Data Retention Compliance

Data Retention Compliance

Delete, retain, hold or anonymise. Every category differs.

What Is Data Retention Compliance?

Storage limitation is one sentence with a long tail of judgement. A quarterly disposal review has slipped three quarters, and five flagged categories wait with a different answer for each. Two are years overdue with nothing justifying the delay. One sits inside a statutory retention period and must not be touched. One is under litigation hold, needing named proceedings, exact records and a review date. The last is analytics the business needs, where anonymisation takes it out of scope. Then you find the exports, warehouses and backups the purge missed.

What You'll Learn in Data Retention Compliance

Data Retention Compliance — Training Steps

  1. Introduction

    Today you will run a disposal review under the storage limitation principle, which says personal data must be kept in identifiable form no longer than is necessary for the purpose it was collected for. The principle is short. Applying it is not, because every category needs a different answer: delete, retain under a legal obligation, hold for litigation, or take it out of scope altogether.

  2. The Audit Finding

    Alice finds a message from Priya Raghunathan, the Data Protection Officer, at the top of her inbox. The quarterly disposal review has slipped three quarters, and internal audit noticed.

  3. Opening the Records System

    Priya's email links to the records system, where the disposal queue is waiting.

  4. Signing In

    The records system holds the retention schedule, the disposal queue and the disposal log for every record category at Kerrowen Insurance.

  5. Reading the Schedule

    Before touching the queue, Alice reads the retention schedule. It is the document that decides every question the queue asks. One column carries all the weight.

  6. What Justifies Keeping It

    The schedule sets the rules. Alice checks that she can tell a real justification from a habit before she starts applying them.

  7. The Disposal Queue

    The queue lists the five flagged categories, each with its schedule entry, how long it has been held, and whether anything blocks disposal.

  8. Disposing of the Lapsed Contacts

    Alice records the disposal. The system asks for confirmation, because the action is irreversible and the confirmation is what puts her name against it in the log.

  9. The Category That Must Be Kept

    The next category looks like the same problem: employee termination files from 2021, well past the point where anyone in the business uses them. It is not the same problem at all.

  10. Obligation or Preference

    Two of the categories look superficially alike: both are old, and both have someone arguing to keep them. Alice checks that she can tell which argument actually counts.

Security Framework Coverage

CIS Controls

  • CIS 3 Data Protection

NIST CSF

  • PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • PR.DS Data Security

GDPR

  • Art. 5 Principles relating to processing of personal data (storage limitation)