Data Retention Policy Builder
Design a governance tool for defining how long each data class is kept, archived, reviewed, and deleted across regions.
The brief
Understand the problem
Background
Retention rules depend on data purpose, jurisdiction, contract, system capability, and active preservation duties. A single global duration can violate either minimization or legal obligations.
User context
Privacy lead Amina needs customer-support recordings deleted after ninety days in most regions, retained for one year where required, and paused from deletion when a legal hold applies.
Product problem
Policy authors need to express precedence and exceptions, preview affected records, and verify that connected systems can enforce the rule.
Objective
Create policy definition, rule simulation, conflict review, approval, and enforcement monitoring for one data class.
What to design
Define the experience
Required experience
- Define data class, purpose, trigger, duration, and disposition
- Add regional or contractual exceptions
- Simulate rules against representative records
- Publish the policy and monitor system enforcement
Screens and states
- Policy builder
- Record simulator
- Conflict and precedence review
- Enforcement dashboard
Core user flow
Follow the critical path
- 01
Amina selects support call recordings and a case-closure trigger
- 02
She adds the default ninety-day deletion and a regional one-year rule
- 03
Simulation shows a record under legal hold that must not delete
- 04
Reviewers approve the policy and connected systems report enforcement status
Product rules
Requirements and constraints
Requirements
- Model trigger, duration, disposition, jurisdiction, purpose, and exception separately
- Explain rule precedence for every simulated record
- Identify systems that cannot enforce part of the policy
- Version, approve, and timestamp every published change
Constraints
- Legal holds override ordinary deletion
- Retroactive policy changes need impact review
- Deletion claims require evidence from each source system
Reality check
States worth considering
Finish line
What to deliver
- Four desktop screens with a conflict and an unenforceable-system state
If you want more
Optional extensions
Optional direction
Visual resources
Use these as a starting constraint if you want one. They are not part of the required solution.