- Retention Period
- The minimum length of time a specific category of record must be kept before it may be destroyed, as set by law, regulation, or internal policy.
- Data Classification
- A scheme that groups data into tiers β such as public, internal, confidential, and restricted β based on sensitivity and the consequences of unauthorized disclosure.
- Legal Hold
- A suspension of the normal destruction schedule for records that are relevant to pending or reasonably anticipated litigation, regulatory investigation, or audit.
- Secure Destruction
- The irreversible elimination of data so it cannot be recovered β achieved through certified shredding of physical media or cryptographic erasure, degaussing, or physical destruction of digital storage.
- Record
- Any information created, received, or maintained by an organization in the course of its operations that has business, legal, or regulatory value β regardless of format or medium.
- Disposition
- The final action taken on a record at the end of its retention period β either destruction or, for records with historical value, transfer to an archive.
- Chain of Custody
- A documented trail of who handled a record or storage device from the point of creation through destruction, used to demonstrate compliance during audits.
- Data Minimization
- The principle β mandated under GDPR and recommended under most privacy frameworks β that organizations collect and retain only the data they actually need for a specified purpose.
- Destruction Certificate
- A formal document issued by a shredding vendor or internal custodian confirming that specific records or media were destroyed on a given date by a given method.
- Retention Schedule
- A table or matrix that maps each category of organizational record to its required retention period, applicable legal authority, and designated record owner.