Data Retention Policy

👤 mohitagw15856 📦 v1.0.0 ⭐ 4.2 ⬇️ 149 下载
💼 行业专业 免费

📖 技能介绍


name: data-retention-policy description: "Build a data retention and deletion schedule grounded in legal basis. Use when asked to create a data retention policy, set retention periods, plan data deletion/minimisation, or answer 'how long can we keep this data?'. Produces a retention schedule — data categories with their retention period, legal/business basis, deletion trigger and method, plus flags for data kept with no basis or no defined period." homepage: https://mohitagw15856.github.io/pm-claude-skills/skill/data-retention-policy.html metadata: { "openclaw": { "emoji": "📋" } }


Data Retention Policy Skill

"Keep everything forever" is a liability, not a strategy — it grows breach exposure, violates data- minimisation rules (GDPR, CCPA), and turns every data subject request into an archaeology project. This skill builds a retention schedule that ties each data category to how long you keep it and why (legal basis), with a concrete deletion trigger — so retention is a defensible policy, not an accident.

Required Inputs

Ask for these only if they aren't already provided:

  • Data categories — the kinds of data you hold (customer records, logs, financial, HR, marketing, backups).
  • Legal/regulatory drivers — anything mandating minimum retention (tax/financial records, employment law) or maximum (GDPR minimisation, sector rules).
  • Business need — why each category is genuinely needed and for how long.
  • Where it lives — systems and backups (backups are the most-forgotten place data outlives its policy).

Output Format

Data Retention Schedule: [organisation]

1. Schedule — the core table, one row per data category:

Data category Retention period Basis (legal/business) Deletion trigger Method System(s)
Customer PII 3y after account closure Legitimate interest + GDPR minimisation Account closed + 3y Hard delete App DB, backups
Financial records 7y Tax law (statutory minimum) End of fiscal year + 7y Archive then delete Finance system

2. Principles — the policy stance: minimise by default, the shortest period that satisfies the basis, and that retention applies to backups and logs too.

3. Deletion mechanics — how deletion actually happens (automated job vs. manual), how it cascades to backups, and how it's evidenced.

4. Flags — categories with no defined period or no legal/business basis (these are the risk — data you can't justify keeping).

Programmatic Helper

scripts/retention_schedule.py (stdlib only) validates a schedule and flags categories missing a period or a basis, and (given a closure/event date) computes the earliest deletion date:

# data.json: [{"category":"Customer PII","retention_months":36,"basis":"GDPR minimisation","event_date":"2024-01-15"}, ...]
python3 scripts/retention_schedule.py data.json
python3 scripts/retention_schedule.py data.json --json

Quality Checks

  • [ ] Every category has both a retention period and a documented basis
  • [ ] Periods default to the shortest that satisfies the legal/business need (minimisation), not "indefinite"
  • [ ] Backups and logs are covered, not just the primary store
  • [ ] Each category has a concrete deletion trigger and method, not just a duration
  • [ ] Statutory minimums (tax, employment) and maximums (minimisation) are both respected

Anti-Patterns

  • [ ] Do not set retention to "indefinite" or leave it blank — undefined retention is the highest-risk, least-defensible state
  • [ ] Do not forget backups — data deleted from production that lives on in backups is still data you hold
  • [ ] Do not keep data with no legal or business basis — if you can't justify it, deleting it lowers risk for free

    小葱技能7w4.net有完整的技能分类。

  • [ ] Do not set a blanket period for all data — tax records and marketing emails have very different drivers
  • [ ] Do not present statutory periods as advice — flag where legal/compliance must confirm the minimums

Based On

Data-minimisation practice — GDPR Art. 5(1)(e) storage limitation, sector retention statutes, and defensible-deletion principles.

🤖 AI 评测

这是一份专注于数据保留策略的专业技能文档,整体质量良好。优势在于框架完整、逻辑清晰,能帮助用户快速建立数据保留和删除的合规思维,并提供了实用的质量检查清单。需要注意的不足是:文档中提到的验证脚本实际上缺失,可能影响实际使用;另外内容较为通用,缺乏针对不同行业的具体示例。普通用户使用时需结合自身业务场景和法规要求进行调整。

📊 多维度评分

适应性4.4
规范性4.2
有效性4.4
可靠性3.7
可信度4.2

📁 包含文件 (3 个)

📄 SKILL.md 4.1 KB
📄 _meta.json 140 B
📄 skill-card.md 2.2 KB