PRI-05—Personal Data (PD) Retention & Disposal
Weight: 8
>Control Description
Mechanisms exist to:
(1) Retain Personal Data (PD), including metadata, for an organization-defined time period to fulfill the purpose(s) identified in the notice or as required by law;
(2) Dispose of, destroys, erases, and/or anonymizes the PD, regardless of the method of storage; and
(3) Use organization-defined techniques or methods to ensure secure deletion or destruction of PD (including originals, copies and archived records).
>Cross-Framework Mappings
EU AI Act
EU AI Act (Detailed)
SOC 2 TSC (Detailed)
GLBA (16 CFR 314)
Oregon CPA
Ask AI
Configure your API key to use AI features.