MYTHOSAI

Privacy and devices / PRACTICAL GUIDE

Make a small data-retention inventory

Find redundant copies and assign an owner before deleting business information.

Before you start

Authorisation to inventory relevant data locations and the organisation's existing retention rules.

Describe the information and its purpose

A retention inventory identifies what information is stored, where it lives, who owns it and why it is kept. It is not a blanket instruction to delete everything old. Customer records, financial documents and incident evidence can have different operational or legal requirements that the responsible organisation must determine.

Start with a defined folder or business process. A private worksheet is sufficient; you do not need a paid data-governance service to make the first useful inventory.

Map the copy locations

  1. List the data category and business purpose without copying the actual sensitive records into the worksheet. Identify the authorised owner who can make retention decisions.
  2. Record primary storage, shared links, email attachments, exports, downloads and backup copies. Include devices or cloud services where information is routinely duplicated.
  3. Note access groups, existing retention rules and any approved hold that prevents deletion. Ask the owner to resolve uncertain requirements using appropriate current guidance rather than guessing a universal retention period.
  4. Identify redundant or unneeded copies and propose a supported removal process. Obtain the required authority and preserve data that remains necessary for recovery, records or an investigation.

Verify a limited cleanup

Choose harmless disposable test data or a clearly approved redundant copy. Remove it using the relevant platform's supported controls and inspect expected recycle-bin or version-retention behaviour. Deleting a working file may leave backups, versions or downloaded copies elsewhere.

Avoid unsupported erasure claims

Ordinary file deletion is not a guarantee of forensic destruction, particularly on modern storage or managed cloud systems. Use the vendor's supported lifecycle and device-retirement process when stronger handling is required. Document what the action actually removed and what remains governed by another retention schedule.

A necessary long-lived record does not need to be readable by every user. Review access separately from whether the record should exist. Conversely, restricting a folder is not a reason to keep an unnecessary export forever.

Maintain an accountable inventory

Assign a review owner and revisit after application changes or staff departures. A useful register helps the business make deliberate retention and access decisions. It should avoid storing a second uncontrolled collection of sensitive data while trying to document the first one.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.