Data Retention
Data retention determines why information is kept, for how long, and what happens when that period ends. This is different from customer retention, which measures whether customers continue using a service.
A duration needs a starting event
Keep for 30 days is incomplete without saying whether the clock starts at collection, delivery, or case closure. Copying a transcript into another store should not accidentally restart its lifetime. Carry the appropriate lifecycle metadata with derived copies.
Different copies may have different justified rules. An active delivery address, a closed support case, and a minimal audit event need not expire together.
Expiry needs an action
Assign an owner and define deletion, restricted preservation, or another approved disposition. An exception should identify its scope, reason, authority, and review condition. Keeping data for an exception does not automatically permit ordinary reuse. Verify that storage jobs and backup restoration follow the rule rather than treating a written duration as enforcement.
Reference: NIST Privacy Framework.
Discover more from Insightful Data Lab
Subscribe to get the latest posts sent to your email.
