Technical data life cycle

Automated retention

Each data type has a retention period and an expiry mechanism (TTL, scheduled job).

# /etc/cron.d/purge-sessions: daily purge of expired sessions
15 3 * * * app psql -c "DELETE FROM sessions WHERE expires_at < now() - interval '30 days';"

Soft vs hard delete: a deleted_at column destroys nothing. Plan a scheduled physical purge after the grace period.

Secure destruction

  • Encryption + key destruction (crypto-shredding): destroying the key makes data unreadable; practical on SSDs and in the cloud.
  • Physical media: certified erasure or destruction; overwriting is unreliable on SSDs.
  • Cloud providers: obtain contractual confirmation of deletion.
  • Backups: set an expiry cycle; document the delay between deletion and disappearance of copies.

Pseudonymization vs anonymization

Pseudonymization Anonymization
Reversible Yes (with the key or a cross-reference) No
Legal status Still PI Out of scope if criteria are met
Example user_id instead of name Aggregates with no possible re-identification

Anonymization must be irreversible and serve serious and legitimate purposes (s. 23 and Anonymization Regulation). An unsalted email hash is not anonymization.