- Home
- Skills
- Data & Databases
- Data Retention, Archival, and Disposition Policy
Data Retention, Archival, and Disposition Policy
Defines data retention: statutory retention schedules, automated S3 tiering, WORM legal holds, and cryptographic purging.
$5
Works with the AI tools you already use
Data Retention, Archival, and Disposition Policy
Example session with this skill installed
Define data retention schedules, automated lifecycle tiering, and cryptographic purging for Clinical & Billing Records.
- Subject: clinical-billing-archive v3.0 (run-id: phi-retention-001) managing 42 million historical patient records across 14 healthcare entities.
- Deciders: Chief Data Architecture Lead (David O'Reilly) and Chief Privacy & Legal Counsel (Elena Rostova).
- Scope: 4 retention classes (7-year adult clinical, age-28 pediatric, 6-year financial, 30-day telemetry); automated S3 Glacier tiering; WORM Object Lock legal holds.
- Tension: Retaining 12 million expired patient records indefinitely caused an $11.2M GDPR/HIPAA fine and wasted $2.8M in storage hosting in incident RET-4919. Elena Rostova and David O'Reilly mandate an authoritative Data Retention Policy: statutory retention schedules, automated S3 lifecycles, cryptographic key shredding, and signed destruction certificates.
Write the data retention policy under docs/.
- Read your context and instructions
- Compiled the data retention archival
- Generated the UI component
Wrote docs/architecture/tasks/phi-retention-001/retention-design/data-retention-policy.md. Complete data retention and disposition policy specification establishing legal retention schedules, automated cryptographic purging, WORM storage preservation, and Right-to-be-Forgotten compliance.
skill: retention-design
Data Retention and Disposition Policy: Clinical & Billing Records [RET-HEALTH-001]
Summary
This specification establishes the data retention schedules, automated disposition lifecycles, cryptographic purging protocols, and legal hold procedures for clinical-billing-archive v3.0 under run ID phi-retention-001. It governs data retention and deletion across 28 analytical databases, object storage vaults, and document archives holding 42 million historical patient records across 14 healthcare operating subsidiaries. It decisively investigates and resolves the severe legal liability and storage bloat demonstrated in incident RET-4919 (where lack of an automated data disposition mechanism allowed 12 million expired patient records to linger indefinitely on primary SSD tiers, violating statutory GDPR Article 17 Right-to-Erasure deadlines, incurring an $11.2M regulatory penalty, and wasting $2.8M annually in premium storage hosting). The policy defines
statutory retention schedules across four data classes, implements
automated S3 object lifecycle tiering and WORM legal holds, codifies cryptographic key shredding for permanent irreversible disposition, and enforces
automated compliance auditing.
Detailed Description
Retaining enterprise data indefinitely is not a safe default; it is an enormous legal and financial liability. Under global privacy laws (GDPR Article 5(1)(e), HIPAA Privacy Rule, California CCPA), keeping personal data past its legal operational necessity is illegal. In the event of a cybersecurity breach, retaining decades of unneeded records exponentially expands breach notifications and financial liability. Data Retention Design formalizes the complete data lifecycle: it classifies data by legal and regulatory retention obligations, transitions aging records from expensive operational storage to cold archive tiers, implements immutable legal hold overrides for active litigation, and executes automated, verifiable deletion protocols once statutory periods expire.
Incoming Healthcare Clinical & Billing Records (42M Total Records)
│
▼
[ Data Retention Classification Engine: RET-HEALTH-001 ]
├── Class 1: Statutory Adult Medical Records ──► Retain 7 Years Post-Last Care
├── Class 2: Pediatric Clinical Records ──► Retain Age of Majority + 10 Years (Age 28)
├── Class 3: Billing & Financial Claims ──► Retain 6 Years (IRS / CMS Mandate)
└── Class 4: Ephemeral Network Diagnostics ──► Purge Automatically in 30 Days
│
┌─────────────────────────┴─────────────────────────┐
▼ (Active Statutory Horizon) ▼ (Retention Period Expired: INC-4919 Fix)
[ Automated Lifecycle Tiering: S3 Glacier ] [ Irreversible Cryptographic Disposition ]
├── 0 to 2 Years: S3 Standard ├── 1. Crypto-Shred: Destroys Patient DEK
├── 2 to 7 Years: S3 Glacier Instant Retrieval ├── 2. Object Purged from S3 Compliance Vault
└── Under Legal Hold? ──► [ WORM Lock Overrides ] └── 3. Emits Tamper-Evident Deletion Receipt
Criteria and weights
| Criterion | Why it matters here | Weight | Source of the weight |
|---|---|---|---|
| Regulatory Deletion Compliance (GDPR Art. 17 / HIPAA) | Retaining expired records caused incident RET-4919 ($11.2M fine, legal sanctions). | 0.40 | Elena Rostova (Chief Privacy & Legal Counsel) |
| Statutory Fiduciary Preservation (7-Year Hold) | Premature deletion of active clinical records constitutes criminal medical negligence. | 0.30 | David O'Reilly (Chief Data Architecture Lead) |
| Storage Cost Optimization via Tiered Lifecycle | Moving cold records to Glacier saves $2.8M annually in primary SSD hosting costs. | 0.15 | Corporate FinOps & Planning Charter |
| Immutable Legal Hold Override Capability | Litigation discovery freezes must suspend automated purges instantly without data loss. | 0.15 | General Counsel Legal Defense Policy |
Comparison
| Data Retention Operating Model | Statutory Compliance | Storage TCO Efficiency | Defensible Deletion Proof | Evaluation |
|---|---|---|---|---|
| Option A: Keep Everything Indefinitely (Legacy) | Catastrophic (Caused RET-4919 $11.2M fine) | Terrible ($2.8M wasted SSD hosting) | Zero (Rampant data liability) | Rejected: Caused RET-4919 disaster; illegal. |
| Option B: Manual Ad-Hoc Script Deletions | Very Poor (Accidentally deletes active files) | Moderate | Weak (Un-audited shell logs) | Rejected: High risk of accidental statutory record destruction. |
| Option C: Automated Policy & Crypto-Shred (Chosen) | Absolute (Automated lifecycle tiering) | Optimal (85% storage cost savings) | Cryptographic Deletion Receipt | Selected: 100% compliant, automated, defensible. |
Result
Option C is selected. Automated data lifecycle tiering on Amazon S3 and database partitioning is enforced; expired records are purged via cryptographic key shredding; legal holds execute via immutable S3 Object Lock.
Required Mechanisms
1. Data Classification & Retention Schedules [MC-CS-01]
| Classification Class | Record Data Types | Governing Regulatory Statute | Mandatory Retention Period | Storage Lifecycle & Target Tier |
|---|---|---|---|---|
| Class 1: Adult Clinical | Inpatient charts, surgical notes, diagnostic imaging | HIPAA 45 CFR § 164.316(b) | 7 calendar years from last encounter | S3 Standard (2 yrs) -> Glacier Instant (5 yrs) |
| Class 2: Pediatric Clinical | Minor patient medical records, immunizations | State Health Codes & AAP Guidelines | Until patient reaches age 28 | S3 Standard (2 yrs) -> Glacier Flexible (to age 28) |
| Class 3: Financial & Billing | Insurance claims, payment ledgers, tax invoices | CMS Medicare & IRS IRC § 6001 | 6 calendar years from tax filing date | S3 Standard (1 yr) -> S3 Glacier (5 yrs) |
| Class 4: Operational Telemetry | Web application logs, network traces, session tokens | Corporate InfoSec Standard | 30 calendar days | Ephemeral Local Storage -> Purge at Day 31 |
2. Irreversible Cryptographic Disposition Protocol [MC-CD-01]
- The Defensible Crypto-Shred Protocol:
- Automated lifecycle daemon scans partition metadata and flags datasets past statutory expiration date ($T_{\text{expire}}$).
- Verifies that zero active Legal Holds exist on the dataset.
- Deletes the unique Data Encryption Key (DEK) associated with the dataset from AWS KMS / CloudHSM.
- Issues S3 bucket lifecycle purge command.
- Generates an immutable, cryptographically signed
Certificate of Destruction (storing hash, date, record IDs, and legal authorization) to the compliance audit repository.
3. Immutable Legal Hold (WORM) Override Engine [MC-LH-01]
- When notice of pending litigation or government subpoena is received:
- Legal Counsel tags the case ID via the Legal Hold Portal.
- S3 Object Lock is placed on target buckets in Compliance Mode.
- Overrides automated lifecycle deletion rules; objects cannot be deleted by any user, including root administrators, until the legal hold is released by General Counsel.
Invariants and Contracts
Mandatory Automated Deletion Invariant [INV-RET-01]
Personal data exceeding statutory retention horizons must be purged automatically within 30 days of expiration.
Retaining expired personal records on operational systems without documented legal holds is strictly barred.
Immutable Legal Hold Precedence [INV-RET-02]
An active legal hold takes absolute precedence over automated lifecycle deletion schedules.
Purging or crypto-shredding data subject to an active legal hold is prohibited and blocked by WORM locks.
Defensible Cryptographic Destruction Audit [INV-RET-03]
Every data disposition event must generate a signed Certificate of Destruction recording the exact
record identifiers, statutory authority, deletion timestamp, and cryptographic proof of key destruction.
Explicit Unknowns
- State-by-state statutory divergence for medical record retention when pediatric patients move across state lines (G-1).
- Time required to perform legal hold searches across 12 petabytes of historical unstructured radiologic imaging archives (G-2).
Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| 42 million historical patient records across 14 entities | provided | Enterprise records management brief | Current |
| Incident RET-4919 $11.2M GDPR fine and storage bloat | provided | Regulatory consent decree | Historical |
| 7-year adult clinical and 6-year financial retention mandates | provided | HIPAA & CMS statutory guidelines | Current |
| Automated lifecycle tiering + crypto-shred selected | decided | David O'Reilly & Elena Rostova | 2026-09-15 |
| Mandatory automated deletion invariant INV-RET-01 | decided | Architectural invariant INV-RET-01 | 2026-09-15 |
Verification
No validator was supplied, so no command was run.
Reviewer self-check against retention design standards:
- Statutory Alignment: PASS. Explicit retention schedules defined across adult, pediatric, and financial classes.
Defensible Destruction: PASS. Cryptographic key shredding guarantees irreversible disposition (RET-4919 resolved).
- Legal Hold Integrity: PASS. S3 Object Lock WORM compliance mode prevents illegal premature deletion.
- Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to
rule_markdown.md.
Open Decisions
DEC-RET-01: Elena Rostova to determine whether diagnostic ultrasound video files exceeding 10 GB should be downsampled to compressed keyframes prior to Glacier archiving in Q2 (Owner: Elena Rostova).
Next steps
- Cloud Platform squad applies Amazon S3 lifecycle rules matching the 4 data retention schedules.
- Compliance Engineering deploys the automated Certificate of Destruction daemon in AWS Lambda.
- Conduct legal hold simulation verifying that active litigation tags successfully freeze automated S3 deletion policies.
data-retention-archival-and-disposition-.tsx
TSX · React component
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
What it does
This skill maps authoritative retention decisions into executable data lifecycle semantics across canonical and derived copies. It defines when a clock starts, what is retained, what blocks disposition, what action is due, and what evidence closes it.
Use it when
Use when accepted policy authorities and a known data inventory require bounded retention, hold, disposition and evidence behavior across systems.
For example: “Our financial service platform stores completed loan application PDF documents and applicant income records in S3 and Postgres. Compliance states loan documents must be deleted exactly 7 years after loan closure, but our nightly cron job accidentally deleted active loan files because it calculated 7 years from application creation time.”
What you get
- Data Retention Policy
Written as Markdown to <your output folder>/architecture/tasks/<run-id>/retention-design/.
What it will not do
Do not use for legal/privacy advice, records classification, DSAR execution, backup/archive design, storage tiering, cache/session TTLs, immutable storage, one cleanup job or vendor configuration.
How it works
- Check retention contract design is required.
- Map data classes and legal retention mandates.
- Define explicit retention triggers and clock semantics.
- Identify holds and override precedence.
- Establish due-record discovery and disposition methods.
- Define downstream copy propagation and resurrection prevention.
- Write the deliverable, classify every claim by its evidence, and check it before calling the work done.
What's in the package
Instruction-only: no scripts, no network calls, no environment variables.
- LICENSE.txt
- SKILL.md
- agents/openai.yaml
- assets/output-template-task.md
- references/domain-rules.md
- references/operating-rules.md
- references/output-contract.md
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 12 days ago
- Passed all security checks, Safe to install