← SOC 2 · P4 — Privacy
P4.1 — Use, retention and disposal of personal information (P4.1–P4.3)
high
data-retentiondata-minimisationdata-deletion
Requirement
The entity limits the use of personal information to the purposes identified in its notice and consistent with the consent received, retains it only as long as necessary, and disposes of it securely.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Required element 1 — any one of
personal informationpersonal data
Required element 2 — any one of
retentionretainpurpose limitationminimis…minimiz…disposedelete
Supporting terms — specificity signals
schedulelawful basisconsentsecondary useanonymis…pseudonymis…
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| PCI DSS 4.0.1 | 3.2 | Minimise storage of account data | data-retention data-minimisation data-deletion |
| GDPR | Art.5(1)(e) | Storage limitation | data-retention data-deletion |
| ISO 27001 | A.8.10 | Information deletion | data-deletion data-retention |
| PCI DSS 4.0.1 | 3.3 | Sensitive authentication data is not stored after authorisation | data-minimisation data-deletion |
| GLBA | 314.4(c)(6) | Secure disposal within two years and periodic review of retention | data-deletion data-retention |
| COPPA | 312.10 | Written data retention policy for children's information | data-retention data-deletion |
| NDPA 2023 | s.24 | Principles of data processing | data-minimisation data-retention |
| GDPR | Art.5(1)(b) | Purpose limitation | data-minimisation |