Agent Skillsmohitagw15856/pm-claude-skills › data-retention-policy

data-retention-policy

GitHub

构建基于法律和商业依据的数据保留与删除计划。生成包含数据类别、保留期限、法律依据及删除触发器的详细时间表,识别无依据或无期限的高风险数据,确保符合GDPR等合规要求并实现数据最小化。

plugins/pm-compliance/skills/data-retention-policy/SKILL.md mohitagw15856/pm-claude-skills

Trigger Scenarios

创建数据保留政策 设定数据保留期限 规划数据删除或最小化策略 询问数据可保留的最长时间

Install

npx skills add mohitagw15856/pm-claude-skills --skill data-retention-policy -g -y
More Options

Non-standard path

npx skills add https://github.com/mohitagw15856/pm-claude-skills/tree/main/plugins/pm-compliance/skills/data-retention-policy -g -y

Use without installing

npx skills use mohitagw15856/pm-claude-skills@data-retention-policy

指定 Agent (Claude Code)

npx skills add mohitagw15856/pm-claude-skills --skill data-retention-policy -a claude-code -g -y

安装 repo 全部 skill

npx skills add mohitagw15856/pm-claude-skills --all -g -y

预览 repo 内 skill

npx skills add mohitagw15856/pm-claude-skills --list

SKILL.md

Frontmatter
{
    "name": "data-retention-policy",
    "description": "Build a data retention and deletion schedule grounded in legal basis. Use when asked to create a data retention policy, set retention periods, plan data deletion\/minimisation, or answer 'how long can we keep this data?'. Produces a retention schedule — data categories with their retention period, legal\/business basis, deletion trigger and method, plus flags for data kept with no basis or no defined period."
}

Data Retention Policy Skill

"Keep everything forever" is a liability, not a strategy — it grows breach exposure, violates data- minimisation rules (GDPR, CCPA), and turns every data subject request into an archaeology project. This skill builds a retention schedule that ties each data category to how long you keep it and why (legal basis), with a concrete deletion trigger — so retention is a defensible policy, not an accident.

Required Inputs

Ask for these only if they aren't already provided:

  • Data categories — the kinds of data you hold (customer records, logs, financial, HR, marketing, backups).
  • Legal/regulatory drivers — anything mandating minimum retention (tax/financial records, employment law) or maximum (GDPR minimisation, sector rules).
  • Business need — why each category is genuinely needed and for how long.
  • Where it lives — systems and backups (backups are the most-forgotten place data outlives its policy).

Output Format

Data Retention Schedule: [organisation]

1. Schedule — the core table, one row per data category:

Data category Retention period Basis (legal/business) Deletion trigger Method System(s)
Customer PII 3y after account closure Legitimate interest + GDPR minimisation Account closed + 3y Hard delete App DB, backups
Financial records 7y Tax law (statutory minimum) End of fiscal year + 7y Archive then delete Finance system

2. Principles — the policy stance: minimise by default, the shortest period that satisfies the basis, and that retention applies to backups and logs too.

3. Deletion mechanics — how deletion actually happens (automated job vs. manual), how it cascades to backups, and how it's evidenced.

4. Flags — categories with no defined period or no legal/business basis (these are the risk — data you can't justify keeping).

Programmatic Helper

scripts/retention_schedule.py (stdlib only) validates a schedule and flags categories missing a period or a basis, and (given a closure/event date) computes the earliest deletion date:

# data.json: [{"category":"Customer PII","retention_months":36,"basis":"GDPR minimisation","event_date":"2024-01-15"}, ...]
python3 scripts/retention_schedule.py data.json
python3 scripts/retention_schedule.py data.json --json

Quality Checks

  • Every category has both a retention period and a documented basis
  • Periods default to the shortest that satisfies the legal/business need (minimisation), not "indefinite"
  • Backups and logs are covered, not just the primary store
  • Each category has a concrete deletion trigger and method, not just a duration
  • Statutory minimums (tax, employment) and maximums (minimisation) are both respected

Anti-Patterns

  • Do not set retention to "indefinite" or leave it blank — undefined retention is the highest-risk, least-defensible state
  • Do not forget backups — data deleted from production that lives on in backups is still data you hold
  • Do not keep data with no legal or business basis — if you can't justify it, deleting it lowers risk for free
  • Do not set a blanket period for all data — tax records and marketing emails have very different drivers
  • Do not present statutory periods as advice — flag where legal/compliance must confirm the minimums

Based On

Data-minimisation practice — GDPR Art. 5(1)(e) storage limitation, sector retention statutes, and defensible-deletion principles.

Version History

  • a38bc30 Current 2026-07-05 11:12

Same Skill Collection

exports/openclaw/360-feedback-template/SKILL.md
exports/openclaw/401k-plan-decoder/SKILL.md
exports/openclaw/ab-test-planner/SKILL.md
exports/openclaw/ab-test-readout/SKILL.md
exports/openclaw/accessibility-audit/SKILL.md
exports/openclaw/account-plan/SKILL.md
exports/openclaw/acquirer-red-team/SKILL.md
exports/openclaw/ad-copy/SKILL.md
exports/openclaw/aeo-optimizer/SKILL.md
exports/openclaw/agenda-or-cancel/SKILL.md
exports/openclaw/agent-design-review/SKILL.md
exports/openclaw/agent-observability-spec/SKILL.md
exports/openclaw/agent-spec/SKILL.md
exports/openclaw/ai-ethics-review/SKILL.md
exports/openclaw/ai-eval-plan/SKILL.md
exports/openclaw/ai-feature-prd/SKILL.md
exports/openclaw/ai-product-canvas/SKILL.md
exports/openclaw/air-quality/SKILL.md
exports/openclaw/altitude-shifter/SKILL.md
exports/openclaw/ambiguity-resolver/SKILL.md
exports/openclaw/analyst-relations-brief/SKILL.md
exports/openclaw/announcement-card/SKILL.md
exports/openclaw/api-docs-writer/SKILL.md
exports/openclaw/api-test-plan/SKILL.md
exports/openclaw/api-versioning-strategy/SKILL.md
exports/openclaw/apology-letter/SKILL.md
exports/openclaw/architecture-decision-record/SKILL.md
exports/openclaw/architecture-diagram/SKILL.md
exports/openclaw/archive-strategy/SKILL.md
exports/openclaw/assumption-bounty/SKILL.md
exports/openclaw/assumption-mapper/SKILL.md
exports/openclaw/async-update-format/SKILL.md
exports/openclaw/auto-repair-estimate-decoder/SKILL.md
exports/openclaw/autopilot-charter/SKILL.md
exports/openclaw/benefits-decoder/SKILL.md
exports/openclaw/bid-tender-review/SKILL.md
exports/openclaw/board-deck-narrative/SKILL.md
exports/openclaw/board-minutes/SKILL.md
exports/openclaw/board-pre-read/SKILL.md
exports/openclaw/bom-cost-review/SKILL.md
exports/openclaw/bookkeeping-categorization/SKILL.md
exports/openclaw/boolean-search-builder/SKILL.md
exports/openclaw/brag-doc/SKILL.md
exports/openclaw/brainstorming/SKILL.md
exports/openclaw/brief-builder/SKILL.md
exports/openclaw/briefing-note/SKILL.md
exports/openclaw/budget-builder/SKILL.md
exports/openclaw/budget-variance-analysis/SKILL.md
exports/openclaw/bug-diagnosis/SKILL.md
exports/openclaw/bug-report/SKILL.md

Metadata

Files
0
Version
471c606
Hash
0414a3c9
Indexed
2026-07-05 11:12

- 위키
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-07-30 11:13
浙ICP备14020137号-1 $방문자$