone violation of Article 13(2)(a) GDPR. That article requires controllers to state the period for which personal data will be stored, or the criteria used to determine that period — not hedge with “as long as necessary” or “for a reasonable period.” California's CPRA (Civil Code §1798.100(d)) added its own retention-disclosure mandate effective January 2023. Brazil's LGPD Article 16 requires deletion when the processing purpose has been achieved, Canada's PIPEDA Principle 4.5 demands destruction once the purpose is fulfilled, and India's DPDP Act Section 8(7) requires erasure once the purpose is no longer being served.

Beyond compliance, clear retention periods reduce your data footprint. Holding data longer than necessary increases your exposure in a breach, raises storage costs, and makes subject-access requests harder to fulfill. A well-defined retention schedule turns an open-ended liability into a manageable, auditable process.

Statutory Floors: When You Cannot Delete Early

Some data types have legally mandated minimum retention periods that override purpose limitation. Payment and tax records are the most common example, and the specific floor varies by country. Germany's Handelsgesetzbuch (HGB) §257 requires commercial and tax records to be retained for ten years from the end of the calendar year in which the last entry was made. France's Code de commerce Article L123-22 mandates the same ten-year period. The UK requires six years under the Companies Act 2006 §388. In the United States, IRC §6501(a) sets a three-year statute of limitations on most federal tax assessments, but §6501(e) extends it to six years when gross income is understated by more than 25 percent, and the IRS recommends keeping supporting records for seven years to cover both windows. Canada's Income Tax Act §230(4) requires six years from the end of the last tax year the records relate to. Brazil's Código Tributário Nacional (CTN) Article 173 sets a five-year decadential period for tax authority assessments. India's Income Tax Act §149(1)(b) allows reassessment up to ten years in cases involving escaped income above ₹50 lakh, making eight years the practical floor for most businesses.

When a statutory floor applies, it acts as a hard minimum — you must retain the data for at least that long even if your general retention policy would delete it sooner. This tool checks for statutory floors across all your selected jurisdictions and surfaces the longest applicable minimum so your retention schedule stays compliant everywhere you operate.

Worked Example: SaaS App With EU and US Users

A SaaS platform collects account emails, IP addresses, analytics events, and payment records from users in the EU and the United States. Here is how the retention periods resolve:

  • Account email: No statutory floor in either jurisdiction. GDPR Article 5(1)(e) and CPRA §1798.100(d) both default to purpose limitation. Recommendation: delete within 30 days of account closure.
  • IP addresses: No statutory floor. The EDPB's guidelines on data processing for server logs recommend a maximum of six months; CPRA allows up to 12 months for security and fraud prevention. The tool picks six months — the stricter ceiling — so the schedule is compliant in both markets.
  • Analytics events: No statutory floor. CNIL's Deliberation 2020-091 recommends a 25-month maximum for analytics data linked to identifiers, with 14 months for raw event data. CPRA allows 12 months. The tool picks 12 months.
  • Payment records: Statutory floor applies in both jurisdictions. The EU default in this tool is seven years (84 months), reflecting the requirement in most member states. The US floor under IRC §6501 covers up to seven years. The tool surfaces seven years as the cross-jurisdiction minimum.

The result: the SaaS platform retains emails for account duration plus 30 days, IP addresses for six months, analytics for 12 months, and payment records for seven years. Each period has a named legal basis the platform can cite in its privacy policy and defend in an audit.

Purpose Limitation: The Default Rule

Where no statutory floor exists, every major privacy law defaults to the same principle: retain personal data only for as long as it is needed to fulfill the purpose for which it was collected, then delete or anonymize it. The GDPR calls this “storage limitation” under Article 5(1)(e). The CPRA codifies it in Civil Code §1798.100(d) as a requirement that retention be “reasonably necessary and proportionate” to the disclosed purpose. PIPEDA's Principle 4.5 states that personal information shall be retained only as long as necessary for the fulfillment of the stated purposes, and the Office of the Privacy Commissioner of Canada has enforced deletion timelines against companies that kept data indefinitely (e.g., PIPEDA Report of Findings #2015-001).

In practice, purpose limitation means you need to define a concrete period for each data type rather than relying on open-ended language. The six-month ceiling for IP addresses in server logs comes from the EDPB's repeated recommendations in opinions on ISP and web-server data processing, adopted by most EU data protection authorities. The thirteen-month cookie lifetime traces to CNIL's Deliberation 2020-091 (updated in 2022), which caps analytics identifiers at 25 months and recommends 13 months for most first-party tracking cookies. The thirty-day limit for precise location data reflects the CPRA's classification of geolocation as “sensitive personal information” under §1798.140(ae)(3), which triggers the consumer's right to limit use and demands tighter retention. Your actual retention periods may be shorter depending on how you use the data. For a step-by-step guide to translating these periods into policy language, see our guide on how to write a privacy policy for your app.

Frequently Asked Questions

Are the retention periods this tool recommends legally binding?

No. The periods are common defaults drawn from published regulatory guidance and enforcement precedent. They represent reasonable starting points, not binding requirements. Statutory floors for payment and tax records are the exception — those are legal minimums set by tax law. For all other data types, consult a privacy attorney to confirm the periods fit your specific use case.

What happens if two jurisdictions recommend different retention periods?

This tool applies the shortest non-floor period across your selected jurisdictions as the recommendation, because the strictest ceiling protects you in all markets. If any jurisdiction imposes a statutory floor (a legal minimum), the tool surfaces the longest floor so you do not delete data you are legally required to keep.

Does the business type change the recommended retention periods?

The core retention periods are driven by jurisdiction, not business type. However, business type adds contextual notes — for example, ecommerce stores get a note about chargeback dispute windows for payment records, and SaaS platforms get a note about post-cancellation data cleanup. These notes highlight practical considerations that may affect how you implement your schedule.

Can I use the generated paragraph directly in my privacy policy?

The paragraph is designed as a starting point. It covers the data types and periods you selected, includes a purpose-limitation statement, and notes statutory floors where they apply. You should review it with your legal team and adjust the language to match your actual data practices before publishing it in your policy.

Does this tool send my data anywhere?

No. Everything runs in your browser. The retention lookup table is embedded in the page, and no data is sent to any server. Your selections and results stay on your device.