OPERATING STANDARD · DATA RETENTION

Keep control records only while their operating purpose remains valid.

This standard assigns retention periods, record owners, deletion behavior, incident holds, backup handling, and review evidence for the current control plane.

Owner
Records Services
Version
1.3
Effective
05 Aug 2026
Review cycle
Annual

1. Principles

  • Collect only fields required for identity, control state, recovery, security, or service operation.
  • Assign a record owner and retention trigger before long-term use.
  • Delete or aggregate records when the purpose ends.
  • Limit holds to a documented scope and review date.
  • Apply equivalent handling to exports and backups.

2. Retention schedule

RecordNormal periodTrigger and disposition
Standard session12-hour absolute; 60-minute idleDelete on logout, idle, or expiry
Remembered session30-day absolute; 60-minute idleDelete on logout, idle, expiry, or session cap
MFA challenge5 minutesRemove on success or expiry pruning
Recovery case90 days after closureDelete unless active investigation requires a hold
Audit event365 daysDelete or archive under restricted access
Operational resourceLife of record plus 90 daysDelete after closure evidence is retained
User settingsLife of identityDelete on deprovisioning
Release backup90 daysDelete after rollback value ends
Security incident evidence365 days after closureReview and delete unless a documented hold applies
Operating commitment

Periods describe the NBS standard. They are not a representation of a third-party provider's retention behavior.

3. Holds

A hold records scope, reason, authority, owner, start time, next review, affected stores, and release decision. A hold does not justify copying unrelated data into the case. When released, the normal retention clock and deletion process resume.

4. Deletion and verification

Deletion is performed through the owning data path or an approved administrative process. Evidence records the class, scope, decision, execution time, result, and reviewer without reproducing deleted content. Session deletion is immediate at the application layer; backup expiry follows the backup schedule.

5. Exports and backups

An exported audit file or database backup inherits the classification, access restriction, and remaining retention period of the source. Exporting does not restart the retention clock. Temporary working copies are removed as soon as the review or recovery task ends.

6. Exceptions

Exceptions require the record class, business need, additional period, risk, compensating protection, owner, approval, expiry, and closure evidence. Indefinite exceptions are not permitted.