Data Retention

Data retention determines why information is kept, for how long, and what happens when that period ends. This is different from customer retention, which measures whether customers continue using a service.

A duration needs a starting event

Keep for 30 days is incomplete without saying whether the clock starts at collection, delivery, or case closure. Copying a transcript into another store should not accidentally restart its lifetime. Carry the appropriate lifecycle metadata with derived copies.

Different copies may have different justified rules. An active delivery address, a closed support case, and a minimal audit event need not expire together.

Expiry needs an action

Assign an owner and define deletion, restricted preservation, or another approved disposition. An exception should identify its scope, reason, authority, and review condition. Keeping data for an exception does not automatically permit ordinary reuse. Verify that storage jobs and backup restoration follow the rule rather than treating a written duration as enforcement.

Reference: NIST Privacy Framework.


Discover more from Insightful Data Lab

Subscribe to get the latest posts sent to your email.

Similar Posts

Questions, corrections, or additional insights?

This site uses Akismet to reduce spam. Learn how your comment data is processed.