cx-record-retention-auditlisted
Install: claude install-skill rulebase-co/rulebase-skills
# Retention audit for support data
Support generates some of the longest-lived and least-governed personal data a company
holds. The policy usually exists. What is actually still in the systems usually differs
from it, in both directions — and the two directions are different problems with
different owners.
- **Over-retention** — data kept past its period. A data-protection exposure, and it
expands the blast radius of any future breach.
- **Premature deletion** — data destroyed before an obligation expired. Frequently the
more serious of the two, because it can destroy the evidence a complaint, a dispute or
a regulator needs, and it is unrecoverable.
Most audits look only for the first. Look for both.
## Enumerate everywhere support data lives
The audit is only as good as the inventory, and the inventory is always longer than
expected. Beyond the helpdesk:
- **Call recordings and their transcripts**, often on a different system with a different
retention period set by a different team.
- **The analytics warehouse or lake**, where support data was copied and where retention
is frequently never configured at all. **This is the most common over-retention
finding.**
- **QA and evaluation records**, including reasoning text that quotes the conversation.
- **Exports** — the spreadsheets, extracts and dumps people made for an analysis. Usually
ungoverned entirely.
- **Backups and snapshots**, where deletion in the primary system does not propagate.
- **Third part