Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Operations Manager

previous version on gdrive

Retention & Destruction Policy

This policy establishes the mandatory schedules, operational protocols, and legal frameworks for the preservation and irreversible destruction of data within anDREa B.V. (anDREa). This document forms a core element of the Information Security Management System (ISMS), mapping directly to ISO 27001:2023 (A.08.10 - Information Deletion, A.08.14 - Redundancy of Information Processing Facilities), the GDPR (Article 5(1)(e) - Storage Limitation), and NIS 2 business continuity mandates.


1. Scope & System Availability

  • Operational Scope: Universally governs all corporate files, system logs, research workspace telemetry, and human resource records generated across the organization's corporate footprint.
  • Mandatory Review: Reviewed and updated at least annually by the security function or immediately following significant legislative or structural shifts.
  • Availability & Training: This policy is required reading for all anDREa employees, seconded personnel, and contractors. It is published transparently for verified external auditors and interested regulatory bodies.

2. Infrastructure Data Lifecycle & Telemetry Retention

To maintain a secure, audit-verifiable cloud architecture, anDREa segregates and retains data categories under strict lifecycle windows:

System Telemetry & Forensic Logging

Log ClassificationOperational Ingestion StreamMandatory Retention Window
Forensic Core LogsMulti-tenant system interaction data, Cloud Support Team (CST) actions, and technical support access events.2 Years Hot Storage +
7 Years Cool/Archived Storage
Workspace Activity LogsLocalized member interaction logs rendered natively via the active user dashboard.90 Days Hot Storage
Governance RegistriesAccess Review audits (identifying the specific initiator, target user, and checked tokens).Linked directly to the underlying Workspace Lifecycle window.
Corporate Operational LogsRisk Ledgers, Incident Tracking files, and continuous issue monitoring records.2 Years Hot Storage +
7 Years Cool/Archived Storage

Platform Profile Telemetry

  • myDRE Identity Profiles: User account entities are preserved within the Microsoft Entra ID database until a formal deletion request is executed or an automated inactivity trigger trips in accordance with the User Management Policy.
  • Corporate Office Identities: Accounts provisioned within anDREa's Google Workspace environment persist until an individual completes their offboarding lifecycle under Onboarding & Offboarding Process. Corporate endpoint hardware is remotely wiped the moment it changes custodians, is decommissioned, or is reported lost.

3. Microsoft Azure Environment & Workspace Lifecycles

Data stored inside customer-billed research subscriptions features distinct destruction horizons depending on the targeted infrastructure block:


┌────────────────────────────────────────────────────────────────────────┐
│                      WORKSPACE LIFECYCLE HORIZONS                      │
├─────────────────────────┬─────────────────────────┬────────────────────┤
│ 🖥️ Virtual Machine VM   │ 📂 Fileshares (Z-Drive) │ ☁️ Storage Account│
├─────────────────────────┼─────────────────────────┼────────────────────┤
│ Deleting an active VM   │ Continuously protected  │ Deleting an entire │
│ instantly purges all    │ by a 30-day rolling,    │ storage account    │
│ internal OS disk blocks │ 24-hour snapshot mesh.  │ activates a 14-day │
│ beyond recovery.        │ Purged after 30 days.   │ soft-delete window.│
└─────────────────────────┴─────────────────────────┴────────────────────┘

  • Virtual Machine Eradication: Data residing within local VM operating system disks is deleted instantly and is completely unrecoverable once a "Delete VM" command is finalized. Local file persistence follows the active group policy profiles assigned to that instance.
  • Fileshare Caching (Z-Drive): Storage account fileshares are continuously backed up via a 30-day rolling, 24-hour snapshot cycle. Deleted files or folders remain self-service restorable by privileged members for exactly 30 days before becoming permanently unrecoverable.
  • Storage Account Soft-Delete: Master storage account entities are protected against accidental de-provisioning via explicit Azure resource locks. If an account is authorized for deletion, Microsoft provides a non-guaranteed 14-day soft-delete restoration window.
  • Workspace Archival: When a local Research Support team formally decommissions an environment following proper compliance checks, the default archival retention window is 15 years (adjustable upon explicit request by the Tenant's RS lead).

4. Human Resource (HR) Retention Architecture

All personnel files, background checks, and candidate assessments are governed by Dutch labor laws, the Wet Verbetering Poortwachter (Gatekeeper Improvement Act), and tax authority compliance mandates.

Post-Employment Retention Ledger

Document TypeStatutory Retention HorizonLegal & Compliance Rationale
Core Personnel File7 YearsGoverns payroll records, wage tax statements, and pension tracking data required for fiscal audits.
Employment Agreement & Addenda7 YearsMandatory legal verification timeline following contract termination.
Payroll Administration Data7 YearsEnforced under Dutch fiscal retention obligations.
Tax Identity Copies5 YearsExplicit statutory requirement mandated by national Tax Authorities.
Sickness & Absence Records2 YearsManaged in strict isolation under the Gatekeeper Improvement Act (Wet Verbetering Poortwachter); deleted sooner if no longer relevant.
Performance Evaluations2 YearsPreserved for labor continuity; purged sooner unless an active legal dispute is logged.
Auxiliary Training Records1 to 2 YearsOperational logs and certificates; deleted immediately once obsolete.
Unsuccessful Job Applications4 Weeks (Up to 1 year)Deleted within 4 weeks of selection completion by default. Retained for 1 year only if explicit candidate consent is logged.
Accident Reports5 YearsContinuous compliance reporting under the Dutch Working Conditions Act (Arbowet).

Dossier Validity & Disaster Recovery Backups

  • Certificate of Good Conduct (VOG): Holds an internal validity window of 2 years. VOG artifacts are archived as part of the primary personnel dossier; updated checks are systematically rerun upon expiration.
  • Identity Documents: Copies are maintained for the exact duration of the underlying document's structural expiration date, prompting annual verification.
  • i-Drive Disaster Recovery Mesh: anDREa utilizes automated i-Drive storage mirrors to maintain cryptographically isolated, off-site backups of all active Google Workspace files. This secondary storage engine serves as our master Disaster Recovery (DR) fallback plane and is audited annually during formal identity checks.

5. Local Extraction Containment & Disposal

To prevent data spillage across unmanaged endpoints, all personnel and external contractors must adhere to strict processing hygiene rules:

  • Task/Ticket Finalization: Immediately upon resolving an active engineering task or support ticket, all data must be committed to an officially managed anDREa environment.
  • Endpoint Sanitization: Any fragments or files cached on non-anDREa managed environments—including local laptop hard drives, external storage media, personal SharePoints, individual Teams channels, or unapproved Google Drives—must be deleted beyond recovery.
  • Corporate Offboarding: Upon termination of a contract or employment relationship, personnel must hand over all operational records and purge any remaining anDREa business records from personal endpoints. Hardware asset retirement follows the guidelines of (A.7 Physical Controls) for secure equipment sanitation and recycling.