Skip to main content

ER-34 Pre-Kickoff - Data Classification, Retention and Disposal Policies

Suzette Richards avatar
Written by Suzette Richards
Updated over a year ago

What to Provide

The data classification, retention and disposal procedures.

Evidence Format

Word/PDF document

Additional Guidance

These procedures are commonly known as your "data handling process" and are typically documented as part of your information security policies. The procedures should capture the following:

  • Roles and responsibilities with regards to data classification and handling.

  • Defining the data the organization captures and identifying the data's level of classification (i.e. public, sensitive, confidential).

  • Including guidance on the use, storage and disposal of sensitive data.

  • Retention requirements for all classifications of data

  • Disposal requirements for organization and customer data

  • Explanation of how customer data deletions are formally processed, documented, and tracked

Associated Unified Control ID

Associated Framework Control

CTRL-896

LCL-30
LCL-62

Did this answer your question?