← Control library
D02 · Data and confidentiality
Access and retention controls
Data remains available too broadly or for longer than the declared purpose requires.
Requirement
Enforce role-based access, tenant separation and documented retention and deletion rules across prompts, traces, caches and backups.
Expected evidence
- Access matrix and tenant-boundary design.
- Retention schedule with deletion test records.
Proposed verification
- Attempt cross-role and cross-tenant access.
- Follow one expired record through primary storage and backup handling.
Limit
Backup erasure may be deferred; the schedule must state the actual mechanism and delay.