Skip to content

Story 8 — GDPR / Data Retention

Use for: compliance, security, data retention, GDPR, balancing requirements.

Search keywords: GDPR compliance data retention one year ten years backup HR sensitivity labels security

30-second answer

At Dinotronic, we had two different retention requirements: active personal data had a one-year retention policy, while certain legal and financial requirements required backup data to be retained for up to ten years. We separated those requirements instead of applying one policy to everything. We also used sensitivity labels for sensitive data such as HR data. This gave us clear and auditable controls for the different requirements.

STAR answer

Situation

At Dinotronic, we had to deal with two different retention requirements. Active personal data had a one-year retention policy, while certain legal and financial requirements required backup data to be retained for up to ten years.

Task

The challenge was to implement controls that satisfied both requirements without treating them as the same requirement.

Action

For active personal data, we implemented a one-year retention policy.

For sensitive data such as HR data, we also used sensitivity labels to restrict access automatically.

Separately, we maintained the longer retention period for backup data where it was required for legal or financial reasons.

The key was separating the requirements instead of applying one retention policy to everything.

Result

We had clear and auditable controls covering both requirements.

Lesson

When I hear "compliance", I try to identify exactly what data is involved, why it needs to be retained, who needs access, and which regulation or business requirement drives the control.