Organization needs to make sure information is deleted when it's no longer needed from systems, devices, or storage. This helps protect sensitive data and meets legal, regulatory, and contract rules for information removal. When third parties store an organization's information, the organization should incorporate information deletion requirements into agreements, ensuring enforcement during and after service termination.
Limiting the retention time is one of the principles of the processing of personal data. If the retention period of the data is not provided by law, when determining the retention periods, the following must be taken into account, for example:
Describe your own process for evaluating retention periods.
Organization must document the retention periods for data sets and their possible archiving process (including archiving method, location or destruction). At the end of the retention period, the data must be archived or destroyed without delay in a secure manner.
When destroying data contained in data systems, the following points should be taken into account:
The process of archiving or destroying data is defined in connection with the documentation, and the owner of the data is responsible for its implementation.