# Data Retention & Disposal Policy **Document owner:** [Owner/Role] **Approved by:** [Steering Committee / CISO] **Effective date:** [YYYY-MM-DD] **Review cadence:** [Annually] --- ## 1. Purpose & Scope This policy establishes mandatory requirements for how long [Organization] retains data and how it is disposed of at end of life. It applies to all data classified under the [Data Classification & Handling Policy](data_classification_policy.md), and supports GDPR principles of storage limitation and the right to erasure (Art. 17). --- ## 2. Policy Statements ### 2.1 Retention Schedule | Data Category | Classification | Retention Period | |---|---|---| | Financial records | TLP:AMBER | 7 years (statutory) | | Employee HR records | TLP:AMBER | Duration of employment + 6 years | | Customer personal data | TLP:AMBER | Duration of relationship + 2 years, or per contract | | Security/audit logs | TLP:AMBER | Per [Logging, Monitoring & Retention Policy §2.3](logging_monitoring_policy.md) | | Incident forensics | TLP:RED → AMBER on closure | 3 years from closure | | Marketing/public content | TLP:CLEAR | Business need, no mandated minimum | Retention periods **must not** exceed what is necessary for the stated business or legal purpose — indefinite retention is a violation of this policy, not a safe default. ### 2.2 Legal Hold - Data subject to litigation, investigation, or regulatory hold **must** be preserved regardless of the schedule in §2.1 until the hold is lifted by Legal. ### 2.3 Disposal & Destruction - Disposal method **must** match the classification level per [Data Classification Policy §3.3](data_classification_policy.md): - TLP:CLEAR/GREEN: standard deletion. - TLP:AMBER and above: secure delete/wipe or cryptographic erasure. - Physical media holding TLP:AMBER+STRICT/RED data: sanitized per [NIST SP 800-88](https://csrc.nist.gov/pubs/sp/800/88/r2/final) or physically destroyed. - Disposal of AMBER+STRICT/RED data **must** be logged (what, when, method, who authorized). ### 2.4 Backup Alignment - Backup retention **must not** silently extend the retention of data otherwise scheduled for deletion; deletion requests (including right-to-erasure) **must** propagate to backups within a defined window (**≤90 days**) or be documented as a technical exception. ### 2.5 Right to Erasure - Verified erasure requests **must** be fulfilled within the statutory window (GDPR: without undue delay, within 1 month, extendable to 3). - Exceptions (legal hold, legitimate business need) **must** be documented and communicated to the requester where required by law. ### 2.6 Enforcement - Data retained past its scheduled disposal date without a documented legal hold or exception **must** be treated as a policy violation and remediated. --- ## 3. Antifragility Alignment This policy is built to the five pillars of the organization's internal **Antifragile Enterprise Manifest**. | Pillar | Applied In | How | |---|---|---| | **1. Structural Decoupling** | §2.4 | Deletion propagating to backups prevents "the vendor's backup system" from becoming a hidden place data outlives its intended lifecycle | | **2. Optionality Preservation** | §2.1 | Disciplined retention avoids the illusion of value in hoarded data that later becomes a liability with no offsetting benefit | | **3. Stress-to-Signal Conversion** | §2.6 | Data found past its disposal date is a tracked finding, not a shrug | | **4. Sovereign Intelligence** | §2.3 | Disposal of sensitive data is logged and owned — auditable proof, not an assumption | | **5. Asymmetric Payoff Design (Barbell)** | §2.3 | Cryptographic erasure/physical destruction concentrated on AMBER+STRICT/RED; CLEAR/GREEN gets standard deletion — no moderate process applied to everything | --- ## 4. References - **[NIST SP 800-88 Rev. 2, Guidelines for Media Sanitization](https://csrc.nist.gov/pubs/sp/800/88/r2/final)** - **[ISO/IEC 27001:2022](https://www.iso.org/standard/27001)**