Control Packs · DAT-004 · v1.0.0
Retention and Deletion Boundary
Require an explicit retention purpose, deletion trigger, and verification path for sensitive data and irreversible deletion.
Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.
What this safeguard addresses
Define purpose, retention trigger, deletion scope, exception handling, and evidence for sensitive data lifecycle operations.
- Sensitive data remains beyond its confirmed purposeRetention or deletion is implicit, incomplete across copies, or impossible to verify without a clear trigger and evidence.
Versioned applicability rule
{
"all": [
{
"characteristic": "SENSITIVE_DATA",
"equals": true
},
{
"characteristic": "IRREVERSIBLE_ACTION",
"equals": true
}
]
}Decisions for the project owner
Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.
- What deletion trigger and verification path applies to this data?The system must not invent a retention period or imply deletion is complete without evidence.DAT-004-Q1 · choice
Requirements for the coding agent
- DAT-004-R1Define retention and deletion triggers, cover replicas and derived copies, record exceptions, and provide evidence for deletion outcomes.
Tests and evidence to retain
- RETENTION_DELETION_TESTVerify retention trigger, deletion across copies, exception handling, retry, and evidence of completion.
- configuration_or_policy
- implementation_location
- test_result
- operational_procedure
Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.
Related guidance
- SI-12 · Information Management and RetentionNIST_SP_800_53_5_2_0 · partially addressesRetention, deletion triggers, replicas, and evidence address a defined lifecycle boundary; they do not cover all information management.
- MP-6 · Media SanitizationNIST_SP_800_53_5_2_0 · informsDeletion across copies informs sanitization considerations; it does not establish media-sanitization compliance.
- PT-5 · Processing Personally Identifiable InformationNIST_SP_800_53_5_2_0 · partially addressesLifecycle triggers and exception handling support controlled PII processing; they do not establish privacy compliance.
Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.
- National Institute of Standards and Technology — Privacy FrameworkGUIDANCE_DATA_MINIMIZATION
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_AUDITABILITY
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_NIST_SP_800_53_5_2_0