Skip to content

Document template · eu.gdpr.data_retention_schedule

Data Retention Schedule

  • Render-verified
  • Legal-sensitive
  • Version 1.0.0

Internal register documenting how long each category of personal data is kept, why, and how it is deleted at end of retention. Supports the storage-limitation principle (Art. 5(1)(e)) and is the evidence base for answers to Art. 13(2)(a) retention-period disclosures.

JSON Schema

Fields in this template

Data sent to the API is validated against the template’s JSON Schema before anything is rendered. This template defines 21 fields:

Field Required Type Description
controller Required object
controller.name Required string
controller.dpo_email Optional string
version Required string
effective_date Required date
next_review Optional date
entries Required array of object
entries[].data_category Required string
entries[].purpose Required string
entries[].legal_basis Optional enum
entries[].retention_period Required string
entries[].retention_criterion Optional string How the clock is measured (e.g. 'from end of contract', 'from last interaction').
entries[].legal_source Optional string Statute or professional rule that sets the period, when applicable (e.g. 'BE Code of Commercial Law — 7 years').
entries[].deletion_method Required string 'Hard delete', 'anonymisation', 'archive with access removed', etc.
entries[].owner Required string
entries[].systems Optional array of string Systems/tables where this category lives.
review_cycle Optional string
approved_by Optional object
approved_by.name Optional string
approved_by.title Optional string
approved_by.date Optional date

POST /render

Generate it

One POST /render call: send your JSON, get the finished PDF back. Or skip the JSON entirely and describe the document in plain language on chut.app.

curl
curl -X POST https://api.papii.eu/render \
  -H "X-API-Key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "template": "eu.gdpr.data_retention_schedule",
    "data": { ... },
    "options": {"language": "en"}
  }' -o data-retention-schedule.pdf

Frequently asked questions

What is “Data Retention Schedule”?

Internal register documenting how long each category of personal data is kept, why, and how it is deleted at end of retention. Supports the storage-limitation principle (Art. 5(1)(e)) and is the evidence base for answers to Art. 13(2)(a) retention-period disclosures. On papii this document is available as template eu.gdpr.data_retention_schedule: a JSON Schema plus a deterministic PDF renderer, so the same data always produces the same document.

Can I generate a Data Retention Schedule with AI?

Yes. chut.app — the AI back office papii powers — fills this template from a plain-language description: you describe the document in one sentence, the AI structures the data, papii validates it against the schema and renders the PDF. Developers can also call the papii API directly with structured JSON.

Is the Data Retention Schedule template legally compliant?

This template is render-verified: its schema, sample data and PDF output are automatically tested on every release. It is published with status “ready”, meaning it has not yet been through papii’s final legal review. Where it references specific legislation, that is stated in the template description — always have a professional check documents with legal effect before relying on them.