3.7 Retention Schedules & Defensible Disposal
Key Takeaways
- Indicator II.A.6 requires retention AND disposal policies and procedures — a schedule with no enforced destruction step increases liability rather than reducing it.
- A defensible retention schedule is built per record class, with a stated purpose, a trigger event, a retention period, a legal or business justification and a disposal method.
- Retention periods come from the longest applicable obligation across statute, contract, limitation period and legitimate business need — not from a single round number applied to everything.
- Legal hold overrides scheduled destruction the moment litigation or investigation is reasonably anticipated, and must be released explicitly when the matter closes.
- Deletion and anonymization are different outcomes: only irreversible anonymization removes data from privacy law's scope, and backups need an aging or crypto-shredding procedure rather than an exemption.
Keeping Everything Is a Decision, and a Bad One
Indicator II.A.6 requires the privacy manager to create data retention and disposal policies and procedures. The pairing is the point. A retention schedule that says customer records are kept for seven years, with no mechanism that destroys them in year eight, has produced a document that now proves the organization knew it was over-retaining.
Over-retention is expensive in four directions at once: it enlarges the breach blast radius, it enlarges the scope of every access and erasure request, it enlarges e-discovery cost, and it is directly enforceable as a storage-limitation failure under GDPR Article 5(1)(e) and comparable state-law provisions.
Building the schedule by record class
Retention is set per record class, never per system and never as one organization-wide number.
| Field | Purpose |
|---|---|
| Record class | Employee personnel file, customer transaction record, CCTV footage, marketing consent record, applicant CV |
| Purpose | Why the class exists at all |
| Trigger event | What starts the clock — account closure, employment end, transaction date, last contact |
| Retention period | Duration measured from the trigger |
| Justification | The statute, contract, limitation period or documented business need |
| Disposal method | Deletion, crypto-shredding, secure destruction, or anonymization |
| Owner | The business function accountable for executing disposal |
A worked set makes the shape obvious:
| Record class | Trigger | Period | Justification |
|---|---|---|---|
| Unsuccessful applicant CV | Decision date | 6-12 months | Discrimination-claim limitation window |
| Employee personnel file | Employment end | Jurisdiction-specific statutory minimum | Employment and tax law |
| Financial transaction record | Transaction | Statutory accounting period | Tax and audit obligations |
| Marketing consent record | Consent withdrawal | Duration of processing plus limitation period | Evidence of lawful basis |
| CCTV footage | Recording | Days to weeks | Security purpose only; longer needs justification |
Note the marketing consent row. Evidence that consent was validly obtained must outlive the processing itself, because the accountability principle requires the controller to demonstrate the basis it relied on. Deleting the consent record along with the marketing data destroys the defence.
Setting the period defensibly
The period is the longest applicable of: an express statutory retention requirement; a contractual commitment; the relevant limitation period for claims; and a documented, specific business need. "We might want it someday" is not a justification, and the exam consistently treats indefinite retention as a finding rather than a strategy.
Where obligations conflict — a statute requiring five-year retention against an erasure request — the retention obligation generally prevails for that specific record, and the correct response is to restrict the data to the compelling purpose and tell the requester why, rather than to delete or to silently ignore the request.
Legal hold
The moment litigation, regulatory investigation or an internal inquiry becomes reasonably anticipated, scheduled destruction of potentially relevant records must stop. A defensible legal-hold process has a trigger definition, a named issuer (usually legal), scoped custodian notices, a suspension mechanism in the systems that actually perform deletion, periodic reminders, and — the most-missed step — an explicit release when the matter closes, so held data does not become permanent by accident.
Backups, archives and derived copies
The common failure is deleting from production while backups quietly restore the record. Backups are not exempt from deletion obligations; the expectation is a defensible procedure rather than an exemption. Practical options are backup aging on a documented cycle so restored records are re-deleted, crypto-shredding by destroying a per-subject key so ciphertext everywhere becomes unreadable, or a suppression list that re-applies deletions after any restore. Derived copies — analytics extracts, warehouses, model training sets, logs — must inherit the source retention rule, or the schedule governs only the copy nobody uses.
Deletion versus anonymization
These produce different legal outcomes and the exam tests the difference. Deletion removes the data. Anonymization transforms it so re-identification is not reasonably possible by any means likely to be used, which takes it outside privacy law's scope — but only if it is genuinely irreversible. Pseudonymization replaces identifiers while retaining a mapping key, so the data remains personal data and remains fully in scope. An organization that "anonymizes" by tokenising with a retained key has not satisfied a deletion obligation.
Worked scenario
A retailer's schedule says loyalty transaction data is retained for three years. A breach reveals eleven years of transactions in a warehouse, because the deletion job ran against the production database only. The schedule was correct and the disposal procedure was absent — precisely the II.A.6 failure. The credited remediation makes disposal executable and evidenced: extend the deletion job to every derived copy, add backup aging, run a quarterly reconciliation that samples records past their trigger date, and report a disposal-compliance metric to the steering committee.
A company's retention schedule requires deletion of loyalty transaction data after three years. A breach reveals eleven years of that data sitting in an analytics warehouse. What does this most directly demonstrate?
An organization receives an erasure request for records that a sector statute requires it to retain for five more years. What is the correct handling?