# Data retention and disposal policy

Source: https://aestech.com.au/policy-templates/#data-retention-and-disposal-policy
Markdown URL: https://aestech.com.au/policy-templates/data-retention-and-disposal-policy.md

Use for ISO 27001 A.5.33, A.5.34, A.8.10, SOC 2 Confidentiality and Privacy, and PCI DSS requirement 3.

Frameworks: ISO 27001, SOC 2, PCI DSS

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines how long records and data are kept, how they are securely disposed of when no longer required, and how the company meets legal, contractual and regulatory retention obligations. It limits the volume of data held to what is necessary, reducing risk and audit scope.

2. Scope
This policy applies to all company and customer information in any format, including production databases, backups, file storage, email, paper records, removable media and data held by suppliers on the company behalf. It applies to all employees, contractors and service accounts.

3. Policy statements
- Every category of data must have a defined retention period recorded in the retention schedule.
- Data must not be kept longer than the retention period unless there is a legal hold, active investigation or documented business need approved by the data owner.
- Personal and regulated data must be retained only for as long as the lawful purpose requires.
- Cardholder data must be kept to the minimum required and deleted when no longer needed for a documented legal, regulatory or business reason.
- When a retention period ends, data must be deleted, anonymised or destroyed using approved methods.
- Electronic media must be sanitised or destroyed before reuse, return or disposal so that data cannot be recovered.
- Paper records must be shredded or disposed of through an approved secure destruction service.
- Suppliers holding company data must delete or return it on contract termination and on request.
- Legal holds override scheduled deletion until the hold is formally released.

4. Roles and responsibilities
- The [Data Protection Lead] owns the retention schedule and approves changes.
- Data owners confirm retention periods for their data categories and authorise exceptions.
- IT and system administrators implement deletion and media sanitisation.
- Legal advises on retention obligations and issues or releases legal holds.
- All staff follow the schedule and do not retain copies of data outside approved systems.

5. Procedures
- Maintain a retention schedule listing data category, owner, system, retention period, legal basis and disposal method.
- Review the retention schedule at least annually and after legal or product changes.
- Run scheduled or periodic deletion jobs for data that has reached end of retention.
- Sanitise media using cryptographic erasure, secure wipe or physical destruction, and record the method.
- Issue a certificate of destruction for physical media and bulk destruction events.
- Apply and track legal holds through [legal hold register].

6. Evidence and records
Keep the retention schedule, deletion job logs, media sanitisation and destruction records, certificates of destruction, legal hold register, supplier deletion confirmations and exception approvals.

7. Review cadence
This policy is reviewed at least annually and after material changes to legal, regulatory or contractual retention obligations.

Owner: [role]
Version: [x.y]   Approved by: [name/role]   Date: [date]
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md