SOC 2 Control Implementation Guide

Confidentiality / Privacy

Retention and Disposal for SOC 2

Confidential information is retained only as required for business, legal, customer, security, or audit purposes and disposed of using approved methods.

Use this guide to put the control into operation, decide what records to retain, and check that an auditor can trace the evidence back to the work your team performed.

Maintained by GreenHat Security · Reviewed August 21, 2026

What this control should accomplish

Confidential information remains only for approved business, legal, customer, security, or audit purposes and is disposed of through a method appropriate to its storage, classification, and recovery risk.

First SOC 2 program

A credible starting point

Identify the confidential records most likely to accumulate outside the core product—support attachments, exports, contracts, personnel records, secrets, backups, and collaboration files. Assign periods and disposal methods, then run tracked deletion or sanitization work and verify the result.

As the company scales

Make it repeatable

Map the retention schedule to automated lifecycle policies across production, SaaS, analytics, backup, device, and collaboration systems. Separate holds from normal retention, monitor expired data and failed jobs, and use sampled verification to confirm that configured disposal actually occurs.

How to implement Retention and Disposal

  1. 1

    Inventory confidential locations

    Identify product stores, backups, logs, support attachments, exports, contracts, personnel records, credentials, collaboration spaces, devices, and third-party locations.

    You should end up with: A confidential-information location register with owner and category.

  2. 2

    Assign retention and hold rules

    Link each category and location to an approved period, purpose, event that starts the clock, and any controlled hold process.

    You should end up with: A retention mapping with rationale, start event, approver, and hold path.

  3. 3

    Configure lifecycle controls

    Set database jobs, object expiry, log periods, backup rotation, SaaS deletion, device actions, and manual tasks to match the decision.

    You should end up with: Configuration records and operating procedures mapped to each location.

  4. 4

    Perform disposal

    Run the approved deletion, cryptographic erasure, media sanitization, account closure, or other disposal action when the period ends or an authorized event occurs.

    You should end up with: Job logs, administrative activity, disposal certificate, or closed work ticket.

  5. 5

    Verify sampled results

    Select expired categories and confirm that records are absent, inaccessible, or scheduled to expire from protected backups as designed.

    You should end up with: A dated verification record with queries, findings, and reviewer.

  6. 6

    Resolve holds and failures

    Review active holds, failed lifecycle jobs, manual backlogs, and vendor limitations, assigning each exception an owner and next action.

    You should end up with: An exception and hold review with resolution or renewed approval.

Evidence to keep, and what it should prove

Build the evidence set in three layers: what defines the control, who approved or reviewed it, and what proves it operated. Collect operating records when the work happens so they remain dated, attributable, correctly scoped, and traceable to the underlying activity.

Before sharing, remove unrelated personal or customer data, never expose passwords, tokens, or secret values, preserve enough source context to authenticate the record, and use the secure exchange approved for the engagement.

Policy / design artifacts

Documents that define the control, its scope, ownership, and expected way of working.

Retention schedule

  • Confirm what the record proves

    Shows why each confidential-information category is retained, which event starts its approved period, who owns the decision, and when disposal should occur.

  • Include this context

    confidential data category

  • Include this context

    retention purpose

  • Include this context

    period and start event

  • Include this context

    owner and approver

  • Include this context

    disposal method reference

  • Include this context

    effective and review dates

Weak evidence to avoid

A single keep as needed statement with no confidential categories, periods, start events, owners, or disposal linkage.

Operating / technical evidence

Dated proof that the control actually ran, such as tickets, logs, settings, exports, reports, and test results.

disposal records

  • Confirm what the record proves

    Shows that an identified batch, account, SaaS location, backup set, or record category reached its disposal trigger and received the approved action and verification.

  • Include this context

    disposal identifier and trigger

  • Include this context

    data category and location

  • Include this context

    records, tenant, or date range

  • Include this context

    method and execution time

  • Include this context

    result and verifier

  • Include this context

    exception or residual copy

Weak evidence to avoid

A monthly task marked complete without identifying which records expired, where they lived, what ran, or how the result was checked.

deletion tickets

  • Confirm what the record proves

    Shows the authorized and traceable deletion of confidential information from named product, support, collaboration, analytics, vendor, or backup locations.

  • Include this context

    ticket and authorization

  • Include this context

    data or account scope

  • Include this context

    systems and copies

  • Include this context

    execution actions and timestamps

  • Include this context

    verification result

  • Include this context

    closure reviewer

Weak evidence to avoid

A ticket saying remove old files with no owner authorization, locations, record scope, system result, or verification.

media sanitization evidence

  • Confirm what the record proves

    Shows that each identified device or medium containing confidential information was sanitized by an approved technique and verified before reuse, return, or disposal.

  • Include this context

    asset and media identifiers

  • Include this context

    classification and prior owner

  • Include this context

    sanitization method and tool

  • Include this context

    date and result

  • Include this context

    performer and verifier

  • Include this context

    final disposition

Weak evidence to avoid

A generic wipe completed note without serial number, method, tool output, date, verifier, or final destination.

Which records should you prepare for the audit?

Type 1

Evidence at the as-of date

Current confidential-information retention mappings, active holds, pending disposal work, failed lifecycle jobs, and protected copies awaiting backup expiry on the examination date.

Type 2

Evidence across the review period

Every confidential record set, tenant, account, backup set, support or collaboration location, SaaS account, device, or medium that reached an approved retention or disposal trigger during the review period, together with every deletion, expiry, sanitization, hold, release, failure, retry, and exception occurrence.

Completeness check

Derive due disposal occurrences from the approved schedule, source-system creation or closure dates, active-hold list, SaaS closures, and retired-device inventory; reconcile them to lifecycle jobs, deletion tickets, sanitization results, and backup expiry, investigating every overdue, failed, or unmatched item.

Build the record set from

  • retention and data catalog
  • database, storage, backup, and analytics platforms
  • support, collaboration, and SaaS administration
  • device and asset management
  • deletion and disposal ticket queue
  • legal hold repository

Keep these fields for each record

  • record set, tenant, account, or asset identifier
  • data category and location
  • retention trigger and due date
  • hold or exception status
  • disposal method and execution time
  • result and verification
  • residual copy or backup expiry
  • owner and closure status

How an auditor may test this control

Use this checklist to prepare for procedures an auditor may perform. The exact steps and sample selection depend on your engagement scope and the service auditor's professional judgment.

  • Confirm the intended control outcome

    Determine whether the control is designed to achieve this result: Confidential information remains only for approved business, legal, customer, security, or audit purposes and is disposed of through a method appropriate to its storage, classification, and recovery risk.

  • Confirm ownership and operating cadence

    Compare the documented owner with the intended role (Privacy Owner / CISO / Data Owners), then compare dated records with the stated cadence: Ongoing; periodic review by privacy/data owner.

  • Establish the complete audit record set

    Derive due disposal occurrences from the approved schedule, source-system creation or closure dates, active-hold list, SaaS closures, and retired-device inventory; reconcile them to lifecycle jobs, deletion tickets, sanitization results, and backup expiry, investigating every overdue, failed, or unmatched item.

  • Prepare the as-of-date evidence for a Type 1 engagement

    Current confidential-information retention mappings, active holds, pending disposal work, failed lifecycle jobs, and protected copies awaiting backup expiry on the examination date.

  • Prepare period evidence for a Type 2 engagement

    Every confidential record set, tenant, account, backup set, support or collaboration location, SaaS account, device, or medium that reached an approved retention or disposal trigger during the review period, together with every deletion, expiry, sanitization, hold, release, failure, retry, and exception occurrence.

  • Inspect the policy / design artifacts

    Documents that define the control, its scope, ownership, and expected way of working.

    • Inspect Retention schedule

      For each selected record, confirm it demonstrates Shows why each confidential-information category is retained, which event starts its approved period, who owns the decision, and when disposal should occur.

      • confidential data category
      • retention purpose
      • period and start event
      • owner and approver
      • disposal method reference
      • effective and review dates
  • Inspect the operating / technical evidence

    Dated proof that the control actually ran, such as tickets, logs, settings, exports, reports, and test results.

    • Inspect disposal records

      For each selected record, confirm it demonstrates Shows that an identified batch, account, SaaS location, backup set, or record category reached its disposal trigger and received the approved action and verification.

      • disposal identifier and trigger
      • data category and location
      • records, tenant, or date range
      • method and execution time
      • result and verifier
      • exception or residual copy
    • Inspect deletion tickets

      For each selected record, confirm it demonstrates Shows the authorized and traceable deletion of confidential information from named product, support, collaboration, analytics, vendor, or backup locations.

      • ticket and authorization
      • data or account scope
      • systems and copies
      • execution actions and timestamps
      • verification result
      • closure reviewer
    • Inspect media sanitization evidence

      For each selected record, confirm it demonstrates Shows that each identified device or medium containing confidential information was sanitized by an approved technique and verified before reuse, return, or disposal.

      • asset and media identifiers
      • classification and prior owner
      • sanitization method and tool
      • date and result
      • performer and verifier
      • final disposition
  • Trace the control from design to operation

    Use the categories that apply to this control: connect any policy or design artifact to its approval or review record, then trace a selected operating record through execution, result, and any exception or remediation.

Common implementation and evidence gaps

  • The core database has a period, but support attachments, exports, logs, collaboration files, and analytics do not.
  • A lifecycle rule is configured without confirming which records start the retention clock or whether the job succeeds.
  • Backups are described as immutable without an approved expiry and restoration-handling plan.
  • Legal or investigation holds have no scoped data set, owner, review date, or release action.
  • Devices and removable media are retired without verified sanitization or managed destruction.
  • Confidential records remain in inactive SaaS accounts after the business purpose ends.

Before you call this control ready

  • Can each sampled confidential location be traced to a period, purpose, start event, and disposal method?
  • Do actual system settings agree with the approved retention mapping?
  • Can expired records be sampled from execution through deletion or backup expiry verification?
  • Are failed jobs, manual backlogs, vendor constraints, and active holds visible and owned?
  • Do support, collaboration, analytics, exports, devices, and backups receive the same review as core product stores?

Trust Services Criteria references

These identifiers help you navigate related Trust Services Criteria. They do not reproduce the criteria or prove that this control fully addresses them in your environment.

  • C1.2
  • P4.2
  • P4.3

Confirm final scope, mappings, and testing expectations with your service auditor. SOC 2® is an AICPA trademark; GreenHat Security is not affiliated with or endorsed by AICPA.