How to Create Smart Data Retention and Deletion Policies (2024)

Data Privacy Week is an annual reminder to brush up on and fine-tune our privacy and compliance best practices. As an ISO 27001 Certified provider, Pure is committed to keeping customers’ data safe.

In fact, compliance is a huge part of the data privacy conversation. There’s a critical aspect of compliance that’s often overlooked, and it’s nearly as important as how a customer’s data gets used: data retention and deletion policies.

In 2019, a €14.5 million GDPR fine was issued for a non-compliant data retention schedule. And a report from 451 Research reveals that 31% of respondents aren’t always following their data deletion and retention policies—or haven’t implemented retention policies at all.

If you have a data retention and deletion schedule, it’s critical that you’re following it. If you don’t, here’s what you need to know—but note, this isn’t legal advice and you should consult with your organization’s lawyer or legal team.

What Is a Data Retention Schedule?

Data retention and deletion schedules address what happens to data after it’s been used, dictating how long data can be stored and how it’s disposed of. Even if you’re not misusing the data and it’s properly secured, retaining it beyond the cut-off date counts as an infraction.

A data retention schedule can be absolutely critical to this aspect of compliance. A retention and deletion policy will cover:

  • What data sets you can store or archive
  • Where these data sets can be stored (e.g., a data-only bunker)
  • How long you can retain a data set in storage
  • When a data set should be deleted or where it can be moved

In storing different data sets, I find one of the most helpful approaches is a tiered backup architecture. It allows you to separate data snapshots that are hot, warm, or cold. A data-only bunker can safely store large amounts of data that aren’t needed for immediate use. Check out this post for an example of a tiered bunker architecture you can create with Pure.

Note: You can set the schedules for data retention and deletion, but they must be justified. You must provide adequate reasoning for the schedule and proof you’re following it.

Hacker’s Guide to Ransomware Mitigation and Recovery

Read the Guide

See Also
Retention
How to Create Smart Data Retention and Deletion Policies (1)

Why Have a Data Retention Policy?

One of the biggest compliance missteps I’ve seen companies make is keeping too much data for too long. In many cases, keeping too much data for too long can expose an organization to unnecessary risk. It’s a bright, flashing target for bad actors and compliance officers alike. Not to mention, it can open your organization up to tremendous legal exposure.

General Data Protection Regulation (GDPR) calls this an individual’s “right to be forgotten,” and it essentially means a company can’t hang on to their data when it’s no longer needed for processing. But other regulations, like HIPAA and ISO, can contribute to what should be in your policy, so don’t just stop at GDPR and consult your privacy expert.

The reason for this is that data sitting in archives or graveyards presents more risk for security breaches. If it’s not needed and can be removed, your risk can be substantially lessened.

How to Create (or Improve) a Retention Schedule

First, know that your retention policy should be an integral part of your overall data security strategy. The two are inextricably linked. Start with a security review so that you can align the two. Then, create a data flow map for your organization. Your retention strategy should address data along the flow map, documenting exactly:

  • What types of data are being stored and where—so it can be easily located when it’s time to delete. This includes all traces, such as in backups or file servers.
  • A permission-based framework for all retained data
  • Anonymization and encryption policies that will be used
  • How it’s being processed and why
  • Why it’s being stored—including if there are legal or regulatory reasons for doing so, such as audits or tax reasons, historic or research purposes, etc.
  • When it’s being deleted (or moved) and protocols for deletion or sanitization
  • How you’ll document deletion or anonymization
  • Roles and responsibilities of individuals monitoring compliance and retention

Note: Sensitive personal information can be anonymized, which may preclude your need for retention or deletion of that particular data set. However, if this data paired with another data set can make it identifiable, it will still need to be deleted.

How Pure Storage Can Help Support Data Privacy and Retention Strategies

Coupled with comprehensive organizational security measures, Pure Storage® can help you meet GDPR and other security requirements and data compliance regulations around the world, without adding more complexity.

  • The creation of tiered retained data with secure, data-only bunkers: Given that communication is established into, but not out of, the bunker, it’s considered a highly secure location.
  • Cloud-ready, seamless data mobility: Seamlessly move workloads to support changing business needs, including data sets that no longer have value for processing.
  • Data and backups safe from encryption or deletion: SafeMode™ snapshots protect your data, especially critical backups, from accidental deletion, compromised credentials, or encryption during an attack.
  • Modern data protection: We deliver the most modern data protection solutions, with security and rapid recovery against ransomware threats.
  • A single control pane for visibility: It’s important to have a clear handle on where your most important data lives at any given time. Pure’s simple setup, effortless operations, and unified control pane make it easy to see what workloads are where, so you can move data sets for deletion.

Your first step is to meet with your compliance officer and include your CISO to make sure everyone’s on the same page.

Download the “FlashArray™ Data Security and Compliance” white paper for an in-depth look at how Pure can help your organization.

How to Create Smart Data Retention and Deletion Policies (2024)
Top Articles
3 High-Yield Dividend Stocks You Can Buy With Less Than $100 Right Now | The Motley Fool
Eight Signs You May Have a Scarcity Money Mindset
Koopa Wrapper 1 Point 0
O'reilly's Auto Parts Closest To My Location
Satyaprem Ki Katha review: Kartik Aaryan, Kiara Advani shine in this pure love story on a sensitive subject
Free VIN Decoder Online | Decode any VIN
How Far Is Chattanooga From Here
Goteach11
Back to basics: Understanding the carburetor and fixing it yourself - Hagerty Media
Jasmine
Housing Intranet Unt
Lima Crime Stoppers
Jasmine Put A Ring On It Age
Connexus Outage Map
Nitti Sanitation Holiday Schedule
Elizabethtown Mesothelioma Legal Question
Https://Store-Kronos.kohls.com/Wfc
Enterprise Car Sales Jacksonville Used Cars
Youravon Comcom
Powerball winning numbers for Saturday, Sept. 14. Check tickets for $152 million drawing
How To Cancel Goodnotes Subscription
[Cheryll Glotfelty, Harold Fromm] The Ecocriticism(z-lib.org)
When Does Subway Open And Close
Craig Woolard Net Worth
Barista Breast Expansion
Idle Skilling Ascension
Firefly Festival Logan Iowa
Reserve A Room Ucla
Everything You Need to Know About Ñ in Spanish | FluentU Spanish Blog
Craigs List Tallahassee
Landing Page Winn Dixie
3 Bedroom 1 Bath House For Sale
Salons Open Near Me Today
Craigslist Dallastx
2487872771
Deleted app while troubleshooting recent outage, can I get my devices back?
How to Get Into UCLA: Admissions Stats + Tips
Clark County Ky Busted Newspaper
Asian Grocery Williamsburg Va
Jefferson Parish Dump Wall Blvd
Robeson County Mugshots 2022
Kelley Blue Book Recalls
Updates on removal of DePaul encampment | Press Releases | News | Newsroom
Craigslist Odessa Midland Texas
All Characters in Omega Strikers
Saline Inmate Roster
How to Install JDownloader 2 on Your Synology NAS
300+ Unique Hair Salon Names 2024
SF bay area cars & trucks "chevrolet 50" - craigslist
Zom 100 Mbti
Edict Of Force Poe
2121 Gateway Point
Latest Posts
Article information

Author: Wyatt Volkman LLD

Last Updated:

Views: 5398

Rating: 4.6 / 5 (46 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Wyatt Volkman LLD

Birthday: 1992-02-16

Address: Suite 851 78549 Lubowitz Well, Wardside, TX 98080-8615

Phone: +67618977178100

Job: Manufacturing Director

Hobby: Running, Mountaineering, Inline skating, Writing, Baton twirling, Computer programming, Stone skipping

Introduction: My name is Wyatt Volkman LLD, I am a handsome, rich, comfortable, lively, zealous, graceful, gifted person who loves writing and wants to share my knowledge and understanding with you.