← SOC 2 · P4 — Privacy

P4.1 — Use, retention and disposal of personal information (P4.1–P4.3)

high data-retentiondata-minimisationdata-deletion

Requirement

The entity limits the use of personal information to the purposes identified in its notice and consistent with the consent received, retains it only as long as necessary, and disposes of it securely.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
personal informationpersonal data
Required element 2 — any one of
retentionretainpurpose limitationminimis…minimiz…disposedelete
Supporting terms — specificity signals
schedulelawful basisconsentsecondary useanonymis…pseudonymis…

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
PCI DSS 4.0.1 3.2 Minimise storage of account data data-retention data-minimisation data-deletion
GDPR Art.5(1)(e) Storage limitation data-retention data-deletion
ISO 27001 A.8.10 Information deletion data-deletion data-retention
PCI DSS 4.0.1 3.3 Sensitive authentication data is not stored after authorisation data-minimisation data-deletion
GLBA 314.4(c)(6) Secure disposal within two years and periodic review of retention data-deletion data-retention
COPPA 312.10 Written data retention policy for children's information data-retention data-deletion
NDPA 2023 s.24 Principles of data processing data-minimisation data-retention
GDPR Art.5(1)(b) Purpose limitation data-minimisation