Regulated organisations can have legitimate reasons to retain information for defined periods. At the same time, privacy governance introduces expectations around purpose, retention and deletion.
The governance problem
A single "delete everything after X days" rule is rarely enough. Retention should be mapped to purpose, data category, legal or regulatory obligations and documented exceptions.
A practical model
- Create a data inventory and purpose map.
- Define retention rules by category and obligation.
- Document lawful retention exceptions.
- Separate active data from restricted or legally retained data.
- Maintain evidence for why retention continued.
The goal
The goal is a defensible governance model where retention and privacy decisions are intentional, documented and auditable.

