D02 · Data and confidentiality

Access and retention controls

Data remains available too broadly or for longer than the declared purpose requires.

Requirement

Enforce role-based access, tenant separation and documented retention and deletion rules across prompts, traces, caches and backups.

Expected evidence

  • Access matrix and tenant-boundary design.
  • Retention schedule with deletion test records.

Proposed verification

  1. Attempt cross-role and cross-tenant access.
  2. Follow one expired record through primary storage and backup handling.

Limit

Backup erasure may be deferred; the schedule must state the actual mechanism and delay.

Sources