Install
$ agentstack add skill-mohitagw15856-pm-claude-skills-data-retention-policy ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Data Retention Policy Skill
"Keep everything forever" is a liability, not a strategy — it grows breach exposure, violates data- minimisation rules (GDPR, CCPA), and turns every data subject request into an archaeology project. This skill builds a retention schedule that ties each data category to how long you keep it and why (legal basis), with a concrete deletion trigger — so retention is a defensible policy, not an accident.
Required Inputs
Ask for these only if they aren't already provided:
- Data categories — the kinds of data you hold (customer records, logs, financial, HR, marketing, backups).
- Legal/regulatory drivers — anything mandating minimum retention (tax/financial records, employment law) or maximum (GDPR minimisation, sector rules).
- Business need — why each category is genuinely needed and for how long.
- Where it lives — systems and backups (backups are the most-forgotten place data outlives its policy).
Output Format
Data Retention Schedule: [organisation]
1. Schedule — the core table, one row per data category:
| Data category | Retention period | Basis (legal/business) | Deletion trigger | Method | System(s) | |---|---|---|---|---|---| | Customer PII | 3y after account closure | Legitimate interest + GDPR minimisation | Account closed + 3y | Hard delete | App DB, backups | | Financial records | 7y | Tax law (statutory minimum) | End of fiscal year + 7y | Archive then delete | Finance system |
2. Principles — the policy stance: minimise by default, the shortest period that satisfies the basis, and that retention applies to backups and logs too.
3. Deletion mechanics — how deletion actually happens (automated job vs. manual), how it cascades to backups, and how it's evidenced.
4. Flags — categories with no defined period or no legal/business basis (these are the risk — data you can't justify keeping).
Programmatic Helper
scripts/retention_schedule.py (stdlib only) validates a schedule and flags categories missing a period or a basis, and (given a closure/event date) computes the earliest deletion date:
# data.json: [{"category":"Customer PII","retention_months":36,"basis":"GDPR minimisation","event_date":"2024-01-15"}, ...]
python3 scripts/retention_schedule.py data.json
python3 scripts/retention_schedule.py data.json --json
Quality Checks
- [ ] Every category has both a retention period and a documented basis
- [ ] Periods default to the shortest that satisfies the legal/business need (minimisation), not "indefinite"
- [ ] Backups and logs are covered, not just the primary store
- [ ] Each category has a concrete deletion trigger and method, not just a duration
- [ ] Statutory minimums (tax, employment) and maximums (minimisation) are both respected
Anti-Patterns
- [ ] Do not set retention to "indefinite" or leave it blank — undefined retention is the highest-risk, least-defensible state
- [ ] Do not forget backups — data deleted from production that lives on in backups is still data you hold
- [ ] Do not keep data with no legal or business basis — if you can't justify it, deleting it lowers risk for free
- [ ] Do not set a blanket period for all data — tax records and marketing emails have very different drivers
- [ ] Do not present statutory periods as advice — flag where legal/compliance must confirm the minimums
Based On
Data-minimisation practice — GDPR Art. 5(1)(e) storage limitation, sector retention statutes, and defensible-deletion principles.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: mohitagw15856
- Source: mohitagw15856/pm-claude-skills
- License: MIT
- Homepage: https://mohitagw15856.github.io/pm-claude-skills/
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.