{"description":"Each cycle runs as a workflow instance attached to the existing data-retention-and-secure-disposal Control item in the control library (UC-DATA-09/UC-DATA-10) — enrich that Control with this run's evidence, never create a duplicate control. A decision-aware cycle covering expired-data identification, disposition approval, verifiable disposal, media sanitization, evidence assembly, and stakeholder reporting. In scope: identifying and disposing of data whose retention has expired across in-scope stores (databases, file shares, document repositories, email archives, backup sets, and physical media) governed by the approved retention schedule. Out of scope: authoring the retention schedule itself — it is consumed as a standing input (the retention Policy item and its attached schedule), not produced here — and any data under an active legal or audit hold, which is fenced off from disposal. No upstream workflow feeds this cycle; it is triggered by the disposal calendar, a storage threshold, a system decommission, or a data-subject erasure request. It produces a signed disposition list, a disposal evidence package (job logs, hash manifests, chain-of-custody records, and certificates of destruction), a cycle dashboard, and an approved cycle report mapped to ISO 27001 A.8.10/A.7.10, NIST SP 800-53 SI-12/MP-6, and GDPR Article 5(1)(e). Downstream it hands nothing to another workflow: open exceptions, deferrals, and accepted gaps carry forward as Issue items in the risk/issue register, and schedule-maintenance gaps are forwarded to the retention-schedule owner as a closure notice.","edges":[{"id":"e-approve-disposition-execute-disposal","label":"Approve disposal","source":"approve-disposition","target":"execute-disposal","whenValue":"approve_disposal"},{"id":"e-approve-disposition-document-deferrals","label":"Defer items","source":"approve-disposition","target":"document-deferrals","whenValue":"defer_items"},{"id":"e-document-deferrals-execute-disposal","source":"document-deferrals","target":"execute-disposal"},{"id":"e-execute-disposal-report-cycle-results","source":"execute-disposal","target":"report-cycle-results"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-DATA-09","UC-DATA-10"],"department":"it","domains":["controls"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=controls-data-retention-disposal","contentDigest":"sha256:f6701b905bc9cb9478c91fc668ae944d10bfa6a8ab6b18eb919a0be2ef47fa5e","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:f6701b905bc9cb9478c91fc668ae944d10bfa6a8ab6b18eb919a0be2ef47fa5e","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-data-retention-disposal"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-data-retention-disposal","source":"coworkcanvas-gallery","standards":["iso-27001","nist-800-53","gdpr"],"teams":["it","privacy"]},"name":"Data Retention & Secure Disposal","nodes":[{"data":{"decisionField":"disposition_decision","description":"Approve the hold-safe disposition population after source spot-checks and rulings on ambiguous classes, mixed records, erasure requests and business need.","formData":{"fields":[{"key":"disposition_decision","label":"Disposition decision","options":[{"label":"Approve disposal","value":"approve_disposal"},{"label":"Defer items","value":"defer_items"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Approve the hold-safe disposition population after source spot-checks and rulings on ambiguous classes, mixed records, erasure requests and business need.\n\n**Inputs**\n- The approved retention schedule — held as a **Policy item** (`policy_type: standard`, `policy_owner`, `review_frequency`, `next_review_date`) linked to the anchor Control, with the schedule document attached to it; it gives, per record class, the retention period, the trigger event that starts the clock, the approved disposal method, and the policy clause behind each.\n- The data inventory / system registers of in-scope stores (databases, file shares, document repositories, email archives, backup sets, and physical media in storage), each with its environment, the record classes it holds, and the recorded data owner. Studio has no native Data Store / Asset item type, so this rides as a **document on this step** (store-register extract, CSV/XLSX), not as linked item records.\n- The active legal-hold and audit-hold register mapping each hold to the record classes and stores it touches. Studio has no native Legal Hold type, so it too is a **document on this step**.\n- The triggering event for this cycle (scheduled cadence, storage threshold, system decommission, or a data-subject erasure request) and the period it covers — recorded on the **workflow instance** at launch as the cycle's own initial inputs; no upstream workflow feeds this cycle.\n- Prior-cycle open findings, if any — the open **Issue items** (`issue_type: policy_exception` or `finding`, `source: management_identified`) linked to the anchor Control from the previous cycle.\n\n**Procedure**\n_This checkpoint absorbs “Identify expired data”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Identify expired data: Confirm scope before querying: reconcile the in-scope store list against the data inventory and flag any store or record class with no retention-schedule entry or no named data owner. Resolve ownership and schedule gaps first — never guess a record class or an owner.\n2. Query every in-scope store against the retention schedule, computing for each item or dataset the record class, the retention trigger date, the expiry date, and days past expiry; capture store, location, data owner, and volume counts.\n3. Exclude every item under an active legal or audit hold, recording the hold reference beside each exclusion so the fence is auditable rather than silent.\n4. Flag edge cases for human judgment: items whose record class is ambiguous, datasets mixing expired and unexpired records, personal data that has outlived its GDPR Article 5(1)(e) processing purpose even where its schedule entry has not lapsed, and orphaned data with no schedule mapping.\n5. Trace secondary locations where expired data also lives — backups, replicas, exports, physical media — and attach them to each disposition entry so disposal is complete rather than cosmetic.\n6. Compile the disposition list grouped by store and record class with item counts, total volumes, and the proposed disposal method per entry (secure deletion, cryptographic erasure, or physical destruction per NIST SP 800-88); attach the raw dated query outputs as evidence.\n\n**Decision criteria**\n- `approve_disposal` — pick when the full disposition list may proceed to disposal as proposed: every entry's retention has genuinely expired, all hold exclusions are honored, every flagged edge case has a ruling, and no entry collides with pending litigation or an investigation, a scheduled audit, an open data-subject request, or a standing business-need attestation from a data owner. The list flows straight to disposal.\n- `defer_items` — pick when any entry must be held back for a stated reason (pending litigation or investigation, a scheduled audit, an open data-subject request, a regulatory inquiry, or a documented business need). The defer branch documents those holds first; disposal then proceeds only for the remaining approved entries.\n\nBefore choosing, the agent drafts a proposed outcome and rationale in the step result citing disposition-list rows and hold references; the records owner records their actual judgment and submits only the routing SELECT.\n\n**Record in AssureSwarm**\n- **Step document:** attach the signed disposition list (XLSX) and the raw dated query outputs to this step.\n- **Step result:** set total items and volume expired, count excluded under hold, and count of flagged edge cases awaiting a ruling.\n- **Item relationship:** link the retention-schedule Policy item and the anchor Control to this cycle. The in-scope stores have no native item type — the store register rides as the document above, not as linked records.\nSubmit the SELECT field `disposition_decision` (`approve_disposal` | `defer_items`). Record the rationale in the step result, citing disposition-list rows and hold references; name the step's approver record.\n\n**Exit criteria**\n- Disposition list attached with per-entry record class, expiry, proposed method, and secondary locations; every hold exclusion carries its reference; every edge case is flagged for a ruling; the records owner has spot-checked a sample against source systems and signed the list; nothing has been deleted.\n- The decision routing selector is submitted and the step result contains a rationale and a named owner; the matching branch is active and the unused branch is prunable.\n\n> **⚡ Audit Artist accelerator:** `/coach-query-data` runs the per-store retention queries and assembles the grouped disposition list with counts and dated query evidence.","kind":"decision","label":"Approve disposition","performedBy":{"primitives":["coach-query-data","coach-document-upload","coach-items-link","coach-form-fill"]}},"id":"approve-disposition"},{"data":{"description":"Agent records each deferral with its reason and new review date; human confirms before disposal proceeds on the remainder","instructions":"**Objective** — Convert every deferred entry into a tracked record with a reason, an owner, and a review date, so deferral is a documented decision and never silent retention, and produce the residual approved list that proceeds to disposal.\n\n**Inputs**\n- The submitted disposition decision form (the `defer_items` branch) and its rationale.\n- The signed disposition list with the entries the decision marked for deferral.\n- The legal-hold and audit-hold register for hold references and expected release dates.\n\n**Procedure**\n1. Create one **Issue** per held-back entry (`issue_type: policy_exception`, `source: management_identified`), capturing in `description` the affected data, its store and record class, the disposition-list row reference, and the stated reason (pending litigation, an open audit, an active data-subject request, a regulatory inquiry, or a documented business need); set `exception_approver` to who authorized the deferral and `issue_owner` to the accountable owner.\n2. Set each Issue's `exception_expiry_date` to the review date tied to its reason — the expected hold release, the audit close, or the next scheduled cycle — so the deferral resurfaces on the expiry index rather than becoming silent retention.\n3. Where a deferral rests on business need alone, draft a risk note stating what continued retention exposes: the GDPR Article 5(1)(e) storage-limitation obligation, an enlarged breach blast radius, and added discovery burden. Where that residual risk is formally accepted, record it as a **Risk** item (`category: privacy` or `compliance_regulatory`, `treatment: accept`) so the acceptance is informed rather than reflexive.\n4. Update the disposition list to mark deferred entries out of the current run and produce the residual approved list that proceeds to disposal.\n\n**Record in AssureSwarm**\n- **Item create:** one **Issue** per held-back entry (`issue_type: policy_exception`, `source: management_identified`, `description` = reason + disposition-list row ref, `exception_approver`, `exception_expiry_date` = review date, `issue_owner`).\n- **Item relationship:** link each deferral Issue to the anchor Control and to the retention-schedule Policy item; where a residual risk was accepted, link it to the accepted **Risk** item (`treatment: accept`).\n- **Step document:** attach the residual approved list to this step.\n\n**Exit criteria** — Every deferred entry has a deferral record with a legitimate reason, an owner, and a firm review date; business-need deferrals carry a risk note that is accepted or escalated; the residual approved list contains no deferred or held entries and is released to disposal.","label":"Document deferrals","performedBy":{"primitives":["coach-item-create","coach-item-update","coach-document-upload","coach-items-link"]}},"id":"document-deferrals"},{"data":{"description":"Agent runs deletion jobs, collects logs and hash evidence, and schedules media destruction with vendors; human witnesses and attests physical destruction","instructions":"**Objective** — Dispose of every approved entry verifiably across electronic stores and physical media, capturing the logs, hashes, and certificates that prove it happened.\n\n**Inputs**\n- The approved-for-disposal list — this step is a join: on the `approve_disposal` branch it is the full signed disposition list; on the `defer_items` branch it is the residual approved list from the deferral step. Wait for whichever branch ran.\n- The retention schedule's approved disposal method per record class, read from the retention **Policy item**.\n- The approved change-window calendar (an external scheduling system) and the approved media-destruction **Vendor item** (`category: professional_services` or `facilities`, `tier`, `data_classification`, `business_owner`, `monitoring_status`) whose per-batch certificate obligations this step tracks.\n- The vendor’s signed per-batch destruction certificate, requested through the trusted vendor evidence channel and attached as a document.\n\n**Procedure**\n1. Sequence the approved list into disposal jobs per store, honoring dependencies — application records before underlying storage, primary copies before backup rotation — and schedule each job in an approved change window.\n2. Trigger electronic disposal by the method the schedule prescribes per record class: secure deletion, cryptographic erasure (destroy the wrapping keys), or purge per NIST SP 800-88; capture job logs, item counts, and completion timestamps per run.\n3. Collect integrity evidence as jobs complete: pre-disposal item manifests with hashes where the platform supports them, post-run confirmation counts, and an error list for any item a job could not remove.\n4. For physical media (drives, tapes, paper) due for destruction, schedule shredding or degaussing with the approved vendor, record the chain of custody from storage location to the destruction point, and request the signed certificate of destruction from the vendor for each batch. Extract its media identifiers, method, completion date, facility and signatory, and reconcile these with the approved batch and witness/custody evidence. Resolve any missing certificate attribute through the trusted vendor channel.\n5. Upload the disposal logs, hash manifests, custody records, and each certificate as it arrives, flagging any batch whose certificate is late, whose destroyed counts disagree with the manifest, or whose declared method differs from the method the schedule prescribes.\n\n**Record in AssureSwarm**\n- **Step document:** upload the disposal job logs, hash manifests, chain-of-custody records, and certificates of destruction (PDF/CSV) to this step.\n- **Evidence document:** request the vendor signatory’s signed certificate and extract its media, quantity, identifiers, method, date, facility and signatory. Reconcile those facts to the approved batch and custody/witness records. Record the executor’s disposal, certificate and error counts in the step result.\n- **Item relationship:** link the media-destruction **Vendor item** to this cycle so each batch certificate traces back to the vendor of record.\n\n**Exit criteria** — Every approved entry has a disposal job log; physical destruction is witnessed and attested on the custody record wherever policy requires an observer; each media batch has a returned attestation and certificate naming the media, method, date, and vendor signatory; no disposal ran against a held or deferred item; and every job error is triaged (rerun or escalate).\n\n**Evidence source** — Request the signed evidence document from the media-destruction vendor's authorized signatory through the trusted vendor channel and attach it as a document. No questionnaire is required.","label":"Execute disposal","performedBy":{"primitives":["coach-document-upload","coach-items-link"]}},"id":"execute-disposal"},{"data":{"description":"Judge source re-query and count reconciliation, sign the reperformable evidence package and release fairly stated disposal metrics and exceptions.","instructions":"**Objective** — Judge source re-query and count reconciliation, sign the reperformable evidence package and release fairly stated disposal metrics and exceptions.\n\n**Inputs**\n- The disposal job logs, hash manifests, chain-of-custody records, and certificates of destruction from the disposal step.\n- The signed disposition list and any deferral records.\n- The submitted decision form and its rationale.\n- The designated evidence repository — here the **workflow instance** itself, since every step's documents accrue on the run — and its retention-label scheme (a document on this step where externally defined).\n- The signed evidence package and its traceability index from the verification step, and its repository reference.\n- The prior cycle's report and metrics for trend comparison.\n- The stakeholder distribution list and the compliance register.\n- The operational risk / issue register and the retention-schedule owner's contact.\n- The policy cadence for computing the next cycle date.\n\n**Procedure**\n_This checkpoint absorbs “Verify and assemble evidence”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Verify and assemble evidence: Re-run the identification queries against every store that had disposals and confirm the disposed items no longer return — including the secondary locations attached at identification (replicas, exports, backups past their rotation point); list every survivor as an open exception.\n2. Reconcile counts end to end: disposition list minus documented deferrals equals items disposed equals items verified absent, with every difference explained in writing.\n3. Assemble the evidence package: the confirmed scope and signed disposition list, the submitted decision form with its rationale, deferral records where that branch ran, disposal job logs and hash manifests, media chain-of-custody records, and every certificate of destruction.\n4. Build an index tracing each disposed entry from identification through the decision to its disposal evidence, apply consistent naming and dates, and scan the package itself for residual sensitive content that would violate retention or classification rules.\n5. Link the indexed package to the cycle record in the evidence repository with the retention label applied — disposal evidence carries its own retention period and must outlive the data it documents.\n6. Report cycle results: Compute the cycle metrics: items and volume identified as expired, disposed and verified, deferred with reasons, excluded under hold, open exceptions with aging, media batches destroyed with certificates received, and elapsed time from expiry to disposal by record class.\n7. Build the cycle dashboard presenting those metrics against the prior cycle so trends — a growing deferral backlog, stores that repeatedly produce survivors, chronically late certificates — are visible rather than buried in tables.\n8. Draft the cycle report covering scope, the decision outcome and rationale, disposal and verification results, open exceptions and deferrals with owners and review dates, and the mapping of results to ISO 27001 controls A.8.10 and A.7.10, NIST SP 800-53 controls SI-12 and MP-6, and GDPR Article 5(1)(e).\n9. Cross-check the draft so every open exception and deferral in the evidence package appears in the report and no statement contradicts the verification results; stage the distribution list (the records owner, data owners of affected stores, security and privacy leads, and the compliance register).\n10. The records owner approves the metrics as fairly stated and releases the report to the distribution list; that approval is the cycle's closure. Verify distribution and that the evidence package is filed and retrievable, listing the confirmation references.\n11. Draft a carry-forward entry for every open exception, deferral, and accepted gap, targeted at the operational risk or issue register, each with an owner, a review date, and a link back to its originating disposition entry.\n12. Compute the next cycle date from the policy cadence, plus interim checkpoints for deferral review dates and expected legal-hold releases, and draft the calendar entries.\n13. Note the schedule maintenance this cycle exposed — record classes with no retention entry, stores missing from the data inventory, disposal methods the schedule prescribes but no tool supports — as a handoff to the retention-schedule owner.\n14. Export the complete workflow record — steps, decision, evidence links, and sign-offs — as the archive copy.\n15. Send the closure notice to stakeholders, carrying the schedule-maintenance gaps to the retention-schedule owner.\n\n**Record in AssureSwarm**\n- **Step document:** link the assembled disposal evidence package to this workflow instance (AssureSwarm itself is the repository — the archived run) with the retention label applied; the package must outlive the data it documents.\n- **Step result:** set items verified absent, open exceptions with aging, and the count-reconciliation result.\n- **Dashboard:** create the cycle dashboard comparing this cycle's disposal, deferral, and exception metrics against the prior cycle.\n- **Step document:** attach the approved cycle report (PDF/DOCX) to this step.\n- **Native approval:** record the records owner’s report-release approval and timestamp.\n- **Workflow instance:** export the complete workflow record (steps, the disposition decision, evidence links, and sign-offs) as the archive copy and note its reference on this step — the archived run is the cycle's evidence repository and must not be purged on the disposed data's own schedule.\n- **Item create:** create one carry-forward **Issue** per open exception, deferral, and accepted gap in the risk/issue register (`issue_type: policy_exception` for waivers and accepted gaps, `finding` for open exceptions still to remediate; `source: management_identified`, `issue_owner`, `exception_expiry_date` = review date); where a residual risk is accepted, also record a **Risk** item (`treatment: accept`).\n- **Item relationship:** link each carry-forward Issue to the anchor Control and back to its originating disposition-list entry.\n- **Notification:** send the closure notice — including the schedule-maintenance gaps forwarded to the retention-schedule owner — and mark the cycle closed.\n\n**Exit criteria**\n- Every disposed entry traces from identification to its disposal evidence; counts reconcile with all differences explained; each media batch has a matching certificate and an unbroken chain of custody; open exceptions are either sent back to disposal or documented as accepted gaps with an owner and date; and the records owner has signed the package as complete enough to re-perform the cycle.\n- The report is checked against the evidence package with no unsupported statement; the metrics are approved as fairly stated and the report released to the distribution list with approval identity and date recorded, which closes the cycle. Every open item now lives in a live register with an owner and a date; the next cycle date and interim checkpoints are approved; the schedule-maintenance notes are forwarded to the retention-schedule owner; the closure notice is sent; and the archive reference is recorded as the final entry.\n\n> **⚡ Audit Artist accelerator:** `/coach-dashboard-create` builds the cycle dashboard comparing this cycle's disposal, deferral, and exception metrics against the prior cycle; `/coach-workflow-export` exports the complete workflow record as the archive copy.","label":"Report cycle results","performedBy":{"primitives":["coach-document-upload","coach-query-data","coach-dashboard-create","coach-workflow-export","coach-item-create","coach-items-link","coach-notify"]}},"id":"report-cycle-results"}],"sourceTemplateId":"workflow-library:controls-data-retention-disposal"}
