Skip to content

Free tool · Runs in your browser

When does this record
become eligible for deletion?

Turn a retention policy you've already decided into an exact date — eligible-for-deletion, plus an optional grace window before the permanent purge.

Retention policy

Common if you soft-delete before a permanent purge — set to 0 for an immediate hard delete at the eligible date.

July 28, 2028

eligible for deletion (in 731d)

August 27, 2028

purge date after grace (in 761d)

Reference points, not legal advice

Retention requirements vary by data type, jurisdiction and your own privacy policy. This tool does date arithmetic — it doesn't tell you what your legal minimum or maximum is.

CAN-SPAM opt-out honoring

Requesters must be suppressed within 10 business days; most senders keep the suppression record indefinitely so the address is never re-imported.

GDPR erasure requests

No fixed retention number — data is kept only as long as the stated purpose requires, then deleted or anonymized on request.

Typical org-deletion grace period

A common pattern (Norbelys included) is a ~30-day reversible grace window after a delete request, then permanent removal.

Why "keep it forever" isn't the safe default

Data you don't have can't leak

Every record kept past its useful purpose is a record that's exposed in the next breach, audit, or subject-access request. Minimization is a security control, not just a compliance checkbox.

Soft-delete first, hard-delete later

A reversible suspension window catches accidental deletions and mistaken requests; the later, irreversible purge is what actually satisfies an erasure obligation.

Suppression records are the exception

The one record type worth keeping indefinitely is usually the opt-out itself — deleting it risks re-contacting someone who explicitly said no.

Anonymized aggregates can outlive the record

A proper erasure removes personally identifying fields while keeping anonymized counts, so historical analytics don't quietly become wrong the day someone exercises their rights.

Questions, answered honestly

Is this legal advice on how long I have to keep data?

No — this is pure date arithmetic, not legal guidance. Retention minimums and maximums depend on the data type, your jurisdiction, your privacy policy, and the lawful basis you're relying on. Use it to turn a policy you've already decided into a concrete date, not to decide the policy.

What's the difference between "eligible" and "purge" date?

The date after which a record is eligible for deletion under your stated policy. The purge date adds an optional grace period on top — common when data is soft-deleted first (recoverable) and hard-deleted later (permanent), rather than destroyed the instant it's eligible.

What does GDPR actually require for retention?

GDPR doesn't set one fixed number — it requires you keep personal data only as long as the purpose you collected it for requires, and delete or anonymize it on a valid erasure request. A common pattern is separating an immediate reversible suspension from a later irreversible purge, which is what the grace-period field here models.

How long should I keep an unsubscribe/suppression record?

CAN-SPAM requires honoring an opt-out within 10 business days, but doesn't set a retention ceiling on the suppression record itself — in practice, most senders keep suppressed addresses indefinitely specifically so the person is never re-imported and re-emailed by accident.

Does this store the dates I enter?

Nowhere — the calculation runs entirely in your browser with plain JavaScript date math. No record dates or policy details are sent to a server or stored.

Curious how Norbelys handles retention?

Norbelys never hard-deletes anything that's been used — it's versioned and soft-deleted first, with a real erasure flow reserved for genuine GDPR requests.

Start sending

From $29/mo · Cancel anytime