Data Core · Data Governance · Module
Retention and deletion
How long each kind of data is kept and what causes it to be removed — the decision that is always deferred and always accumulates.
The idea
How it works
Keeping data requires no decision and deleting it requires one, which is why every organisation holds more than it intended and less deliberately than it believes.
Retained data is an obligation: it has to be secured, may have to be produced, and carries risk in proportion to age and to how little anyone remembers about it.
Working with it
In practice
- 01
Set a period per data type
Derived from obligation and use rather than from storage cost, which is no longer the constraint.
- 02
Automate the deletion
A retention policy executed manually is a retention policy that is not executed.
- 03
Resolve the conflicts explicitly
Where one rule requires keeping and another requires deleting, decide rather than letting whichever system acts first decide.
- 04
Record what was deleted
So that a later question about missing data has an answer other than uncertainty.
One level in
The components of retention and deletion
A component is something that exists afterwards which did not exist before — a deliverable or a mechanism, not an intention.
A retention policy executed manually is a retention policy that is not executed.
The other modules in data governance
Ownership
Who is accountable for each data set being right, current and appropriately used — one person, in the business rather than in a technical function.
LearnDefinitions and lineage
What each term means, where the figure comes from, and what happens to it on the way — the record that makes two reports reconcilable.
LearnAccess
Who may see what, on what basis, and how that is reviewed — balancing the cost of restriction against the cost of exposure deliberately.
Learn