Governance & Compliance · Data artifact
Personal Data Retention Policy
Data artifactGovernance & ComplianceSafety, Security & Governancearc:PersonalDataRetentionPolicy
A policy stating, per personal-data category, how long data is kept for its purpose or legal obligation and when it must be deleted.
Responsibility. Defines storage limits and legal-retention exceptions for personal data.
Also known as: Retention schedule, Storage limitation policy
Relationships
is configured by structural
is read by dependency
constrains control
Design guidance
- MUST distinguish data requiring retention for legal compliance from data to delete when its purpose ends.
Quantitative guidance
As stated by the sources; verify before use.
- Tax records retained seven years post-employment; performance reviews, training records and internal communications deleted after employment ends (Ch9.7 HR).
- Health-claims data retained seven years for regulatory compliance (Ch9.7 DPIA).
- Diagnostic images deleted seven years post-procedure (Ch9.7 hospital).
- Chat logs 30 days, error logs 30 days, audit logs 90 days, analytics 12 months, payment info 7 years, user profile for account lifetime (Ref9.05 example).
Classification
- Patterns
- Storage limitation
- Quality attributes
- Transparency and accountability (NIST AI RMF: accountable and transparent)
- Risks mitigated
- Accumulation of historical personal data serving no purpose
- Frameworks & regulations
- GDPR Art. 5(1)(e)
Sources
- Ch9.7: T. Nguyen, "GDPR and Data Protection Regulations," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.7. ISBN: 9798244538229.
- Ref9.05: "Privacy and Data Protection for AI Systems," unpublished reference note (references/Chapter 9 - Safety, Ethics, and Compliance/05-Privacy-Data-Protection.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note