Check retention compliance and over-retention exposure: schedule coverage, deletion success, legal holds and storage cost.
Compliance depends on three things: whether a retention period is defined, whether deletion actually executes, and whether the resulting age profile matches the rule. Automated deletion is weighted highest because manual purges are perpetually deferred, and its coverage is multiplied by job success rate — a deletion job that fails silently is worse than none, since the records say the data is gone. Backups are the common failure: data deleted from production but retained in a seven-year archive has not been deleted. Over-retained data is pure liability — it carries full breach and discovery exposure, ongoing storage cost, and by definition no remaining business value.
Data Retention Compliance
overRetainedFraction = (actualAge − requiredPeriod) ÷ actualAge, less the share under legal hold; compliance = (0.40×scheduleCoverage + 0.45×effectiveDeletion + 0.15×retentionAlignment) × backupFactor.
Cost of over-retention
wastedCost = overRetainedTB × costPerTBPerYear — the recurring price of keeping data you are required to delete.
overRetainedFraction = (actualAge − requiredPeriod) ÷ actualAge, less the share under legal hold; compliance = (0.40×scheduleCoverage + 0.45×effectiveDeletion + 0.15×retentionAlignment) × backupFactor. Compliance depends on three things: whether a retention period is defined, whether deletion actually executes, and whether the resulting age profile matches the rule. Automated deletion is weighted highest because manual purges are perpetually deferred, and its coverage is multiplied by job success rate — a deletion job that fails silently is worse than none, since the records say the data is gone. Backups are the common failure: data deleted from production but retained in a seven-year archive has not been deleted.
Over-retained data is pure liability — it carries full breach and discovery exposure, ongoing storage cost, and by definition no remaining business value.
This calculator takes 9 inputs: Data in scope, Data types with a defined retention period, Coverage by automated deletion, Scheduled deletions completing successfully, Required retention period, Actual average age of retained data, Data under legal hold, Backups and archives included in deletion, Storage cost per TB per year. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
For the data actually under hold, yes — that is a legitimate override. The problem is scope creep: holds applied to entire systems rather than relevant records, then never lifted, which is how organisations keep everything forever and call it legal.
Because a subject-access or erasure obligation follows the data, not the tier. Most regulators accept a documented approach where backups age out on a defined cycle rather than being surgically edited — but 'we never delete from backup' is not that approach.