graphgrc

DAT-03: Data Retention & Deletion

Objective

Minimize data retention and enable secure deletion.

Description

Data is retained according to policy and legal requirements. Data is securely deleted when no longer needed. Customers can request deletion of their data.

Implementation Details

Retention Policy: Application logs retained 90 days. Audit logs retained 7 years. Customer data retained per contract + 90 days.

Automated Deletion: S3 lifecycle policies automatically delete old data. Automated scripts clean up aged development/test data.

Customer Deletion: API endpoint allows customers to request data deletion. Deletion completed within 30 days and confirmed.

Backup Retention: Database backups retained 30 days, then deleted. Long-term archives encrypted and access-controlled.

Examples

Audit Evidence


Framework Mapping

SOC 2

GDPR


Referenced By

This section is automatically generated by make generate-backlinks. Do not edit manually.

Standards: