How to Answer Data Retention and Deletion Questions
Your customer asked: “How long do you retain customer data, and how is it deleted?”
The short answer
Describe the actual retention and deletion practice for the data in scope. Be especially careful with fixed timelines, backups, legal or contractual retention, and copies held by subprocessors because those details can make a simple answer inaccurate.
Educational guidance only. This page does not determine what is true about your company and does not create a security, compliance, testing, or certification claim.
What the customer is really asking
Understand the question before you answer it.
Customers want to understand how long their information remains in your environment and what happens when it is no longer needed or the relationship ends. These answers can become contractual commitments, so precision matters.
How to answer accurately
Start with the version that matches reality.
If you have defined retention periods
State the period only for the data types and systems it actually covers, and identify important exceptions such as backups or legally required records.
If deletion occurs on request or termination
Describe the trigger and process. Do not add a number of days unless the company has approved and can meet that timeline.
If retention is not formally defined
Say that the process is not yet formally documented rather than inventing a schedule from memory.
A useful answer structure
Status → scope → current practice → supporting information. Start with the direct answer, narrow it to what you can verify, explain how the practice works, and reference evidence only when that evidence actually exists.
Evidence that may help
These are examples, not requirements and not proof that your company has the practice. Use only evidence that really exists and is appropriate to share.
- Data retention policy or schedule
- Application deletion workflow
- Backup retention settings
- Vendor or subprocessor retention terms
What not to say
- “All data is deleted within 30 days” unless that covers every relevant copy and system.
- That deleting the production account automatically removes backups.
- That a policy timeline is proven operational performance.
How Oredra handles this
Answer it once. Keep the truth behind the answer.
Oredra can store retention statements by scope so a customer-specific answer does not accidentally turn a limited rule into an all-data promise.
Inside Oredra, a written policy, stated company practice, implemented control, available evidence, tested control, and independent certification remain distinct. Oredra uses approved information to draft future answers and flags questions that the approved profile cannot support.
Authoritative references
Oredra uses primary guidance where a technical or assurance concept benefits from verification. These references do not determine your company's answer.
Related questionnaire questions
Is customer data encrypted in transit?
The question is asking whether information is protected while moving between systems, users, or services. Verify the actual protocols and the scope of the data flows before answering. Do not assume that using a modern cloud platform means every transmission path is covered.
Is customer data encrypted at rest?
Encryption at rest concerns stored data. Before answering, identify where customer information is stored and confirm which storage systems, databases, devices, and backups are actually encrypted.