Agent skill

Retention Schedule

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle.

Apache-2.0Auto-check passedLegal & Compliance

Install Retention Schedule

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-schedule -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills retention-schedule --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/retention-schedule .claude/skills/retention-schedule && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
retention-schedule
GitHub stars
297
Token cost
~3.3k tokens
SKILL.md length
1,478 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle.

  • Works in 4 steps: Data Inventory and Categorization → Determine Retention Periods → Retention Schedule Matrix → …
  • Schedule maintenance
  • SKILL.md covers Overview, Legal Foundation, Retention Schedule Construction and Retention Review Triggers, plus 2 more sections
  • Runs Python scripts from its folder

What it does

Retention Schedule is an agent skill from mukul975/Privacy-Data-Protection-Skills. Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle. Maps data categories to retention periods with legal basis justification, regulatory minimum holding periods, and automated review triggers for schedule maintenance. Activate for retention policy, storage limitation, data lifecycle, retention period queries.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Schedule maintenance
  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the retention-schedule skill to design and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle”
  • “/retention-schedule”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Data Inventory and Categorization
  2. Determine Retention Periods
  3. Retention Schedule Matrix
  4. Retention Period Justification Template

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Retention Schedule loads about 3.3k tokens when it runs, and up to ~4.8k if it reads all its reference files. Until then it costs about 98 tokens; SKILL.md has 1,478 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,478 words, ~3,280 tokens.

Download SKILL.mdSave it as .claude/skills/retention-schedule/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
retention-schedule
description
Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle. Maps data categories to retention periods with legal basis justification, regulatory minimum holding periods, and automated review triggers for schedule maintenance. Activate for retention policy, storage limitation, data lifecycle, retention period queries.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
data-retention-deletion
metadata.tags
retention-schedule, storage-limitation, gdpr-article-5, data-lifecycle, retention-period

Data Retention Schedule Design and Implementation

Overview

A data retention schedule is the foundational governance document that specifies how long each category of personal data is retained, the legal basis for that retention period, and the triggers for review or deletion. GDPR Article 5(1)(e) establishes the storage limitation principle: personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed. This skill provides the complete framework for building, maintaining, and enforcing a category-based retention schedule.

GDPR Article 5(1)(e) — Storage Limitation

Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed. Personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes in accordance with Article 89(1), subject to implementation of appropriate technical and organisational measures.

GDPR Recital 39 — Storage Limitation Elaboration

Personal data should be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed. Personal data should be processed only if the purpose of the processing could not reasonably be fulfilled by other means. In order to ensure that the personal data are not kept longer than necessary, time limits should be established by the controller for erasure or for a periodic review.

GDPR Article 13(2)(a) and Article 14(2)(a) — Transparency

The controller shall provide the data subject with the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period.

GDPR Article 30(1)(f) — Records of Processing

Where possible, the envisaged time limits for erasure of the different categories of data must be recorded in the Records of Processing Activities.

Retention Schedule Construction

Step 1: Data Inventory and Categorization

Identify and categorize all personal data processed by the organization:

Category IDData CategoryExample Data ElementsProcessing PurposeLegal Basis (Art. 6)
CAT-001Employee HR RecordsName, address, NI number, salary, performance reviewsEmployment administrationArt. 6(1)(b) Contract + Art. 6(1)(c) Legal obligation
CAT-002Customer Account DataName, email, phone, address, account preferencesService deliveryArt. 6(1)(b) Contract
CAT-003Customer Transaction RecordsPurchase history, payment details, invoicesContract performance and legal obligationArt. 6(1)(b) Contract + Art. 6(1)(c) Legal obligation
CAT-004Marketing Contact DataName, email, consent records, campaign interactionsDirect marketingArt. 6(1)(a) Consent
CAT-005Website AnalyticsIP address, device data, browsing behaviour, cookiesWebsite optimizationArt. 6(1)(f) Legitimate interest
CAT-006Job Applicant DataCV, cover letter, interview notes, referencesRecruitmentArt. 6(1)(b) Pre-contractual steps
CAT-007CCTV FootageVideo recordings of premisesSecurity and safetyArt. 6(1)(f) Legitimate interest
CAT-008Supplier Contact DataName, email, phone, company, contract termsVendor managementArt. 6(1)(b) Contract
CAT-009Customer Support RecordsTickets, correspondence, complaint recordsService delivery and qualityArt. 6(1)(b) Contract + Art. 6(1)(f) Legitimate interest
CAT-010Financial and Tax RecordsAccounts, tax filings, audit reports, bank statementsLegal complianceArt. 6(1)(c) Legal obligation
Step 2: Determine Retention Periods

For each data category, determine the retention period based on:

  1. Statutory minimum: Legal requirements mandating minimum retention (e.g., tax records: 6 years under HMRC requirements).
  2. Contractual necessity: Duration of the contract plus any post-contractual obligations.
  3. Limitation periods: Time within which legal claims may be brought (e.g., 6 years for contract claims under Limitation Act 1980 in the UK; 3 years for tort claims).
  4. Regulatory requirements: Sector-specific retention mandates (e.g., FCA record-keeping rules, MiFID II requirements).
  5. Legitimate business need: Justifiable operational necessity beyond legal minimums (must be documented and proportionate).
Step 3: Retention Schedule Matrix

The following is the retention schedule for Orion Data Vault Corp:

Category IDData CategoryRetention PeriodLegal Basis for RetentionRetention TriggerReview Frequency
CAT-001Employee HR RecordsDuration of employment + 6 yearsLimitation Act 1980 s.5 (contract); Employment Rights Act 1996Employment termination dateAnnual
CAT-002Customer Account DataDuration of account + 2 yearsContractual necessity; limitation period bufferAccount closure dateAnnual
CAT-003Customer Transaction Records6 years from transaction dateHMRC record-keeping; Companies Act 2006 s.386; Limitation Act 1980Transaction completion dateAnnual
CAT-004Marketing Contact DataUntil consent withdrawn + 30 days processingConsent-based; deletion upon withdrawalConsent withdrawal date or 24 months since last engagementBiannual
CAT-005Website Analytics26 months from collectionICO guidance; CNIL recommendation on analytics cookiesData collection dateAnnual
CAT-006Job Applicant Data6 months from recruitment decision (unsuccessful); duration of employment + 6 years (successful)ICO Employment Practices Code; limitation period for discrimination claims (6 months from decision)Recruitment decision dateAfter each recruitment cycle
CAT-007CCTV Footage30 days from recording (standard); up to 6 months if incident flaggedICO CCTV Code of Practice; proportionality principleRecording dateMonthly
CAT-008Supplier Contact DataDuration of contract + 6 yearsLimitation Act 1980; contractual necessityContract termination dateAnnual
CAT-009Customer Support Records3 years from case closureLegitimate interest; limitation period for service-related claimsCase closure dateAnnual
CAT-010Financial and Tax Records6 years from end of financial year (standard); 20 years (deeds and title documents)HMRC requirements; Companies Act 2006 s.388; Limitation Act 1980 s.8End of relevant financial yearAnnual
Show full SKILL.md (590 more words)Show less
Step 4: Retention Period Justification Template

For each retention period exceeding the minimum statutory requirement, document the justification:

RETENTION PERIOD JUSTIFICATION — Orion Data Vault Corp
------------------------------------------------------
Category: [CAT-XXX — Category Name]
Proposed Period: [X years from trigger event]
Statutory Minimum: [X years, cite statute]
Proposed Excess: [X additional months/years]

Justification for Excess Period:
1. [Specific business need — e.g., contractual warranty period extends 12 months beyond statutory minimum]
2. [Risk assessment — e.g., historical claims data shows 3% of claims filed in year 5-6]
3. [Regulatory expectation — e.g., FCA expects retention beyond statutory minimum for conduct risk purposes]

Proportionality Assessment:
- Volume of data subjects affected: [number]
- Sensitivity of data: [low/medium/high]
- Risk to data subjects from extended retention: [assessment]
- Mitigating measures: [e.g., access restriction, pseudonymization after statutory minimum]

Approved by: [DPO Name]
Date: [YYYY-MM-DD]
Next Review: [YYYY-MM-DD]

Retention Review Triggers

Automatic Triggers

The following events trigger an immediate review of the applicable retention period:

  1. Retention period expiry: Automated alert 30 days before the retention period for any data category expires.
  2. Legislative change: Any amendment to statutes cited as the legal basis for a retention period (e.g., changes to Companies Act, tax legislation, sector-specific regulations).
  3. Regulatory guidance update: Publication of new ICO, EDPB, or sector-specific regulatory guidance on retention.
  4. Purpose change: Any change to the purpose for which data in a category is processed.
  5. Data breach: Following a data breach involving a data category, review whether the retention period contributed to the scope of the breach.
  6. Data subject complaint: Complaint or challenge from a data subject regarding the retention period for their data.
  7. Litigation or regulatory investigation: Commencement of legal proceedings or regulatory investigation affecting a data category.
Scheduled Review Cycle
Review TypeFrequencyScopeResponsible
Category-level reviewAs per schedule (see retention matrix)Individual data category retention period, legal basis, and justificationData Owner + DPO
Full schedule reviewAnnual (Q1)Entire retention schedule, all categories, legislative scanDPO + Legal + IT
Regulatory alignment checkBiannualCross-reference retention periods against current statutory requirementsLegal Counsel
Technical compliance auditAnnual (Q3)Verify that automated deletion and archiving systems enforce scheduled periodsIT + DPO

Implementation Guidance

Technical Implementation
  1. Metadata tagging: Every data record must carry metadata indicating its data category (CAT-XXX), creation/collection date, retention trigger date, and calculated deletion date.
  2. Automated monitoring: Deploy retention monitoring that scans data stores against the retention schedule and flags records approaching or exceeding their retention period.
  3. Deletion queue: Records exceeding their retention period enter an automated deletion queue with a 14-day grace period for review before permanent deletion.
  4. Audit logging: All retention actions (creation, review, extension, deletion) must be logged with timestamp, actor, and justification.
  5. Suppression lists: Maintain suppression records for deleted data subjects to prevent re-collection where appropriate (e.g., marketing opt-out lists).
Governance Requirements
  1. Data owners: Each data category must have a designated data owner responsible for reviewing and approving retention periods.
  2. DPO oversight: The Data Protection Officer reviews and approves all retention periods and any exceptions.
  3. Board reporting: Retention schedule compliance metrics (percentage of data within retention period, volume of data deleted, exceptions granted) are reported to the board quarterly.
  4. Training: All staff who handle personal data must receive training on the retention schedule applicable to their function, refreshed annually.

Common Retention Period Reference (EU/UK)

RequirementStatutory PeriodSource
Tax records (UK)6 years from end of accounting periodHMRC; TMA 1970 s.34
Company accounting records6 years from end of financial yearCompanies Act 2006 s.388
Employment records (general)6 years from terminationLimitation Act 1980 s.5
Payroll records6 years from end of tax yearIncome Tax (PAYE) Regulations 2003
Health and safety records40 years from last entryCOSHH Regulations 2002; Ionising Radiations Regulations 2017
Anti-money laundering records5 years from end of business relationshipMoney Laundering Regulations 2017 reg.40
Consumer contracts6 years from breachLimitation Act 1980 s.5
Personal injury claims3 years from date of knowledgeLimitation Act 1980 s.11
Discrimination claims (employment)6 months from act complained ofEquality Act 2010 s.123
CCTV footage30 days (ICO guidance)ICO CCTV Code of Practice
Pension records6 years from end of scheme year (minimum); 12 years recommendedPensions Act 2004; Limitation Act 1980

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/retention-schedule of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Retention Schedule next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Retention Schedule compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Retention Schedule this skillmukul975/Privacy-Data-Protection-Skills297—~3.3kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms586—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    586 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    943 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    943 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    149 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    297 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    297 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    297 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    297 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    297 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    297 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Retention Schedule

What does Retention Schedule do?

Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle. Retention Schedule is an agent skill from mukul975/Privacy-Data-Protection-Skills. Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle.

When should I use Retention Schedule?

Retention Schedule fits situations like: schedule maintenance; tasks that involve Privacy and GDPR.

How do I install Retention Schedule in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-schedule -a claude-code`. Or copy the skill folder (skills/privacy/retention-schedule in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/retention-schedule in your project. Claude Code loads it when a task matches its description.

How do I install Retention Schedule in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-schedule -a codex`. Or copy the skill folder (skills/privacy/retention-schedule in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/retention-schedule in your project. Codex loads it when a task matches its description.

Can I use Retention Schedule in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-schedule -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/retention-schedule, .gemini/skills/retention-schedule, .github/skills/retention-schedule and .opencode/skills/retention-schedule in your project.

What does Retention Schedule need to run?

Going by SKILL.md and its folder, Retention Schedule needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Retention Schedule access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Retention Schedule safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Retention Schedule use?

Retention Schedule is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Retention Schedule use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Retention Schedule?

Skills that share tags, products or a category with Retention Schedule: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Retention Schedule?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 297 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.