Data-Lifecycle Record
Template for tracing each data category from collection through deletion across all stores, caches, backups, replicas, logs, and derived datasets.
System / feature context
| Field |
Value |
| System / feature name |
|
| Data categories in scope |
|
| Regulatory / policy drivers |
|
| Record owner |
|
| Last updated |
|
Data categories and classification
| Data category |
Classification |
Examples |
Sensitivity rationale |
|
Public / Internal / Confidential / Restricted (PII) |
|
|
|
|
|
|
Purpose declaration
| Data category |
Purpose |
Legal basis (if applicable) |
Purpose review cadence |
|
|
|
|
|
|
|
|
Full lifecycle trace
For each data category, trace through every stage. A lifecycle that ends at "primary database" is incomplete.
| Lifecycle stage |
Location / store |
Retention at this stage |
Access at this stage |
Deletion mechanism |
Deletion verified? |
| Collection |
|
N/A |
|
N/A |
N/A |
| Processing |
|
|
|
|
|
| Primary storage |
|
|
|
|
|
| Caches |
|
|
|
|
|
| Replicas (read) |
|
|
|
|
|
| Backups |
|
|
|
|
|
| Logs |
|
|
|
|
|
| Analytics / derived |
|
|
|
|
|
| Archives |
|
|
|
|
|
| Third-party / subprocessor |
|
|
|
|
|
Deletion cascade
| Trigger event |
Data categories affected |
Cascade order |
SLA per store |
Verification method |
| Account closure |
|
|
|
|
| Retention expiry |
|
|
|
|
| Consent revocation |
|
|
|
|
| Deletion request (DSAR) |
|
|
|
|
Retention clock
| Data category |
Retention period |
Clock start trigger |
Clock stop trigger |
Rationale |
|
|
|
|
|
Access map
| Data category |
Role / system |
Access type (read/write/delete) |
Access condition |
Access logged? |
|
|
|
|
|
Residency
| Data category |
Residency constraint |
Current region(s) |
Compliance evidence |
|
|
|
|
Consent state machine
| Consent state |
Data collected |
Retention behavior |
Deletion behavior |
| Pre-consent |
|
|
|
| Post-consent |
|
|
|
| Post-revocation |
|
|
|
Gaps and follow-up
| Gap |
Severity |
Owner |
Due date |
Closure evidence |
|
|
|
|
|