Privacy
Data retention
Also called retention window.
Data retention is how long you keep identifiers and records before deleting or aggregating them. GDPR calls the principle storage limitation.
How it is measured
Set a period per data type: raw hit rows, user IDs, support emails, backups. State the clock start, such as last activity or account closure. Run a job that deletes past the period and check its output.
Verify by querying for the oldest record of each type. If anything is older than its stated period, the job is failing.
Worked example
An online course site keeps raw event rows for 14 months, then reduces them to daily totals. A query shows the oldest raw row dated 16 months ago, so the delete job has been skipping a table.
After the fix, 2.1 million stale rows are removed in one night.
How it differs
Data retention limits time. Data residency limits place. Retention excludes where the data sits; residency excludes when it must go.
Common errors
Keeping everything forever. Setting a period and never enforcing it. Forgetting backups. Having different periods in the notice and in the system. Counting from the wrong start date.
In practice
Pick a period for each data type this week. Add a deletion job. Check it with a query.