{"id":789,"date":"2024-01-01T14:44:35","date_gmt":"2024-01-01T14:44:35","guid":{"rendered":"https:\/\/solutionsreview.com\/expert\/?p=789"},"modified":"2024-02-02T14:26:44","modified_gmt":"2024-02-02T14:26:44","slug":"developing-a-personal-information-business-justification-process","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/thought-leaders\/developing-a-personal-information-business-justification-process\/","title":{"rendered":"Developing a Personal Information Business Justification Process"},"content":{"rendered":"<p style=\"text-align: justify;\">How long can personal information be retained? While global privacy laws do limit the retention of personal information, this does not mean that personal information must be deleted after only a year, for example. Organizations should establish a business justification process which documents the legitimate need for personal information retention. At a minimum, such a process shows good-faith effort at following the rules.<\/p>\n<p style=\"text-align: justify;\">Companies should take a \u201cgoldilocks\u201d approach in determining this retention. It need not be too short, nor too long, but rather following a middle period based on reasonable justification:<\/p>\n<p style=\"text-align: justify;\"><em>Periods<\/em> \u2013 Legal and regulatory recordkeeping requirements trump privacy rules. In the example from the previous section, California requires that \u201cany and all applications, personnel, membership, or employment referral records and files; personnel files of applicants or terminated employees\u201d be retained for four years. As such all such records such have a minimum four-year retention after the records\/files are initially created\/received, or four years after the date the employment action was taken. Records retention requirements serve as a \u201clow water mark\u201d retention period.<\/p>\n<p style=\"text-align: justify;\">Companies May Retain Personal Information for a Longer Period Through Business Justification \u2013 There are many instances in which companies have a legitimate business need to retain personal information longer<\/p>\n<p style=\"text-align: justify;\">than legal and regulatory requirements. Personal information may be retained for these longer periods, so long as there is a reasonable business justification. This justification should be documented in the data retention policy (see below).<\/p>\n<p style=\"text-align: justify;\">Business Justification Must be Reasonable \u2013 The ability to save personal information through a business justification process does not give license for an organization to save personal information longer than reasonable. For example, many companies have significant stores of personal information saved in data warehouse and other similar types of applications, some which contains personal information which may be literally 10 or 20 years old. (See box below). While this personal information may be useful for marketing purposes, it is difficult to see how this retention would be needed for business purposes supporting the sales to a customer.<\/p>\n<p>More information on developing compliant data retention policies is available <a href=\"https:\/\/www.contoural.com\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external\">Contoural<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>How long can personal information be retained? While global privacy laws do limit the retention of personal information, this does not mean that personal information must be deleted after only a year, for example. Organizations should establish a business justification process which documents the legitimate need for personal information retention. At a minimum, such a [&hellip;]<\/p>\n","protected":false},"author":539,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[11],"tags":[],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Developing a Personal Information Business Justification Process<\/title>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Developing a Personal Information Business Justification Process\" \/>\n<meta property=\"og:description\" content=\"How long can personal information be retained? While global privacy laws do limit the retention of personal information, this does not mean that personal information must be deleted after only a year, for example. Organizations should establish a business justification process which documents the legitimate need for personal information retention. At a minimum, such a [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/solutionsreview.com\/thought-leaders\/developing-a-personal-information-business-justification-process\/\" \/>\n<meta property=\"og:site_name\" content=\"Solutions Review Thought Leaders\" \/>\n<meta property=\"article:published_time\" content=\"2024-01-01T14:44:35+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-02-02T14:26:44+00:00\" \/>\n<meta name=\"author\" content=\"Mark Diamond\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Mark Diamond\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/developing-a-personal-information-business-justification-process\/\",\"url\":\"https:\/\/solutionsreview.com\/thought-leaders\/developing-a-personal-information-business-justification-process\/\",\"name\":\"Developing a Personal Information Business Justification Process\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/#website\"},\"datePublished\":\"2024-01-01T14:44:35+00:00\",\"dateModified\":\"2024-02-02T14:26:44+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/#\/schema\/person\/edb68d22af13eb192d2f3fc54976f0b4\"},\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/developing-a-personal-information-business-justification-process\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/thought-leaders\/developing-a-personal-information-business-justification-process\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/developing-a-personal-information-business-justification-process\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/thought-leaders\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Developing a Personal Information Business Justification Process\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/#website\",\"url\":\"https:\/\/solutionsreview.com\/thought-leaders\/\",\"name\":\"Solutions Review Thought Leaders\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/thought-leaders\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/#\/schema\/person\/edb68d22af13eb192d2f3fc54976f0b4\",\"name\":\"Mark Diamond\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/0263a0ab50709e00f9482d37f0706b3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/0263a0ab50709e00f9482d37f0706b3a?s=96&d=mm&r=g\",\"caption\":\"Mark Diamond\"},\"description\":\"Mark Diamond is CEO of Contoural, the largest independent provider of Records &amp; Information Management and Litigation Readiness Consulting Services. He is also Founder and program administrator of the Association of Corporate Counsel Data Steward program, the industry-leading law firm and legal service provider information security assessment, benchmark and accreditation program.\",\"url\":\"https:\/\/solutionsreview.com\/thought-leaders\/author\/mark-diamond\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Developing a Personal Information Business Justification Process","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"Developing a Personal Information Business Justification Process","og_description":"How long can personal information be retained? While global privacy laws do limit the retention of personal information, this does not mean that personal information must be deleted after only a year, for example. Organizations should establish a business justification process which documents the legitimate need for personal information retention. At a minimum, such a [&hellip;]","og_url":"https:\/\/solutionsreview.com\/thought-leaders\/developing-a-personal-information-business-justification-process\/","og_site_name":"Solutions Review Thought Leaders","article_published_time":"2024-01-01T14:44:35+00:00","article_modified_time":"2024-02-02T14:26:44+00:00","author":"Mark Diamond","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Mark Diamond","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/thought-leaders\/developing-a-personal-information-business-justification-process\/","url":"https:\/\/solutionsreview.com\/thought-leaders\/developing-a-personal-information-business-justification-process\/","name":"Developing a Personal Information Business Justification Process","isPartOf":{"@id":"https:\/\/solutionsreview.com\/thought-leaders\/#website"},"datePublished":"2024-01-01T14:44:35+00:00","dateModified":"2024-02-02T14:26:44+00:00","author":{"@id":"https:\/\/solutionsreview.com\/thought-leaders\/#\/schema\/person\/edb68d22af13eb192d2f3fc54976f0b4"},"breadcrumb":{"@id":"https:\/\/solutionsreview.com\/thought-leaders\/developing-a-personal-information-business-justification-process\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/thought-leaders\/developing-a-personal-information-business-justification-process\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/thought-leaders\/developing-a-personal-information-business-justification-process\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/thought-leaders\/"},{"@type":"ListItem","position":2,"name":"Developing a Personal Information Business Justification Process"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/thought-leaders\/#website","url":"https:\/\/solutionsreview.com\/thought-leaders\/","name":"Solutions Review Thought Leaders","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/thought-leaders\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/thought-leaders\/#\/schema\/person\/edb68d22af13eb192d2f3fc54976f0b4","name":"Mark Diamond","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/thought-leaders\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/0263a0ab50709e00f9482d37f0706b3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/0263a0ab50709e00f9482d37f0706b3a?s=96&d=mm&r=g","caption":"Mark Diamond"},"description":"Mark Diamond is CEO of Contoural, the largest independent provider of Records &amp; Information Management and Litigation Readiness Consulting Services. He is also Founder and program administrator of the Association of Corporate Counsel Data Steward program, the industry-leading law firm and legal service provider information security assessment, benchmark and accreditation program.","url":"https:\/\/solutionsreview.com\/thought-leaders\/author\/mark-diamond\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/posts\/789"}],"collection":[{"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/users\/539"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/comments?post=789"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/posts\/789\/revisions"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/media?parent=789"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/categories?post=789"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/tags?post=789"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}