Skip to content

Data Retention

What is Data Retention?

The policies and practices governing how long an organisation keeps personal data. Privacy regulations require that personal data is not kept longer than necessary for the purpose for which it was collected.

Privacy

Each of these is named in at least one of the same controls as data retention. The number is how many controls name both.

What the standards actually require on data retention

Requirements naming data retention across 6 standards, quoted from the control text.

CIS Controls v82 controls

Retain data according to the enterprise’s data management process. Data retention must include both minimum and maximum timelines.

CIS-3.4 · Enforce Data Retention

Although the PPL does not impose a single retention period, the use-limitation principle (s.2 and s.8(b)) requires that information be kept only as long as necessary for the registered purpose.

PPL-DSR-RETAIN · Data Retention and Disposal

Retain data according to the enterprise data management process. Data retention must include both minimum and maximum timelines.

3.4 · Enforce Data Retention

Retain data according to the enterprise data management process. Data retention must include both minimum and maximum timelines.

3.4 · Enforce Data Retention
COPPA1 control

An operator may retain personal information collected from a child only for as long as reasonably necessary to fulfil the specific purpose for which it was collected, and must then delete it using reasonable measures to protect against unauthorised access duri...

COPPA-312.10 · Data Retention and Deletion (Written Retention Policy)

Manage data retention, archiving and deletion against business requirements and applicable law, so data is neither kept longer nor destroyed sooner than allowed.

CCM-DSP-16 · Data Retention and Deletion

Questions people ask about data retention

What is Data Retention?
The policies and practices governing how long an organisation keeps personal data. Privacy regulations require that personal data is not kept longer than necessary for the purpose for which it was collected.
Why is Data Retention important for compliance?
Data Retention is a key concept in Privacy. Understanding data retention helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Data Retention?
Data Retention appears in the requirement text of CIS Controls v8, Israel Protection of Privacy Law (5741-1981), NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements, BRCGS Global Standard for Food Safety Issue 9, COPPA. Across these standards we have identified 9 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Data Retention?
Explore our compliance framework pages to see how data retention applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Data Retention applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.