Control Packs · DAT-004 · v1.0.0

Retention and Deletion Boundary

Require an explicit retention purpose, deletion trigger, and verification path for sensitive data and irreversible deletion.

Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.

What this safeguard addresses

Define purpose, retention trigger, deletion scope, exception handling, and evidence for sensitive data lifecycle operations.

  • Sensitive data remains beyond its confirmed purposeRetention or deletion is implicit, incomplete across copies, or impossible to verify without a clear trigger and evidence.
Versioned applicability rule
{
  "all": [
    {
      "characteristic": "SENSITIVE_DATA",
      "equals": true
    },
    {
      "characteristic": "IRREVERSIBLE_ACTION",
      "equals": true
    }
  ]
}

Decisions for the project owner

Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.

  • What deletion trigger and verification path applies to this data?The system must not invent a retention period or imply deletion is complete without evidence.DAT-004-Q1 · choice

Requirements for the coding agent

  • DAT-004-R1Define retention and deletion triggers, cover replicas and derived copies, record exceptions, and provide evidence for deletion outcomes.

Tests and evidence to retain

  • RETENTION_DELETION_TESTVerify retention trigger, deletion across copies, exception handling, retry, and evidence of completion.
  • configuration_or_policy
  • implementation_location
  • test_result
  • operational_procedure

Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.

Related guidance

  • SI-12 · Information Management and RetentionNIST_SP_800_53_5_2_0 · partially addressesRetention, deletion triggers, replicas, and evidence address a defined lifecycle boundary; they do not cover all information management.
  • MP-6 · Media SanitizationNIST_SP_800_53_5_2_0 · informsDeletion across copies informs sanitization considerations; it does not establish media-sanitization compliance.
  • PT-5 · Processing Personally Identifiable InformationNIST_SP_800_53_5_2_0 · partially addressesLifecycle triggers and exception handling support controlled PII processing; they do not establish privacy compliance.

Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.

Continue your review