FillTrust

How to answer

What is your data retention period, and how is customer data deleted after termination?

The number is easy. What separates a good answer from one that unravels is whether it accounts for backups, logs and every other place a copy came to rest.

A model answerReused from your library

Customer data is deleted within [30] days of contract termination, on request or automatically at the end of the retention period defined in our DPA. Backups containing customer data are purged on their own rolling [35]-day cycle, after which no copy remains.

Square brackets are yours to fill in. FillTrust grades an answer like this reused from your library when your documents support it.

Answered from
Your DPA, which is where the contractual commitment lives. A retention policy adds detail but the DPA is what the reviewer will hold you to.
Evidence to attach
Nothing. This is a contractual answer, not an evidentiary one.
Where it is asked
CAIQ v4.0 · DSP-16SIG LiteISO 27001 Annex A · A.8.10

This is a contract question wearing a technical costume. Whatever your engineering does, the answer a reviewer will hold you to is the one in your Data Processing Agreement, so the first move is to read your own DPA and quote it, rather than to describe your deletion job.

The number itself is uncontroversial. Thirty days after termination is the common commitment; some vendors say immediately on request with a thirty-day backstop. Either is fine.

What separates a durable answer from one that unravels under a follow-up is whether it accounts for every copy. Deleting the row in the production database is the easy part. The same customer data is also, typically, in: automated backups on a rolling window, a data warehouse someone set up for analytics, an object store holding uploaded files, log lines if request payloads were ever logged, and the support tool where a customer pasted a record into a ticket. Each of those has its own retention, and several of them are longer than thirty days.

The answer that survives is the one that names the longest of them. "Live data is deleted within 30 days; backups containing it are purged on a rolling 35-day cycle, after which no copy remains" is a stronger answer than "deleted within 30 days", because it is the one that stays true when somebody checks.

There is a second-order trap worth knowing about, because it has bitten products in this exact category: if your storage objects are keyed by something that disappears when the database rows are deleted, you cannot find them afterwards to delete them. They are not merely retained. They are unattributable. Deletion has to enumerate before it destroys.

This is the question most likely to be answered from a library rather than regenerated, because the answer is a contractual constant. Approve it once and it should never need writing again.

How this one goes wrong

Specific to this question, not general advice.

  • Forgetting backups. Deleting the live record while a backup retains it for another 35 days means the honest deletion window is 35 days, not immediate, and that is fine to say as long as you say it.
  • Quoting a period your DPA does not contain. The DPA is the enforceable document; the questionnaire answer has to match it.
  • Answering for the database while logs, analytics warehouses and support tickets keep their own copies on their own schedules.

There are another two hundred of these in the file.

FillTrust drafts every one from your own documents and shows the passage behind each answer, including the ones it refuses to answer.

Or write this answer down once and publish it on a Trust Center of your own, which costs nothing.