LNC Nexus · Trust Center← Back to LNC Nexus
Trust Center document

Data Retention and Disposal Policy

Public security and assurance reference

POL-6: Data Retention and Disposal Policy

Purpose

This policy defines the requirements for retaining and disposing of data to ensure compliance with legal, regulatory, and business needs. It protects the privacy of individuals and prevents unauthorized access to regulated data.

Scope

This policy applies to all data retained or disposed of by LNC Nexus hosted, private, or self-managed deployments. It covers regulated data, proprietary information, and public data.

Policy Statements

Data shall be retained only for as long as necessary to fulfill business or regulatory requirements. Disposal methods must render data unrecoverable. In self-managed deployments, customers are responsible for data retention and disposal; LNC Nexus provides tools but not enforcement. Regulated data disposal requires documented verification. No data shall be retained beyond its defined retention period without explicit justification.

Roles and Responsibilities

The Security Team defines retention schedules and disposal methods. Data owners determine retention periods for their data. System administrators implement retention and disposal procedures. The Legal Team reviews retention requirements for regulatory compliance.

Evidence and Review

Retention logs, disposal records, and verification reports serve as evidence of compliance. The Security Team conducts periodic reviews of data retention and disposal practices and investigates anomalies. Deployment-specific configurations are treated as controlled material.

Exceptions

Exceptions to this policy require written approval from the Security & Compliance owner or delegated risk owner and must be documented with a risk acceptance statement. Exceptions are valid only for a defined period and must be re-evaluated before expiration.

Enforcement

Violations of this policy may result in disciplinary action, up to and including termination, and legal prosecution where applicable. Data access may be suspended immediately upon detection of a violation.

POL-5 (Data Classification Policy), POL-7 (Encryption Policy), POL-11 (Backup Policy).

Revision History

VersionStatusChange
1.0Draft for approvalInitial framework draft