unified
UC-DATA-09 — Retain personal and confidential data per schedule, then destroy it
Maintain an approved retention schedule for personal and confidential information tied to documented legal and business requirements, and retain data no longer than the schedule permits. When retention ends, delete or irreversibly destroy the information wherever it resides, including in external services, using methods that prevent reconstruction, and record disposal actions as evidence.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Data Protection & Privacy
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-DATA-09
- title
- Retain personal and confidential data per schedule, then destroy it
- statement
- Maintain an approved retention schedule for personal and confidential information tied to documented legal and business requirements, and retain data no longer than the schedule permits. When retention ends, delete or irreversibly destroy the information wherever it resides, including in external services, using methods that prevent reconstruction, and record disposal actions as evidence.
- domain
- Data Protection & Privacy
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- SI-12
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- P4.2
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- P4.3
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- C1.2
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.8.10
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- SOC 2 Confidentiality Assessment tests UC-DATA-09 — Retain personal and confidential data per schedule, then destroy it
- UC-DATA-09 — Retain personal and confidential data per schedule, then destroy it mitigates Unauthorized disclosure / breach of sensitive information
- strength
- related
- rationale
- Destroying data past its retention shrinks the volume of data exposable in any breach.
- UC-DATA-09 — Retain personal and confidential data per schedule, then destroy it maps_to A.8.10 — Information deletion
- framework
- iso-27001
- control_id
- A.8.10
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-DATA-09 — Retain personal and confidential data per schedule, then destroy it mitigates Unlawful retention or premature deletion of records
- strength
- primary
- rationale
- An approved retention schedule with timely, irreversible destruction directly prevents both unlawful over-retention and premature deletion.
- UC-DATA-09 — Retain personal and confidential data per schedule, then destroy it mitigates Residual data on improperly disposed or re-used media
- strength
- primary
- rationale
- Irreversible destruction preventing reconstruction wherever data resides, including external services, directly eliminates residual data on disposed/reused storage.
- UC-DATA-09 — Retain personal and confidential data per schedule, then destroy it maps_to P4.3 — The entity securely disposes of personal information to meet the entity's objectives related to privacy.
- framework
- soc2
- control_id
- P4.3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-DATA-09 — Retain personal and confidential data per schedule, then destroy it maps_to SI-12 — Information Management and Retention
- framework
- nist-800-53
- control_id
- SI-12
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Data Retention & Secure Disposal operates UC-DATA-09 — Retain personal and confidential data per schedule, then destroy it
- UC-DATA-09 — Retain personal and confidential data per schedule, then destroy it maps_to C1.2 — The entity disposes of confidential information to meet the entity's objectives related to confidentiality.
- framework
- soc2
- control_id
- C1.2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-DATA-09 — Retain personal and confidential data per schedule, then destroy it maps_to P4.2 — The entity retains personal information consistent with the entity's objectives related to privacy.
- framework
- soc2
- control_id
- P4.2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- SOC 2 Privacy Criteria Assessment tests UC-DATA-09 — Retain personal and confidential data per schedule, then destroy it
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-DATA-09 — Retain personal and confidential data per schedule, then destroy it