Retention Period Justifications and Approvals

Version1.0
Effective DateApril 2026
Review CycleAnnual
Document OwnerChief Information Security Officer (CISO)
ClassificationCONFIDENTIAL — Internal Use Only
Applicable StandardSOC 2 Type II

1. Purpose

This document provides the rationale and approvals for the retention periods applied to each category of personal and operational data processed by DCKAP Integrator. It demonstrates that retention decisions are deliberate, justified, and reviewed.

2. Retention Period Justifications

Data CategoryRetention PeriodJustificationApproved By
Consumer transit dataMax 24 hoursDCKAP’s role is to transfer, not store, consumer data. 24 hours allows for immediate retry on transient failures while minimising privacy exposure.CISO + DPO
Sync execution logs90 days90 days covers typical support escalation timelines and provides sufficient history for SOC 2 audit evidence without excessive data accumulation.CISO + Engineering Lead
API request/response logs30 days30 days sufficient for debugging recent issues. PII is masked, reducing privacy risk. Shorter than sync logs as these are more voluminous.CISO + Engineering Lead
Audit trail1 yearSOC 2 Type II requires evidence of controls over the entire audit period (typically 12 months). 1 year satisfies this while balancing storage cost.CISO + External Auditor Guidance
Security events / SIEM1 yearIncident response investigations may cover events months in the past. 1 year aligns with industry standard and SOC 2 requirements.CISO
Portal user account dataAccount + 30 days30-day post-deletion retention allows recovery of accidental deletions and completion of any pending support cases.CISO + Product
Billing records7 yearsTax regulations in multiple jurisdictions (including the US and UK) require financial records to be kept for a minimum of 6–7 years.CFO + Legal
Customer config dataAccount + 90 days90-day post-termination retention supports customer data recovery requests during the offboarding period, a common contractual commitment.CISO + Customer Success

3. Review and Approval History

VersionReview DateReviewer(s)Outcome
1.0June 27, 2026CISO, DPO, CFO, Legal CounselInitial schedule approved — all periods justified.
1.1 (planned)June 2027CISO, DPO, Legal CounselAnnual review — scheduled

4. Criteria for Retention Period Review

  • Change in applicable law or regulation (e.g., new data protection legislation).
  • Change in DCKAP’s data processing activities or product architecture.
  • Recommendation from external auditor or data protection authority.
  • Customer contract requirements that necessitate a different period.

5. Placement in Product

Product LocationScreen / PageAudience
Compliance FolderSOC 2 Evidence → Retention JustificationsExternal Auditors, CISO
Internal WikiLegal → Privacy → Retention DecisionsDPO, Legal, Engineering
Trust CenterLegal → Data Retention Rationale (summary)Enterprise DPOs