---
name: data-retention-and-restore
description: "Contents, backups, retention, deletion path, and a proven restore per data store. Use when adding or changing a store of user data."
---

# Data Retention And Restore

**Produce one entry per data store.** A store is anything that keeps data
after the request ends: a database, a file bucket, a cache with a long
lifetime, a log archive, a spreadsheet export, a third-party service. Each
entry states:

- what it holds, listing every field that identifies a person;
- how often it is backed up, and where the backup is kept;
- how long the data is kept before it is deleted;
- the steps that execute one person's deletion request.

**Translate the retention question before you ask it.** State the choice in
the owner's world, propose a default, name the consequence of the default, and
record the answer as the owner's decision. Ask "how long do you keep a booking
after the appointment?", not "what is your retention policy?".

**Give backups and derived copies their own retention.** A backup, an export,
a log line and a search index each carry the retention of the store they came
from unless the entry states otherwise `[ASSUMPTION]`. Otherwise deleted data
returns from a copy nobody listed.

**Make the deletion path reach every copy.** Write the steps in order, name
who may run them, and name the copies each step clears. State how the operator
confirms the data is gone and how long the path takes.

**Restore into a throwaway environment.** Do it at least once every 90 days
`[ASSUMPTION A-8]`. Write down the date, how long the restore took, and a
verified record count compared against the source. A backup that has never
been restored is an untested file.

**A reviewer checks:**

- no store is missing a retention period, including backups, exports and logs;
- a restore into a throwaway environment happened within the last 90 days,
  with its duration and a verified record count written down;
- the deletion path is written as executable steps and names every copy;
- every field that identifies a person is listed in the entry that holds it;
- the retention decision is recorded as the owner's, with the date.
