Docs

Console: retention & purge

How long superseded consent history is kept, and when already-erased subjects get purged for good.

Configured per site, under Retention & purge. A daily job (enforce-retention) applies the thresholds every night. The live consent state and the newest record per purpose are always kept regardless of these settings — they only affect history that has already been superseded.

Prune superseded history after (days)

Permanently deletes ConsentRecord / PreferenceRecord rows that have already been superseded (replaced by a newer one) and are older than the threshold. A value of 0 keeps all history indefinitely.

Hard-purge erased subjects after (days)

A DSAR erasure crypto-shreds the identifier’s encryption keys immediately — the subject is unfindable from that moment on. This setting goes one step further: after N days it also removes the remaining de-identified rows (and their receipts / TC strings), closing the ciphertext residue left over from shredding. The hash-chained audit log keeps the proof that it happened. A value of 0 keeps them indefinitely.

Both purges are irreversible and run automatically every night as soon as you save a non-zero value — there is no additional confirmation or grace period.