Data retention (GDPR / HinSchG)
Closed reports are deleted automatically after a retention period. This satisfies GDPR Art. 5(1)(e) (storage limitation) and HinSchG §11 Abs. 5 (documentation is deleted three years after the procedure ends).
- Each deletion writes an immutable audit entry (
report.auto_deleted) with the case number and legal basis. /admin/retentionshows the configuration and the next scheduled run.- On by default since v1.5.0. A report is deleted
RETENTION_DAYSafter it is closed. OpenWhistle was released in 2026, so no installation holds a report closed three years ago: turning retention on deletes nothing today.
| Variable | Description |
|---|---|
RETENTION_ENABLED Optional |
Daily automatic deletion of closed reports older than RETENTION_DAYS. Set to false only on legal advice (e.g. pending litigation). Default: true |
RETENTION_DAYS Optional |
Days after a report is closed before it is automatically deleted. Default matches HinSchG §11 Abs. 5: documentation is deleted 3 years after the procedure ends. Change only on legal advice. Default: 1095 |