Data Core · Data Governance · Module

Retention and deletion

How long each kind of data is kept and what causes it to be removed — the decision that is always deferred and always accumulates.

The idea

How it works

Keeping data requires no decision and deleting it requires one, which is why every organisation holds more than it intended and less deliberately than it believes.

Retained data is an obligation: it has to be secured, may have to be produced, and carries risk in proportion to age and to how little anyone remembers about it.

Working with it

In practice

  1. 01

    Set a period per data type

    Derived from obligation and use rather than from storage cost, which is no longer the constraint.

  2. 02

    Automate the deletion

    A retention policy executed manually is a retention policy that is not executed.

  3. 03

    Resolve the conflicts explicitly

    Where one rule requires keeping and another requires deleting, decide rather than letting whichever system acts first decide.

  4. 04

    Record what was deleted

    So that a later question about missing data has an answer other than uncertainty.

One level in

The components of retention and deletion

A component is something that exists afterwards which did not exist before — a deliverable or a mechanism, not an intention.

  1. The schedule

    How long each data type is kept, and why.

    Learn
  2. The mechanism

    What actually performs the deletion, and whether it runs.

    Learn
  3. The conflicts

    Where retention and deletion obligations collide, and how that was resolved.

    Learn

A retention policy executed manually is a retention policy that is not executed.