Skip to content
Calcrivo

Data Retention Compliance Calculator

Check retention compliance and over-retention exposure: schedule coverage, deletion success, legal holds and storage cost.

Inputs

TB
%
%
%
years
years
%
currency/TB/year

Retention Compliance Score

41.3/ 100

Over-Retained Data

205.1TB

Excess Retention

4.0years

Annual Cost of Over-Retention

$45,120

Deletion Coverage Gap

61.8%

Exposure Note

Backups excluded from deletion — data you deleted is still discoverable and still breachable

Next Step

Extend deletion to backups and archives, or shorten backup retention to match

Step by step

  1. Values used

    Data in scope = 600 TB; Data types with a defined retention period = 70 %; Coverage by automated deletion = 45 %; Scheduled deletions completing successfully = 85 %; Required retention period = 7 years; Actual average age of retained data = 11 years; Data under legal hold = 6 %; Backups and archives included in deletion = No; Storage cost per TB per year = 220 currency/TB/year

  2. Data Retention Compliance

    overRetainedFraction = (actualAge − requiredPeriod) ÷ actualAge, less the share under legal hold; compliance = (0.40×scheduleCoverage + 0.45×effectiveDeletion + 0.15×retentionAlignment) × backupFactor.

  3. Cost of over-retention

    wastedCost = overRetainedTB × costPerTBPerYear — the recurring price of keeping data you are required to delete.

  4. Retention Compliance Score

    = 41.3 / 100

  5. Over-Retained Data

    = 205.1 TB

  6. Excess Retention

    = 4.0 years

  7. Annual Cost of Over-Retention

    = 45,120

  8. Deletion Coverage Gap

    = 61.8

  9. Exposure Note

    = Backups excluded from deletion — data you deleted is still discoverable and still breachable

How it works

Compliance depends on three things: whether a retention period is defined, whether deletion actually executes, and whether the resulting age profile matches the rule. Automated deletion is weighted highest because manual purges are perpetually deferred, and its coverage is multiplied by job success rate — a deletion job that fails silently is worse than none, since the records say the data is gone. Backups are the common failure: data deleted from production but retained in a seven-year archive has not been deleted. Over-retained data is pure liability — it carries full breach and discovery exposure, ongoing storage cost, and by definition no remaining business value.

Formulas

Data Retention Compliance

overRetainedFraction = (actualAge − requiredPeriod) ÷ actualAge, less the share under legal hold; compliance = (0.40×scheduleCoverage + 0.45×effectiveDeletion + 0.15×retentionAlignment) × backupFactor.

effectiveDeletion
Automated deletion coverage multiplied by job success rate
legalHoldShare
Data legitimately retained beyond schedule for litigation
backupFactor
0.75 where deletion does not reach backups and archives

Cost of over-retention

wastedCost = overRetainedTB × costPerTBPerYear — the recurring price of keeping data you are required to delete.

overRetainedTB
Volume beyond the required retention period

Frequently Asked Questions

How is Data Retention Compliance calculated?

overRetainedFraction = (actualAge − requiredPeriod) ÷ actualAge, less the share under legal hold; compliance = (0.40×scheduleCoverage + 0.45×effectiveDeletion + 0.15×retentionAlignment) × backupFactor. Compliance depends on three things: whether a retention period is defined, whether deletion actually executes, and whether the resulting age profile matches the rule. Automated deletion is weighted highest because manual purges are perpetually deferred, and its coverage is multiplied by job success rate — a deletion job that fails silently is worse than none, since the records say the data is gone. Backups are the common failure: data deleted from production but retained in a seven-year archive has not been deleted.

Why does Data Retention Compliance matter?

Over-retained data is pure liability — it carries full breach and discovery exposure, ongoing storage cost, and by definition no remaining business value.

What values do I need to enter?

This calculator takes 9 inputs: Data in scope, Data types with a defined retention period, Coverage by automated deletion, Scheduled deletions completing successfully, Required retention period, Actual average age of retained data, Data under legal hold, Backups and archives included in deletion, Storage cost per TB per year. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Does a legal hold excuse over-retention?

For the data actually under hold, yes — that is a legitimate override. The problem is scope creep: holds applied to entire systems rather than relevant records, then never lifted, which is how organisations keep everything forever and call it legal.

Why treat backups as in scope for erasure?

Because a subject-access or erasure obligation follows the data, not the tier. Most regulators accept a documented approach where backups age out on a defined cycle rather than being surgically edited — but 'we never delete from backup' is not that approach.

You might also need