IDEF Data Retention and Disposal, v1.0

Specifies requirements in accordance with Identity Ecosystem Framework (IDEF) requirement PRIVACY-14: DATA RETENTION AND DISPOSAL.

Assessment Steps (2)

1
Limited Retention of Personal Information Over Time (LimitedRetentionofPersonalInformationOverTime)
Does the entity limit the retention of personal information to the time necessary for providing and administering the functions and services to users for which the information was collected, except as otherwise required by law or regulation?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
2
Secure Disposal of Personal Information (SecureDisposalofPersonalInformation)
Does the entity securely dispose of personal information, when it is no longer needed, in a manner aligning with appropriate industry standards and/or legal requirements?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Data Retention and Disposal
Entities MUST limit the retention of personal information to the time necessary for providing and administering the functions and services to users for which the information was collected, except as otherwise required by law or regulation. When no longer needed, personal information MUST be securely disposed of in a manner aligning with appropriate industry standards and/or legal requirements.
Citation
IDEF
Page 22