Recommendation : 3. Manage data life
Have the legal constraints related to data preservation been analyzed and the rules and deadlines for "forgetting it" been specified ?
Life cycle
B People
B Planet
B Prosperity
Difficulty
*
Priority
High
Récurrence
Periodic
Tests
Are there mechanisms in place for data lifecycle management (expiration)? Have mechanisms been put in place for archiving data with a low manipulation rate? Has an end of life for the data been planned (implementation of a validity date for each piece of data, implementation of a validity date by type of technical data, implementation of a validation date by type of functional data)? Have users been consulted to consider the necessary lifespan of key data?
Precisions
The regulations impose control of the data life cycle for certain categories (personal data governed by the GDPR), however, the other categories of data are not taken into account, which leads to the accumulation of data without taking into account their expiration dates. This introduces a permanent increase in the volume of data, the volume of backups, and the resources consumed to access the data. As time goes by, the level of accuracy of the data loses its importance, which should lead to a reduction in the volume of data in the phase preceding their removal.
Use Case
Risks assessment
Additional elements
Operational issues related to the project
Rule for assessing the level of compliance of the criterion
Formalized = 100 ; Planned = 75 ; Identified = 50 ; Ignored = 0 / 100
Life cycle
Fin de Vie
4 other criteria related to the recommendation: Manage data life
Sustainable IT Infrastructure
Does the storage strategy keep infrastructure or data duplication to a minimum in relation to its criticality ?
Sustainable IT Infrastructure
Is non-production data anonymized and scaled down to a representative sample of production ?
Life cycle
Is the frequency of data refresh determined in relation to user expectations ?
Purchase Sustainable IT
Are the responsibilities from a GDPR point of view (or local framework in other countries: Privacy Act for example) with service providers clearly defined ?