2.0 KiB
2.0 KiB
Data Retention & Disposal Guidance
Document owner: [Owner/Role]
Approved by: [Steering Committee / CISO]
Effective date: [YYYY-MM-DD]
Review cadence: [Annually]
1. Purpose & Scope
Implementation guidance for the Data Retention & Disposal Policy. Applies to IT, data owners, and Legal.
2. Automating Retention
- Use lifecycle policies native to the storage platform (M365 retention labels, S3 lifecycle rules, database TTL/partition-drop jobs) rather than relying on manual deletion — manual processes are the reason retention schedules drift into indefinite retention.
- Tag data at creation with its retention class so lifecycle rules can act on it automatically.
3. Sanitization Method by Media
| Media | Method |
|---|---|
| Cloud storage object | Cryptographic erasure (delete the key) or platform secure-delete API |
| Local SSD/HDD (AMBER+ data) | Cryptographic erasure preferred; full-disk overwrite if unencrypted |
| Physical media (RED data) | Physical destruction (shred/degauss), logged |
| Backup tapes/snapshots | Expire per retention schedule; confirm deletion propagates, don't assume |
4. Right-to-Erasure Workflow
- Verify requester identity.
- Check for legal hold — if present, inform requester of the exception per §2.5 of the policy.
- Delete from primary systems, then trigger backup propagation (or document why not, e.g., immutable backup within its retention window).
- Confirm and log completion within the statutory window.
5. Checklist
✅ Retention schedule (policy §2.1) mapped to actual system lifecycle rules, not just written down.
✅ Legal hold process tested at least once with a mock hold.
✅ Backup deletion propagation verified, not assumed.
✅ Disposal of AMBER+STRICT/RED data logged with method and authorizer.