Data Retention and Disposal Policy template (SOC 2)

Defines how long each category of data is kept and how data, media and devices are securely disposed of when they are no longer needed.

Policy P07 of 22 · Owner: Security Owner · 3 criteria in the crosswalk · Apache-2.0

What this policy is for

The Data Retention and Disposal Policy is one of the 22 governance policies in the Policyseed set. It is owned by the Security Owner, approved by the executive you name in the intake, and reviewed on the cadence you choose. Like every policy in the set it has nine numbered sections: purpose, scope, roles, policy statements, procedures, exceptions, enforcement, review cadence and a revision history table. Sections 4 and 5 carry the substance; those are the sections the Audit Kit rewrites for your named tools.

SOC 2 criteria this policy addresses

The Policyseed crosswalk maps 3 criteria to this policy. Each row names the section an auditor would read for that criterion; the criterion pages explain what it asks in plain words and list evidence examples.

CriterionWhat it coversWhere in this policy
CC6.5Disposal of physical assetsSection 5 (Procedures)
C1.1Identifying and protecting confidential informationSection 4 (Policy Statements)
C1.2Disposing of confidential informationSection 5 (Procedures)

Evidence auditors typically ask for

A policy is tested against artifacts. These are examples from the crosswalk for the criteria above, written for a small SaaS company; the Audit Kit ships the full list as an evidence checklist with an owner per row.

  • MDM remote-wipe confirmation for laptops returned by leavers in the period
  • Asset inventory entries marked disposed with the wipe date and method
  • Certificate of destruction from the recycling or ITAD vendor, where used
  • Data classification matrix listing the classification levels and handling rules for each
  • Data inventory or data map showing where confidential and personal data is stored
  • Retention schedule listing each data category and its retention period
  • Sample customer contract confidentiality clause
  • Customer offboarding or deletion request records with completion dates

Full text: the Data Retention and Disposal Policy rendered for Northwind Cloud Inc

Below is the complete template as the generator renders it for Northwind Cloud Inc, a fictional 11-50-person remote company running Northwind on AWS, Vercel, GitHub and Okta. Every name, tool and date comes from that sample intake; your answers replace them. Section headings carry anchors so the criterion pages can link straight to the section they cite.

Sample document

Northwind Cloud Inc Data Retention and Disposal Policy

1. Purpose

This policy establishes how long Northwind Cloud Inc retains each category of data it creates, receives or processes while operating Northwind, and how that data is destroyed when it is no longer needed. Keeping data longer than necessary increases breach impact, storage cost and legal exposure; deleting it too early can breach contracts, tax law or employment law. A written retention schedule, automated deletion and disposal methods that render data unrecoverable resolve that tension and support the SOC 2 criteria for disposal of data and physical assets and for destruction of confidential information.

2. Scope

This policy applies to all data regardless of format or location: production databases and object storage on AWS and Vercel, backups and snapshots in AWS Backup, logs in Datadog, source code and build artifacts in GitHub and GitHub Actions, email and collaboration tools, SaaS vendor systems including Supabase, Stripe, Datadog and Slack, laptops and mobile devices, removable media and paper records. It applies with particular force to the PII data that Northwind Cloud Inc handles. It binds all employees and contractors and covers data held for customers as well as Northwind Cloud Inc's own records. Where a customer agreement or law requires a different retention period, that requirement prevails and the schedule in Section 5 records it.

3. Roles and Responsibilities

  • Executive Management approves this policy, funds retention automation, authorizes legal holds and resolves conflicts between business needs and retention limits.
  • Security Owner (Dana Whitfield, CTO) owns the retention schedule, approves disposal of Confidential and Restricted data, maintains the disposal log and legal-hold register, runs the quarterly retention audit and reports results at each policy review.
  • Engineering implements retention in Northwind through lifecycle rules, time-to-live settings and deletion jobs, executes customer deletion requests, decommissions cloud resources and verifies that backups expire on schedule.
  • People Operations retains employment, recruiting and training records per the schedule, coordinates return and wiping of equipment at offboarding, and confirms departing personnel have kept no company data.
  • All Personnel store company data only in approved systems, keep no personal copies or exports, and follow the disposal procedures for any data or media they handle.

4. Policy Statements

  • 4.1 Northwind Cloud Inc maintains a written retention schedule (Section 5.1) listing each data category, its system of record, retention period and disposal method. Data is kept no longer than its business purpose, contractual commitment or legal obligation requires, whichever is longest, and is disposed of promptly afterwards.
  • 4.2 Personnel collect and keep only data needed for a defined purpose. New data collection in Northwind must have an owner, a classification under the Data Classification and Handling Policy and a retention period before release.
  • 4.3 Customer data in Northwind is retained for the term of the customer agreement and deleted within 30 days after termination or after a verified written deletion request, unless a legal hold applies. Northwind Cloud Inc confirms deletion in writing on request.
  • 4.4 Backups follow the Daily schedule in the Backup and Recovery Policy and expire automatically no later than 35 days after creation through AWS Backup lifecycle settings. Deleted production data is fully purged once the last backup containing it expires; personnel do not restore backups to circumvent a deletion.
  • 4.5 Security and audit logs are retained for 12 months and application debug logs for 30 days, consistent with the Logging and Monitoring Policy, unless a legal hold or documented investigation requires longer.
  • 4.6 Data subject to specific legal or regulatory retention rules follows those rules, which take precedence over the general schedule. Personal data is retained only as described in the privacy notices given to individuals, and verified deletion requests are fulfilled within 30 days.
  • 4.7 Electronic data is disposed of by cryptographic erasure, provider-level deletion followed by expiry of associated snapshots, or overwriting, so that it cannot be reconstructed with commercially reasonable effort. Media leaving Northwind Cloud Inc's control is purged or destroyed per NIST SP 800-88 Rev. 1; paper is cross-cut shredded.
  • 4.8 Laptops and mobile devices are fully erased before reassignment, return, sale or recycling using the remote erase function in Kandji. Because all devices use full-disk encryption under the Endpoint and Workstation Security Policy, destroying the device encryption key is an acceptable disposal method.
  • 4.9 A legal hold suspends every deletion that would otherwise apply to the data it covers. Only Executive Management, on advice of counsel, initiates or releases a hold; the Security Owner records each hold, its scope and its release in the legal-hold register.
  • 4.10 Vendors that process Northwind Cloud Inc or customer data must be contractually obliged to delete or return it within 90 days after the service ends and to confirm deletion on request. This is verified during vendor reviews for Supabase, Stripe, Datadog and Slack.
  • 4.11 Personnel may not keep company or customer data in personal email, personal cloud storage, personal devices or removable media. Bulk exports of customer data require a documented reason and Security Owner approval and are deleted once their purpose is served.
  • 4.12 Disposal of Confidential or Restricted data and of hardware that has held company data is recorded in the disposal log with date, method, performer and verifier.

5. Procedures

  • 5.1 Retention schedule. Customer data in Northwind: agreement term plus 30 days; system of record is the production databases and object storage on AWS and Vercel; disposal by application deletion job and provider API. Backups and snapshots: 35 days rolling, automatic expiry. Security and audit logs: 12 months; application debug logs: 30 days. Source code: indefinitely in GitHub; build artifacts and CI logs in GitHub Actions: 90 days. Employment records: 7 years after employment ends, or longer where law requires. Unsuccessful candidate records: 12 months. Financial, tax and payroll records: 7 years. Contracts and vendor records: term plus 7 years. Support tickets: 3 years after closure. Incident records, risk assessments, access reviews, policy approvals and audit evidence: 7 years. Product analytics and marketing data: 24 months.
  • 5.2 Automated deletion. Engineering configures lifecycle rules, time-to-live settings or scheduled deletion jobs for each category and documents them alongside the schedule; changes follow the Change Management Policy. Each quarter Engineering confirms every rule is present and executed successfully and attaches the evidence to the retention audit.
  • 5.3 Customer deletion requests. Requests arriving through support or security@northwindcloud.example are verified as coming from an authorized customer representative, ticketed and assigned to Engineering, which deletes the data from production within 30 days and confirms no copies remain in non-production environments. Support confirms deletion to the customer in writing.
  • 5.4 Customer offboarding. When an agreement ends, the account enters a read-only export state for 30 days, after which the deletion procedure in 5.3 runs. Where sub-processors such as Supabase, Stripe, Datadog and Slack hold the customer's data, Engineering triggers deletion in each within the same window and records the confirmation.
  • 5.5 Device disposal. People Operations collects devices at offboarding or replacement and records receipt in the asset register. Engineering issues a remote erase through Kandji and retains the completion record. Devices leaving the company go to a certified recycler whose certificate of destruction is attached to the asset record.
  • 5.6 Cloud decommissioning. When a service, environment or account on AWS and Vercel is retired, Engineering completes a checklist: delete volumes and buckets, expire snapshots and backups, revoke credentials and keys, remove DNS and monitoring, and update the asset inventory. The checklist is attached to the change record.
  • 5.7 Legal hold. Executive Management notifies the Security Owner in writing of the matter, custodians and data categories. Within two business days the Security Owner suspends the relevant automated deletions, instructs custodians in writing, records the hold in the register and reviews it quarterly until Executive Management releases it in writing.
  • 5.8 Quarterly retention audit. The Security Owner samples each category, confirms the oldest records do not exceed their retention period, checks the disposal log for completeness and records the results. Findings become issues with a 30-day remediation deadline and are reported to Executive Management.
  • 5.9 Paper and removable media. Paper holding Confidential or Restricted data is kept in locked cabinets and destroyed by cross-cut shredder or locked shredding bin. Removable media is prohibited for company data except with Security Owner approval; approved media is encrypted and destroyed after use, and the destruction is logged.
  • 5.10 Schedule review. At each annual policy review the Security Owner checks the schedule against new customer commitments, changes in law and new data categories in Northwind, and updates the schedule and automation.

6. Exceptions

Exceptions require a written request describing the data, the business justification, the proposed retention period or disposal method and the compensating controls. The Security Owner approves or rejects it; exceptions involving customer data or a period longer than the schedule also require Executive Management approval. Approved exceptions are recorded in the exception register, expire after no more than 12 months unless renewed, and are reviewed at each policy review.

7. Enforcement

Violations of this policy are handled under the Human Resources Security Policy and may result in disciplinary action up to and including termination of employment; contractors and vendors are subject to contract termination. Unauthorized retention, export or disposal of data is treated as a security incident and reported to security@northwindcloud.example under the Incident Response Policy.

8. Review Cadence

The Security Owner reviews this policy on the annual review cycle and after any significant change to Northwind Cloud Inc's systems, vendors, customer commitments or applicable law, and after any incident involving improper retention or disposal. Changes are approved by Priya Natarajan, CEO and recorded in the revision history.

9. Revision History

VersionDateDescriptionApproved by
1.02026-09-02Initial releasePriya Natarajan, CEO

Frequently asked questions

Who should own the Data Retention and Disposal Policy?
In the Policyseed template the Security Owner owns the Data Retention and Disposal Policy: they maintain the text, run the procedures in section 5 and hold the evidence those procedures produce. The approver you name in the intake signs it, and section 8 sets the review cadence you choose (annual, semi-annual or quarterly).
Which SOC 2 criteria does the Data Retention and Disposal Policy address?
3 criteria in the Policyseed crosswalk: CC6.5 (Disposal of physical assets), C1.1 (Identifying and protecting confidential information) and C1.2 (Disposing of confidential information). Each mapping points at a numbered section of this policy, and the Audit Kit exports the same mapping as an Excel crosswalk with an evidence checklist.
Is the Data Retention and Disposal Policy template free to use?
Yes. The template is Apache-2.0 licensed and the generator renders it in your browser with your company, stack and owner names filled in; nothing is stored server-side. The Audit Kit ($39 one-time) rewrites sections 4 and 5 for your named tools with Claude and adds Word documents, the crosswalk spreadsheet, acknowledgment forms and a review calendar. Refunds are available within 14 days on request. Policyseed provides governance policy templates, not legal advice; the CPA firm performs the examination.

Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.