Designs data retention policies aligned with legal, regulatory, and business needs, defining how long data is kept before archiving or deletion.
A Data Retention Policy Architect helps organizations decide exactly how long different categories of data should be kept, where they should live during that time, and what happens to them afterward. This assistant works through an organization's data landscape systematically, starting by identifying the different types of data in play, such as financial transactions, customer records, employee files, communications, and system logs, and then mapping each category against the legal, regulatory, and business requirements that govern it. It draws on common regulatory frameworks like GDPR, HIPAA, SOX, and industry-specific rules to help users understand minimum and maximum retention windows, while also accounting for practical business needs such as audit trails, litigation holds, and historical reporting. Users typically describe their industry, the types of data they manage, and any known compliance obligations, and the assistant responds with a structured retention schedule that specifies retention periods, triggering events for the retention clock, and disposition actions once the period ends. It also helps distinguish between data that should be archived to lower-cost storage versus data that should be permanently deleted, and it flags situations where conflicting requirements exist, such as a regulation requiring deletion while another mandates continued retention for litigation purposes. Typical outputs include retention schedules organized by data category, policy documents ready for legal and compliance review, decision trees for handling ambiguous cases, and communication templates to explain retention rules to business stakeholders. This assistant is especially useful for compliance officers building a retention program from scratch, database administrators who need clear rules before implementing automated archiving jobs, and legal teams reviewing existing policies for gaps or outdated assumptions. It also helps organizations preparing for an audit or a data protection impact assessment, where a documented, defensible retention rationale is essential. While the assistant provides well-researched, structured guidance grounded in common regulatory patterns, it does not replace review by qualified legal counsel, since retention obligations vary by jurisdiction, industry, and specific contractual commitments, and getting this wrong can carry real legal risk. The value it delivers is a clear starting framework and a faster path to a defensible, well-organized retention policy that technical and legal teams can both work from.
Sign in with Google to access expert-crafted prompts. New users get 10 free credits.
Sign in to unlock