# Data Retention Policy

> Build a data retention and deletion schedule grounded in legal basis. Use when asked to create a data retention policy, set retention periods, plan data deletion/minimisation, or answer 'how long can we keep this data?'. Produces a retention schedule — data categories with their retention period, legal/business basis, deletion trigger and method, plus flags for data kept with no basis or no defin…

- **Type:** Skill
- **Install:** `agentstack add skill-mohitagw15856-pm-claude-skills-data-retention-policy`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [mohitagw15856](https://agentstack.voostack.com/s/mohitagw15856)
- **Installs:** 0
- **Category:** [AI & ML](https://agentstack.voostack.com/c/ai-and-ml)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [mohitagw15856](https://github.com/mohitagw15856)
- **Source:** https://github.com/mohitagw15856/pm-claude-skills/tree/main/plugins/pm-compliance/skills/data-retention-policy
- **Website:** https://mohitagw15856.github.io/pm-claude-skills/

## Install

```sh
agentstack add skill-mohitagw15856-pm-claude-skills-data-retention-policy
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Data Retention Policy Skill

"Keep everything forever" is a liability, not a strategy — it grows breach exposure, violates data-
minimisation rules (GDPR, CCPA), and turns every data subject request into an archaeology project. This
skill builds a retention schedule that ties each data category to *how long* you keep it and *why*
(legal basis), with a concrete deletion trigger — so retention is a defensible policy, not an accident.

## Required Inputs

Ask for these only if they aren't already provided:

- **Data categories** — the kinds of data you hold (customer records, logs, financial, HR, marketing, backups).
- **Legal/regulatory drivers** — anything mandating minimum retention (tax/financial records, employment law) or maximum (GDPR minimisation, sector rules).
- **Business need** — why each category is genuinely needed and for how long.
- **Where it lives** — systems and backups (backups are the most-forgotten place data outlives its policy).

## Output Format

### Data Retention Schedule: [organisation]

**1. Schedule** — the core table, one row per data category:

| Data category | Retention period | Basis (legal/business) | Deletion trigger | Method | System(s) |
|---|---|---|---|---|---|
| Customer PII | 3y after account closure | Legitimate interest + GDPR minimisation | Account closed + 3y | Hard delete | App DB, backups |
| Financial records | 7y | Tax law (statutory minimum) | End of fiscal year + 7y | Archive then delete | Finance system |

**2. Principles** — the policy stance: minimise by default, the shortest period that satisfies the basis, and that retention applies to **backups and logs too**.

**3. Deletion mechanics** — how deletion actually happens (automated job vs. manual), how it cascades to backups, and how it's evidenced.

**4. Flags** — categories with **no defined period** or **no legal/business basis** (these are the risk — data you can't justify keeping).

## Programmatic Helper

`scripts/retention_schedule.py` (stdlib only) validates a schedule and flags categories missing a
period or a basis, and (given a closure/event date) computes the earliest deletion date:

```bash
# data.json: [{"category":"Customer PII","retention_months":36,"basis":"GDPR minimisation","event_date":"2024-01-15"}, ...]
python3 scripts/retention_schedule.py data.json
python3 scripts/retention_schedule.py data.json --json
```

## Quality Checks

- [ ] Every category has both a retention period and a documented basis
- [ ] Periods default to the shortest that satisfies the legal/business need (minimisation), not "indefinite"
- [ ] Backups and logs are covered, not just the primary store
- [ ] Each category has a concrete deletion trigger and method, not just a duration
- [ ] Statutory minimums (tax, employment) and maximums (minimisation) are both respected

## Anti-Patterns

- [ ] Do not set retention to "indefinite" or leave it blank — undefined retention is the highest-risk, least-defensible state
- [ ] Do not forget backups — data deleted from production that lives on in backups is still data you hold
- [ ] Do not keep data with no legal or business basis — if you can't justify it, deleting it lowers risk for free
- [ ] Do not set a blanket period for all data — tax records and marketing emails have very different drivers
- [ ] Do not present statutory periods as advice — flag where legal/compliance must confirm the minimums

## Based On

Data-minimisation practice — GDPR Art. 5(1)(e) storage limitation, sector retention statutes, and defensible-deletion principles.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [mohitagw15856](https://github.com/mohitagw15856)
- **Source:** [mohitagw15856/pm-claude-skills](https://github.com/mohitagw15856/pm-claude-skills)
- **License:** MIT
- **Homepage:** https://mohitagw15856.github.io/pm-claude-skills/

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-mohitagw15856-pm-claude-skills-data-retention-policy
- Seller: https://agentstack.voostack.com/s/mohitagw15856
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
