Skip to content
CLD-095 Cloud Services

Cloud ServicesCLD-095

What is a retention policy?

A retention policy is a rule that determines how long cloud data is kept and what happens when that period ends.

It may retain, archive, delete or review data automatically.

What this means in practice

Some policies are designed to preserve records. Others are designed to remove them after a set period. The same organisation may use both.

Policies may apply to files, messages, logs, backups, accounts or specific folders and users.

They may be set by the provider, customer organisation, administrator or compliance system.

Investigators should identify the policy in force at the relevant time, not just the current policy.

A policy may also apply differently to active, deleted and archived data.

Where automatic deletion is approaching, preservation action may be urgent.

The policy owner and technical administrator may also be different people.

What this does not show on its own

The dangerous assumption is that a retention policy only protects data from deletion.

Retention policies can also interact with legal holds, backups, archives, migration tools and separate compliance systems. One rule may delete the live item while another preserves a compliance copy that ordinary users cannot see, access or remove through the normal interface.

What to do next

Check the scope, start date, retention period, deletion action, exceptions and whether users or administrators could override it.

Do not assume that policy documentation proves the system followed it perfectly. Configuration errors, licence changes or logging gaps may affect the outcome.

Key takeaway

A retention policy controls how cloud data is kept or removed, so establish the exact historical rule, scope and automated action affecting the evidence.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.