How should a team set data retention and deletion requirements?

Discussion

Verified answerLast verified: 2026-08-02
  • Author
    Posts
  • #3337

    Keeping everything forever increases risk, but deleting records too early can break legal, operational, or audit obligations. What should the software requirements state?

    #3338
    Accepted editorial answer

    Map each data type to its owner, purpose, governing retention rule, storage locations, backups, holds, and approved deletion method. State when the clock starts and which event pauses or restarts it.

    Require the system to operationalize the policy in practice. The team should be able to find covered records, apply holds, delete or sanitize data across active and backup environments, restrict who can take action, and obtain evidence that the action is complete.

    NIST SP 800-53 Revision 5.1 covers retention, media sanitization, backups, authorization, and evidence of control operation. The exact periods still come from the buyer’s records, privacy, legal, and business requirements.

  • You must be logged in to reply to this topic.

Reply to this discussion

You must be logged in to reply. Editors verify buy-side questions and cite reviews when answering.

Create an account