Managing Data Retention and Compliance

Kristina Cardona
Kristina Cardona
  • Updated

Overview

This article guides you through organizing and managing your data categories within the Talexio Data Privacy module. It outlines how to dynamically map standard retention periods to individual subsets of employee documentation, helping your organization automate compliance tracking across all system files.

Permissions

To manage these Data Retention and GDPR rules, you must have the Manage Data Retention/GDPR Settings at the Global level.

 

How to Access the Page

To configure your compliance and retention settings, follow these steps to navigate to the correct dashboard:

  1. Navigate to the main menu and select the Settings tab.
  2. From the available settings options, click on the Data Retention / GDPR tab.

 

Global Compliance Settings

The left panel governs your company's overarching data legal frameworks. Here you can configure who monitors your data and formally document your internal policies.

System-Settings-Talexio-05-22-2026_02_20_PM.png
  • Data Protection Officer (DPO): Set and identify your organisation's formal Data Protection Officer. The assigned officer will be able to perform the deletion of employee information that has fully reached its scheduled retention period. To assign an officer, click the Select an employee dropdown menu, locate the individual, and select SAVE CHANGES.
  • Data Retention Policy Document: Upload your organisation's data retention policy document. Once an active file is securely uploaded, it becomes transparently available to everyone across your organization for general visibility and legal compliance audits. Click the UPLOAD A NEW POLICY button to attach your company's official handbook or legal document.

To set your company's DPO, you will first need to create a profile for them. If the DPO is not employed with your company, they do not need to have a position. In such a case, all you need to do is add their Name, Surname, Work Email address, and Access level (permissions).

Configuring Retention Periods

System-Settings-Talexio-05-22-2026_02_23_PM.png

Before mapping retention rules to specific types of information, you can build a customised matrix of standard duration under the Retention Periods section. To do so:

  1. Locate the Retention Periods column on the left side of the screen.
  2. Click the + ADD RETENTION PERIOD button to create a new duration line.
  3. Enter a recognisable term (e.g., Micro, Short, Medium, Long) in the Name field.

  4. Enter the duration value in the Days field (e.g., 3652 days for a 10-year policy rule).

  5. Click SAVE CHANGES at the bottom of the section to finalise.

 

To delete an existing retention period constraint that is no longer required, simply click the Bin Icon next to the respective duration field and click save changes.

Data Categories Matrix

The table below outlines how to map your custom retention periods to individual employee information subsets. By default, fields are set to Indefinite retention until a specific policy option is assigned via its dropdown menu.

Data Category Description & Scope Included
Contact details Primary contact channels and emergency contact details.
Contracts Legal employment contracts and documents.
Correspondence Official internal and external correspondence with or about the employee.
CV Curriculum Vitae details.
Disciplinary Formal disciplinary write-ups, warnings, and official company records.
Employment General employment history records.
Health & Safety Documents related to health and safety measures, workplace incidents, and protocols.
Interests Tracked hobbies and personal employee interests.
Job Description Assigned job description information and role responsibilities.
LEAVE Historic records of holiday allocations, sickness, and other general absences.
Other Miscellaneous operational documents and general employee-related information.
Payroll Historical payroll run information, employee benefits, and expense claims.
Performance Formal appraisals, reviews, and tracking of other performance measures.
Personal details Core identifying details including legal name, home address, date of birth, and other distinctive features that uniquely identify an individual.
Personal Health Information Recorded allergies or pre-existing medical and health conditions.
Sensitive Any document or highly confidential information deemed sensitive. Changing visibility to this folder does not automatically restrict access; it must be managed manually via custom system permissions.
Time and Attendance Clocking data, timesheets, and overall attendance information.
Training Training history records, courses attended, proofs of payment, and qualification certificates.
Work Permit Official immigration files, visa applications, and physical work permit documents.

Always review local laws and GDPR rules before modifying retention settings to a finite duration. Once data retention periods pass and deletion is confirmed by your DPO, the corresponding files cannot be recovered.

Are documents automatically deleted?

So how does this all work? Let's say you added a retention period of 365 days for Contracts. If an employee was terminated on the 14th of April 2026, the DPO will receive an email 365 days after the termination date informing them that, in line with the retention period set up in the Data Retention/GDPR settings, the employee's contract must be deleted.

The company's Admin must delete the documents themselves if the DPO does not have access to other employees' documents.

Simplify your HR with Talexio. Learn more.

Share: