← ClaudeAtlas

cx-record-retention-auditlisted

Use to compare a support data retention policy against what is actually still stored, and find both over-retention and premature deletion. Trigger for "are we deleting support data on time", "retention audit", "how long do we keep transcripts", "we still have data from 2018", conflicting retention obligations, or preparing for a data protection review.
rulebase-co/rulebase-skills · ★ 1 · AI & Automation · score 72
Install: claude install-skill rulebase-co/rulebase-skills
# Retention audit for support data Support generates some of the longest-lived and least-governed personal data a company holds. The policy usually exists. What is actually still in the systems usually differs from it, in both directions — and the two directions are different problems with different owners. - **Over-retention** — data kept past its period. A data-protection exposure, and it expands the blast radius of any future breach. - **Premature deletion** — data destroyed before an obligation expired. Frequently the more serious of the two, because it can destroy the evidence a complaint, a dispute or a regulator needs, and it is unrecoverable. Most audits look only for the first. Look for both. ## Enumerate everywhere support data lives The audit is only as good as the inventory, and the inventory is always longer than expected. Beyond the helpdesk: - **Call recordings and their transcripts**, often on a different system with a different retention period set by a different team. - **The analytics warehouse or lake**, where support data was copied and where retention is frequently never configured at all. **This is the most common over-retention finding.** - **QA and evaluation records**, including reasoning text that quotes the conversation. - **Exports** — the spreadsheets, extracts and dumps people made for an analysis. Usually ungoverned entirely. - **Backups and snapshots**, where deletion in the primary system does not propagate. - **Third part