[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-data-retention::en":3,"gloss-cluster-data-retention::en":23,"gloss-next-data-retention::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"data-retention","security","Data Retention Policy","A data retention policy defines how long you keep each type of data and what happens when that clock runs out — deletion, anonymization, or archival. It's the counterweight to the default engineering instinct to keep everything forever. Privacy laws like GDPR require that personal data not be held longer than necessary, enterprise customers ask about retention during security reviews, and 'we still had it' is what turns a minor breach into a major one. Well-set retention also cuts storage cost and shrinks your attack surface: data you've already deleted can't be stolen. For AI SaaS, retention questions extend to prompts, model outputs, and logs — which often contain the most sensitive user content. Practical note: map each data type to a retention period and a lawful basis, automate deletion with scheduled jobs rather than relying on manual cleanup, remember to purge backups and derived copies (caches, search indexes, warehouses), and log deletions so you can prove compliance when asked.","A data retention policy sets how long each kind of data lives and what happens when the clock runs out — deletion, anonymization, or archival, and GDPR expects one.",null,[11,14,17,20],{"slug":12,"name":13},"audit-log","Audit Log (Audit Trail)",{"slug":15,"name":16},"gdpr","GDPR (General Data Protection Regulation)",{"slug":18,"name":19},"pii","Personally Identifiable Information (PII)",{"slug":21,"name":22},"sub-processor","Sub-processor",[24,26,30,34,37,40,43,46,49,52,55,58],{"slug":12,"category":5,"name":13,"updated_at":25},"2026-08-24T02:46:37+00:00",{"slug":27,"category":5,"name":28,"updated_at":29},"blast-radius","Blast Radius","2026-08-24T03:30:02+00:00",{"slug":31,"category":5,"name":32,"updated_at":33},"break-glass-access","Break-Glass Access","2026-08-24T02:46:38+00:00",{"slug":35,"category":5,"name":36,"updated_at":33},"bridge-letter","Bridge Letter",{"slug":38,"category":5,"name":39,"updated_at":33},"business-associate-agreement","Business Associate Agreement (BAA)",{"slug":41,"category":5,"name":42,"updated_at":25},"byok","Bring Your Own Key (BYOK)",{"slug":44,"category":5,"name":45,"updated_at":33},"cve","CVE (Common Vulnerabilities and Exposures)",{"slug":47,"category":5,"name":48,"updated_at":29},"data-classification","Data Classification",{"slug":50,"category":5,"name":51,"updated_at":33},"data-loss-prevention","Data Loss Prevention (DLP)",{"slug":53,"category":5,"name":54,"updated_at":33},"data-minimization","Data Minimization",{"slug":56,"category":5,"name":57,"updated_at":33},"data-poisoning","Data Poisoning",{"slug":59,"category":5,"name":60,"updated_at":33},"data-processing-agreement","Data Processing Agreement (DPA)"]