Data Retention Policy Skill
Define data retention policy for {{ system_name }} under {{ data_jurisdiction }} jurisdiction.
Workflow
Phase 1 — Data Inventory
DATA CATALOG
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
[ ] Data stores identified:
Store | Type | Size | Contains PII
___________________|___________|________|_____________
| | |
| | |
| | |
[ ] Data categories:
[ ] Customer personal data (PII)
[ ] Financial/transaction data
[ ] Authentication/access logs
[ ] Application logs
[ ] Analytics/telemetry data
[ ] User-generated content
[ ] Backup/archive data
[ ] Temporary/cache data
Phase 2 — Regulatory Requirements
REGULATORY MAPPING
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Jurisdiction: {{ data_jurisdiction }}
Regulation | Data Type | Min Retention | Max Retention
____________________|____________________|_______________|______________
GDPR (Art. 5(1)(e))| Personal data | N/A | Purpose-limited
GDPR (Art. 17) | Subject to erasure | N/A | Upon request
CCPA | Consumer data | N/A | Purpose-limited
PCI DSS | Cardholder data | N/A | Business need
SOX | Financial records | 7 years | N/A
HIPAA | Health records | 6 years | N/A
Tax regulations | Tax records | ___ years | N/A
[ ] Legal review completed: [ ] YES — date: ___
[ ] Conflicts between regulations resolved: [ ] YES
Phase 3 — Retention Schedule
RETENTION PERIODS
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Data Category | Active | Archive | Delete After | Legal Hold
________________________|_________|_________|______________|___________
Customer PII | | | |
Transaction records | | | |
Access/auth logs | | | |
Application logs | | | |
Analytics data | | | |
User content | | | |
Backups | | | |
Temp/cache | | | |
LIFECYCLE STAGES
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Active: Hot storage, full access
Archive: Cold storage, restricted access, compressed
Delete: Permanent removal, verified destruction
Legal Hold: Suspended deletion, preserved for litigation
Phase 4 — Implementation
AUTOMATION SETUP
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
[ ] Automated lifecycle policies configured:
[ ] S3 lifecycle rules
[ ] Database TTL / partitioned deletion
[ ] Log management retention policies
[ ] Backup rotation policies
[ ] Deletion mechanism:
[ ] Soft delete (tombstone, recoverable for ___ days)
[ ] Hard delete (permanent, verified)
[ ] Crypto-shredding (for encrypted data)
[ ] Deletion verification:
[ ] Deletion logs maintained
[ ] Spot checks scheduled
[ ] Audit trail preserved (metadata only, not content)
Phase 5 — Policy Documentation and Review
GOVERNANCE
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
[ ] Policy document published
[ ] Data owners acknowledged policy
[ ] Exception process defined:
- Request template available
- Approval chain: ___
[ ] Legal hold process documented
[ ] Data subject request (DSR) process integrated
[ ] Review cycle: {{ review_cycle }}
[ ] Next review date: ___
[ ] Policy version: ___
Counter-Rationalizations
| Shortcut | Counter | Why |
|---|---|---|
| "We can skip some steps for this case" | Adapt the workflow steps, don't skip them | Skipped steps are where incidents and oversights originate |
| "The user seems to already know what to do" | Complete all workflow phases with the user | The workflow catches blind spots that experience alone misses |
| "This is a minor case, full process is overkill" | Scale the process down, don't turn it off | Minor cases become major when unstructured; the process scales, not disappears |
| "I'll fill in the details later" | Complete each section before moving on | Deferred details are forgotten; real-time capture is more accurate |
| "The template output isn't necessary" | Always produce the structured output format | Structured output enables comparison, audit trails, and handoff to other teams |
Output Format
Produce a data retention policy document with:
- Data inventory (categories, stores, classifications)
- Regulatory requirements (applicable regulations, retention mandates)
- Retention schedule (periods by data category with lifecycle stages)
- Implementation plan (automation, deletion mechanisms, verification)
- Governance (review cycle, exceptions, legal hold procedures)