3.7 Retention Schedules & Defensible Disposal

Key Takeaways

  • Indicator II.A.6 requires retention AND disposal policies and procedures — a schedule with no enforced destruction step increases liability rather than reducing it.
  • A defensible retention schedule is built per record class, with a stated purpose, a trigger event, a retention period, a legal or business justification and a disposal method.
  • Retention periods come from the longest applicable obligation across statute, contract, limitation period and legitimate business need — not from a single round number applied to everything.
  • Legal hold overrides scheduled destruction the moment litigation or investigation is reasonably anticipated, and must be released explicitly when the matter closes.
  • Deletion and anonymization are different outcomes: only irreversible anonymization removes data from privacy law's scope, and backups need an aging or crypto-shredding procedure rather than an exemption.
Last updated: August 2026

Keeping Everything Is a Decision, and a Bad One

Indicator II.A.6 requires the privacy manager to create data retention and disposal policies and procedures. The pairing is the point. A retention schedule that says customer records are kept for seven years, with no mechanism that destroys them in year eight, has produced a document that now proves the organization knew it was over-retaining.

Over-retention is expensive in four directions at once: it enlarges the breach blast radius, it enlarges the scope of every access and erasure request, it enlarges e-discovery cost, and it is directly enforceable as a storage-limitation failure under GDPR Article 5(1)(e) and comparable state-law provisions.

Building the schedule by record class

Retention is set per record class, never per system and never as one organization-wide number.

FieldPurpose
Record classEmployee personnel file, customer transaction record, CCTV footage, marketing consent record, applicant CV
PurposeWhy the class exists at all
Trigger eventWhat starts the clock — account closure, employment end, transaction date, last contact
Retention periodDuration measured from the trigger
JustificationThe statute, contract, limitation period or documented business need
Disposal methodDeletion, crypto-shredding, secure destruction, or anonymization
OwnerThe business function accountable for executing disposal

A worked set makes the shape obvious:

Record classTriggerPeriodJustification
Unsuccessful applicant CVDecision date6-12 monthsDiscrimination-claim limitation window
Employee personnel fileEmployment endJurisdiction-specific statutory minimumEmployment and tax law
Financial transaction recordTransactionStatutory accounting periodTax and audit obligations
Marketing consent recordConsent withdrawalDuration of processing plus limitation periodEvidence of lawful basis
CCTV footageRecordingDays to weeksSecurity purpose only; longer needs justification

Note the marketing consent row. Evidence that consent was validly obtained must outlive the processing itself, because the accountability principle requires the controller to demonstrate the basis it relied on. Deleting the consent record along with the marketing data destroys the defence.

Setting the period defensibly

The period is the longest applicable of: an express statutory retention requirement; a contractual commitment; the relevant limitation period for claims; and a documented, specific business need. "We might want it someday" is not a justification, and the exam consistently treats indefinite retention as a finding rather than a strategy.

Where obligations conflict — a statute requiring five-year retention against an erasure request — the retention obligation generally prevails for that specific record, and the correct response is to restrict the data to the compelling purpose and tell the requester why, rather than to delete or to silently ignore the request.

Legal hold

The moment litigation, regulatory investigation or an internal inquiry becomes reasonably anticipated, scheduled destruction of potentially relevant records must stop. A defensible legal-hold process has a trigger definition, a named issuer (usually legal), scoped custodian notices, a suspension mechanism in the systems that actually perform deletion, periodic reminders, and — the most-missed step — an explicit release when the matter closes, so held data does not become permanent by accident.

Backups, archives and derived copies

The common failure is deleting from production while backups quietly restore the record. Backups are not exempt from deletion obligations; the expectation is a defensible procedure rather than an exemption. Practical options are backup aging on a documented cycle so restored records are re-deleted, crypto-shredding by destroying a per-subject key so ciphertext everywhere becomes unreadable, or a suppression list that re-applies deletions after any restore. Derived copies — analytics extracts, warehouses, model training sets, logs — must inherit the source retention rule, or the schedule governs only the copy nobody uses.

Deletion versus anonymization

These produce different legal outcomes and the exam tests the difference. Deletion removes the data. Anonymization transforms it so re-identification is not reasonably possible by any means likely to be used, which takes it outside privacy law's scope — but only if it is genuinely irreversible. Pseudonymization replaces identifiers while retaining a mapping key, so the data remains personal data and remains fully in scope. An organization that "anonymizes" by tokenising with a retained key has not satisfied a deletion obligation.

Worked scenario

A retailer's schedule says loyalty transaction data is retained for three years. A breach reveals eleven years of transactions in a warehouse, because the deletion job ran against the production database only. The schedule was correct and the disposal procedure was absent — precisely the II.A.6 failure. The credited remediation makes disposal executable and evidenced: extend the deletion job to every derived copy, add backup aging, run a quarterly reconciliation that samples records past their trigger date, and report a disposal-compliance metric to the steering committee.

Test Your Knowledge

A company's retention schedule requires deletion of loyalty transaction data after three years. A breach reveals eleven years of that data sitting in an analytics warehouse. What does this most directly demonstrate?

A
B
C
D
Test Your Knowledge

An organization receives an erasure request for records that a sector statute requires it to retain for five more years. What is the correct handling?

A
B
C
D