Retention limits that cannot be edited away
Most sites have a data retention policy. Most of those policies are a paragraph in a document, and the actual behaviour of the system is to keep everything forever because nobody wrote the delete.
The gap only becomes visible during a subject access request or a breach, which are the two worst moments to discover it.
What we look for now is a retention setting that does something on a schedule, with a hard ceiling that no configuration can exceed, and a screen that says what the current window is in plain words. If somebody can quietly set it to ninety-nine years, it is a preference rather than a limit.
The pleasant surprise is that shorter retention makes everything else faster. Smaller tables, quicker queries, backups that finish. Deleting old data is not only the correct thing to do, it is the cheap thing.