OPERATING STANDARD · DATA RETENTION
Keep control records only while their operating purpose remains valid.
This standard assigns retention periods, record owners, deletion behavior, incident holds, backup handling, and review evidence for the current control plane.
1. Principles
- Collect only fields required for identity, control state, recovery, security, or service operation.
- Assign a record owner and retention trigger before long-term use.
- Delete or aggregate records when the purpose ends.
- Limit holds to a documented scope and review date.
- Apply equivalent handling to exports and backups.
2. Retention schedule
| Record | Normal period | Trigger and disposition |
|---|---|---|
| Standard session | 12-hour absolute; 60-minute idle | Delete on logout, idle, or expiry |
| Remembered session | 30-day absolute; 60-minute idle | Delete on logout, idle, expiry, or session cap |
| MFA challenge | 5 minutes | Remove on success or expiry pruning |
| Recovery case | 90 days after closure | Delete unless active investigation requires a hold |
| Audit event | 365 days | Delete or archive under restricted access |
| Operational resource | Life of record plus 90 days | Delete after closure evidence is retained |
| User settings | Life of identity | Delete on deprovisioning |
| Release backup | 90 days | Delete after rollback value ends |
| Security incident evidence | 365 days after closure | Review and delete unless a documented hold applies |
Periods describe the NBS standard. They are not a representation of a third-party provider's retention behavior.
3. Holds
A hold records scope, reason, authority, owner, start time, next review, affected stores, and release decision. A hold does not justify copying unrelated data into the case. When released, the normal retention clock and deletion process resume.
4. Deletion and verification
Deletion is performed through the owning data path or an approved administrative process. Evidence records the class, scope, decision, execution time, result, and reviewer without reproducing deleted content. Session deletion is immediate at the application layer; backup expiry follows the backup schedule.
5. Exports and backups
An exported audit file or database backup inherits the classification, access restriction, and remaining retention period of the source. Exporting does not restart the retention clock. Temporary working copies are removed as soon as the review or recovery task ends.
6. Exceptions
Exceptions require the record class, business need, additional period, risk, compensating protection, owner, approval, expiry, and closure evidence. Indefinite exceptions are not permitted.
Operational