Data retention
Keeping data for a defined period set by legal, regulatory and business requirements, then disposing of it securely, as documented in a retention policy and schedule.
Data retention means holding data for as long as it is needed and then disposing of it. A retention policy states the organisation’s rules, and a retention schedule applies them to specific record types, giving each a period and a trigger such as account closure. Periods come from statutes that set minimums for tax or employment records, from regulators, contracts and business need, and from privacy law, which sets a ceiling. For personal data, the storage limitation principle in GDPR Article 5(1)(e) is that ceiling.
Retention pulls in two directions. Keeping data too briefly can breach record-keeping laws; keeping it too long increases breach exposure, discovery cost and privacy risk. A legal hold suspends the schedule for data relevant to litigation or an investigation, and destroying held data can amount to spoliation. When the period ends, defensible disposal and media sanitisation complete the data lifecycle. Asset retention is a separate objective, 2.5, in the ISC2 outline.
Exam relevance: data retention appears by name under objective 2.4 of the ISC2 outline. A scenario is likely to set a legal requirement against a wish to delete, or a litigation hold against a routine purge. Candidates are expected to recognise that the documented schedule, adjusted by any legal hold, tends to decide.