Data Retention Compliance Calculator
Check retention compliance and over-retention exposure: schedule coverage, deletion success, legal holds and storage cost.
Inputs
Retention Compliance Score
41.3/ 100
Over-Retained Data
205.1TB
Excess Retention
4.0years
Annual Cost of Over-Retention
$45,120
Deletion Coverage Gap
61.8%
Exposure Note
Backups excluded from deletion — data you deleted is still discoverable and still breachable
Next Step
Extend deletion to backups and archives, or shorten backup retention to match
Step by step
Values used
Data in scope = 600 TB; Data types with a defined retention period = 70 %; Coverage by automated deletion = 45 %; Scheduled deletions completing successfully = 85 %; Required retention period = 7 years; Actual average age of retained data = 11 years; Data under legal hold = 6 %; Backups and archives included in deletion = No; Storage cost per TB per year = 220 currency/TB/year
Data Retention Compliance
overRetainedFraction = (actualAge − requiredPeriod) ÷ actualAge, less the share under legal hold; compliance = (0.40×scheduleCoverage + 0.45×effectiveDeletion + 0.15×retentionAlignment) × backupFactor.
Cost of over-retention
wastedCost = overRetainedTB × costPerTBPerYear — the recurring price of keeping data you are required to delete.
Retention Compliance Score
= 41.3 / 100
Over-Retained Data
= 205.1 TB
Excess Retention
= 4.0 years
Annual Cost of Over-Retention
= 45,120
Deletion Coverage Gap
= 61.8
Exposure Note
= Backups excluded from deletion — data you deleted is still discoverable and still breachable
How it works
Compliance depends on three things: whether a retention period is defined, whether deletion actually executes, and whether the resulting age profile matches the rule. Automated deletion is weighted highest because manual purges are perpetually deferred, and its coverage is multiplied by job success rate — a deletion job that fails silently is worse than none, since the records say the data is gone. Backups are the common failure: data deleted from production but retained in a seven-year archive has not been deleted. Over-retained data is pure liability — it carries full breach and discovery exposure, ongoing storage cost, and by definition no remaining business value.
Formulas
Data Retention Compliance
overRetainedFraction = (actualAge − requiredPeriod) ÷ actualAge, less the share under legal hold; compliance = (0.40×scheduleCoverage + 0.45×effectiveDeletion + 0.15×retentionAlignment) × backupFactor.
- effectiveDeletion
- Automated deletion coverage multiplied by job success rate
- legalHoldShare
- Data legitimately retained beyond schedule for litigation
- backupFactor
- 0.75 where deletion does not reach backups and archives
Cost of over-retention
wastedCost = overRetainedTB × costPerTBPerYear — the recurring price of keeping data you are required to delete.
- overRetainedTB
- Volume beyond the required retention period
Frequently Asked Questions
How is Data Retention Compliance calculated?
overRetainedFraction = (actualAge − requiredPeriod) ÷ actualAge, less the share under legal hold; compliance = (0.40×scheduleCoverage + 0.45×effectiveDeletion + 0.15×retentionAlignment) × backupFactor. Compliance depends on three things: whether a retention period is defined, whether deletion actually executes, and whether the resulting age profile matches the rule. Automated deletion is weighted highest because manual purges are perpetually deferred, and its coverage is multiplied by job success rate — a deletion job that fails silently is worse than none, since the records say the data is gone. Backups are the common failure: data deleted from production but retained in a seven-year archive has not been deleted.
Why does Data Retention Compliance matter?
Over-retained data is pure liability — it carries full breach and discovery exposure, ongoing storage cost, and by definition no remaining business value.
What values do I need to enter?
This calculator takes 9 inputs: Data in scope, Data types with a defined retention period, Coverage by automated deletion, Scheduled deletions completing successfully, Required retention period, Actual average age of retained data, Data under legal hold, Backups and archives included in deletion, Storage cost per TB per year. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Does a legal hold excuse over-retention?
For the data actually under hold, yes — that is a legitimate override. The problem is scope creep: holds applied to entire systems rather than relevant records, then never lifted, which is how organisations keep everything forever and call it legal.
Why treat backups as in scope for erasure?
Because a subject-access or erasure obligation follows the data, not the tier. Most regulators accept a documented approach where backups age out on a defined cycle rather than being surgically edited — but 'we never delete from backup' is not that approach.
You might also need
- Quantum Threat Readiness CalculatorCommonly used together
- Forensic Evidence Storage CalculatorCommonly used together
- Data Classification CalculatorCommonly used together
- Privacy Risk CalculatorCommonly used together
- Enterprise Cybersecurity Health Score CalculatorAlso in Forensics & Emerging Threats
- Kill Chain Coverage CalculatorAlso in Forensics & Emerging Threats