risk
Unlawful retention or premature deletion of records
Retaining personal data beyond necessity/mandated schedules (privacy and breach risk) or deleting records before required retention periods (litigation-hold, regulatory, tax risk); records-management policy not enforced technically.
In catalog since 2026-09-17T22:28:00Z · Last changed 2026-09-17T22:28:00Z (f368a6cce277)
Record JSON · Open in map · Data retrieval guide
Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.
Attributes
- category
- privacy
- domain
- Data Protection & Privacy
- Compliance, Audit & Assurance
- taxonomy
- nist-privacy-risk
- enterprise-risk
- inherent_rating
- medium
Details
- risk_id
- data-retention-noncompliance
- category
- privacy
- likelihood
- medium
- impact
- medium
- inherent_rating
- medium
- treatment
- mitigate
- taxonomies
- nist-privacy-risk
- enterprise-risk
Source
No record-specific source URL is provided.
Connections
- UC-DATA-09 — Retain personal and confidential data per schedule, then destroy it mitigates Unlawful retention or premature deletion of records
- strength
- primary
- rationale
- An approved retention schedule with timely, irreversible destruction directly prevents both unlawful over-retention and premature deletion.
- UC-DATA-08 — Execute deletion and other rights requests within deadlines mitigates Unlawful retention or premature deletion of records
- strength
- related
- rationale
- Executing erasure requests deletes specific subjects' data, reducing unlawful over-retention.
- UC-AUDIT-25 — Maintain quality records and information for internal control mitigates Unlawful retention or premature deletion of records
- strength
- primary
- rationale
- Retaining and disposing of records per schedules aligned to legal/regulatory/contractual requirements (ISO A.5.33) prevents unlawful retention and premature deletion.