How long to keep a signed waiver
The honest answer depends on a limitation period you have to look up. Here is how to work out the shape of it, and what to keep meanwhile.

This question gets answered with a number — three years, seven years — and the number is almost always somebody's local rule repeated until it sounded general. There is no single retention period for signed agreements, and anybody who gives you one without asking where you are has guessed.
What there is, is a way to work out the shape of the answer.
Start with the limitation period, not the document
The reason to keep a signed waiver is that somebody might make a claim, and you want the record when they do. So the period that matters is how long somebody has to bring one, which is set by statute and varies by state, by the kind of claim, and by who is claiming.
Personal injury limitation periods in the United States commonly run from one to six years depending on the state. Contract claims are frequently longer. Those are the numbers to look up for where you operate — and they are the floor of the answer, not the answer.
Then add the things that extend it
Minors. This is the big one and the one most often missed. In many jurisdictions the clock on a minor's own claim does not start until they reach majority. A waiver signed by a guardian for a twelve-year-old can therefore sit inside a window that runs well past the participant's eighteenth birthday. Operators who work with children frequently keep those records dramatically longer than adult ones, and the reason is arithmetic rather than caution.
Discovery. Some claims run from when the harm was discovered rather than when it occurred, which can be considerably later.
An incident. The moment something happens, the ordinary schedule stops applying to anything connected to it. Preserve it, including the surrounding records — the other signatures from that day, the version of the document in force, the reminders sent. Deleting on schedule during a live matter is the worst possible version of having a retention policy.
Then look at what else is in the document
Retention is not only about claims. A form carrying a date of birth, a health note, a photograph of an identity document or a card number brings its own rules, and those tend to push the other way — toward keeping it for less time, not more.
Under the GDPR and comparable regimes, personal data is kept no longer than is necessary for the purpose it was collected for. "We keep everything forever because it might be useful" is the position those rules exist to refuse. A health note gathered to run an activity safely has served its purpose when the activity is over; the signature on the release has not.
Which points at the thing most operators never do: different parts of the same form can have different lives. There is no rule that the health notes and the signature have to expire together.
What a schedule looks like when it is real
A retention policy that exists as a paragraph in a folder is not a retention policy. A real one has four properties:
- It names categories, not documents — signed agreements, identity
- evidence, message logs, drafts — because that is the level at which rules
- differ.
- Each category has a period and a reason, and the reason is a specific
- one. "Limitation period for personal injury in our state, plus a margin"
- beats "business need".
- Something actually deletes, on a schedule, without a person remembering.
- There is a hold that stops deletion when a matter is live, and a record
- of who placed it.
SignSealer has that machinery — a schedule per category, a sweep that runs, and a hold — because a policy nothing enforces is a description of intentions. What the periods should be is still your decision, with advice, for the places you operate.
Keep the evidence, not just the document
A signed PDF on its own is weaker than it looks after a few years. What makes it worth keeping is what surrounds it: the version of the document in force that day, the exact words the person consented to, when and from where, and a fingerprint taken at the moment of signing that shows the copy you hold now is the one they saw.
That bundle is the thing with a retention period. The PDF is one file in it.
The practical starting point
Find the limitation periods for your state and the claims you are exposed to. Work out whether minors are involved and what that does to the clock. Ask whether anything in the form is personal data with its own constraint. Write the periods down with the reasons beside them. Then make something enforce it.
SignSealer is not a law firm and this is not legal advice. Limitation periods and data-protection obligations differ by jurisdiction and by circumstance; what your own schedule should be is a question for a lawyer who knows where you operate.
