DAT-008 Data Retention and Deletion
Description
Documented retention schedules exist for all data categories, aligned with legal obligations, contractual commitments and business requirements. Data is securely deleted or anonymised when retention periods expire. Deletion is verifiable and applied consistently across primary storage, backups and replicas. The schedule also carries the path customer data takes after a contract ends: the retrieval period during which it stays available to the customer, the erasure that follows the expiry of that period once the customer has finished moving and the scope of that erasure, which reaches the customer's digital assets as well as its data.
Rationale
Retaining data beyond its useful or legal life increases breach exposure and regulatory liability. Verified deletion is particularly critical at tenant offboarding. An erasure clock is not a retention period. It starts at the end of a retrieval window rather than at the end of a use, and it waits on the customer having finished leaving, so a schedule built from retention categories alone has no row for it and the data sits in a staging location nobody owns. DAT-023 documents the retrieval period and the scope, and DAT-026 records the switch the erasure is conditioned on; the schedule and the deletion itself are here.
Applicability (9 profiles)
EX-104 written in S8 wave B (migration 057). The retention schedule now carries the path customer data takes after a contract ends: the retrieval period during which it stays available, the erasure that follows the expiry of that period once the customer has finished moving and the customer's digital assets inside the erasure scope. Art. 25(2)(h) stays partial for one element, the guarantee as a clause of the customer agreement, which VND-013 carries. The guarantee rests on the verifiable deletion across primary storage, backups and replicas that the control already required.
Framework Mappings (22)
| DSP-02 | Secure Disposal | partial |
| DSP-16 | Data Retention and Deletion | full |
| DSP-02 | Secure Disposal | partial |
| DSP-16 | Data Retention and Deletion | full |
| DORA-Art.30.2.d | Access, recovery and return of data on insolvency or termination | informative |
| EU-DA-Art.25.2.h | Guaranteed Erasure After the Retrieval Period | partial |
| GDPR-Art.17 | Right to Erasure (Right to be Forgotten) | informative |
| GDPR-Art.5.1e | Storage Limitation | full |
| HIPAA-164.310.d.2.i | Disposal | full |
| HIPAA-164.312.c.1 | Integrity | informative |
| HIPAA-164.316.b.2.i | Time Limit | informative |
| 8.10 | Information deletion | full |
| NIS2-CIR-12.2 | Handling of Assets | informative |
| MP-6 | Media Sanitization | partial |
| SI-12 | Information Management and Retention | full |
| SI-21 | Information Refresh | partial |
| GV-1.7-002 | AI System Decommissioning Processes | GV-1.7-002 | informative |
| ASI06 | Memory & Context Poisoning | informative |
| LLM09 | Vector and Embedding Weaknesses | informative |
| C1.2 | Disposal of Confidential Information | full |
| P4.2 | Retention of Personal Information | full |
| P4.3 | Disposal of Personal Information | full |
Evidence (2)
Data retention policy and schedule defining retention periods per data category, legal basis for each retention period, and deletion or anonymisation requirements at expiry.
Example: Data Retention Schedule (Confluence / spreadsheet), approved by DPO and Legal, listing each data category with: retention period, legal justification, storage location, deletion method (automated purge / manual review), and date last reviewed
Test: Request the data retention schedule. Verify: (1) all personal data categories in the RoPA have a retention period assigned, (2) each period has a legal or business justification, (3) deletion method is specified (automated or manual) for each category, (4) schedule was approved and reviewed within 24 months. (5) the schedule carries the post-contract path for customer data: the retrieval period, the erasure that follows its expiry once the customer has finished moving and the digital assets inside the erasure scope.
Automated or manual deletion records confirming that data is purged or anonymised when retention periods expire, including across backups and replicas.
Example: Automated deletion job execution logs (AWS Lambda / Airflow / database scheduler) for the last 3 months, showing records deleted, data categories affected, execution timestamps, and confirmation of deletion from primary, backup and replica stores
Test: Request deletion execution logs for the most recent quarter. Verify: (1) deletion jobs ran at the scheduled frequency, (2) deletion covers primary database, backup snapshots and replicas, (3) volume of deleted records is consistent with expected data volumes, (4) no failed deletion jobs are outstanding without documented exception handling. (5) for a customer whose contract ended in the period, the erasure ran after the retrieval period expired rather than at termination and covered the digital assets alongside the data.
Questions (3)
Does your organisation maintain documented retention schedules for all data categories?
Retention schedules should be assigned to all personal data categories in the RoPA, with a legal or business justification for each period. Deletion should cover primary storage, backups and replicas.
How is data deletion or anonymisation executed when a retention period expires?
Fully automated deletion across all storage tiers (primary, backup, replica) is the strongest control. Any manual or ad hoc approach must be supported by execution records to demonstrate completeness.
What does the retention schedule state about customer data once a contract ends?
Options run from the most commonly stated to the least. The sequence matters more than the periods: an erasure clocked from termination rather than from the end of the retrieval window deletes data a customer is still entitled to collect, and one with no completion condition deletes it mid-migration. Digital assets are the item most often left out, because they are held by a different team from the one that owns the retention schedule.