Story 8 — GDPR / Data Retention
Use for: compliance, security, data retention, GDPR, balancing requirements.
Search keywords: GDPR compliance data retention one year ten years backup HR sensitivity labels security
30-second answer
At Dinotronic, we had two different retention requirements: active personal data had a one-year retention policy, while certain legal and financial requirements required backup data to be retained for up to ten years. We separated those requirements instead of applying one policy to everything. We also used sensitivity labels for sensitive data such as HR data. This gave us clear and auditable controls for the different requirements.
STAR answer
Situation
At Dinotronic, we had to deal with two different retention requirements. Active personal data had a one-year retention policy, while certain legal and financial requirements required backup data to be retained for up to ten years.
Task
The challenge was to implement controls that satisfied both requirements without treating them as the same requirement.
Action
For active personal data, we implemented a one-year retention policy.
For sensitive data such as HR data, we also used sensitivity labels to restrict access automatically.
Separately, we maintained the longer retention period for backup data where it was required for legal or financial reasons.
The key was separating the requirements instead of applying one retention policy to everything.
Result
We had clear and auditable controls covering both requirements.
Lesson
When I hear "compliance", I try to identify exactly what data is involved, why it needs to be retained, who needs access, and which regulation or business requirement drives the control.