Data Retention, Backup & Secure Disposal Standard
Retention follows the customer’s approved records schedule by data category. PCL One supports configurable retention, legal holds, usable data export and secure disposal, with a destruction certificate at contract exit or on request where applicable.
Purpose
This standard defines the baseline lifecycle treatment for customer records held in PCL One-managed services. It is designed to support municipal and public-sector retention obligations without forcing one universal retention period across records that have different legal and operational requirements.
Retention baseline
| Data category | Retention position | Control |
|---|---|---|
| Business records and attachments | Customer-defined schedule | Configured by record category where supported; legal/operational holds override routine deletion. |
| Audit, configuration and security logs | Contracted/customer-approved schedule | Retained for audit, investigation and compliance purposes and made available through supported search/export mechanisms. |
| Operational telemetry | Service-specific minimum necessary period | Collected for service operation, security and support; unnecessary personal data should not be introduced into telemetry. |
| Backups | Default contract baseline: 30-day rolling window unless the service schedule states otherwise | Nightly full backup with continuous transaction-log protection for the municipal cloud baseline; encrypted and access-controlled. |
| Migration / staging data | Only as long as required for migration, validation and acceptance | Removed or de-identified when no longer required, subject to legal, contractual or active-issue needs. |
| Data after contract end | Export/transition window followed by deletion | Production data is deleted or rendered inaccessible after the agreed transition window; backup copies expire through the documented backup cycle. |
Backup handling
- Backups are encrypted and protected by role-based administrative controls.
- For the Canadian municipal baseline, backup and recovery copies remain within approved Canadian regions.
- Restore testing is performed periodically to confirm recoverability, not simply backup completion.
- Backup retention is not used to bypass a customer deletion instruction; deleted production data ages out through the documented backup rotation unless legal retention requires otherwise.
Secure disposal and exit
- The customer retains ownership of customer data and may export data using supported standard formats during the service term.
- At termination or expiry, PCL One provides a reasonable data-export and transition period agreed in the service schedule.
- After the transition period, remaining customer data is securely deleted or rendered inaccessible, subject to legal retention obligations and documented backup-cycle limitations.
- Where requested or contractually required, PCL One issues a signed secure-data-destruction certificate identifying the scope and completion date of destruction.
Legal hold and exceptions
A documented legal hold, investigation hold, records-freeze instruction or statutory requirement suspends routine deletion for the affected data only. Once the hold is released, the normal retention schedule resumes. Any exception is recorded with an owner, reason and review point.
Assurance records
- Customer retention schedule / configuration record
- Backup success and restore-test evidence
- Legal-hold or retention-exception register, where applicable
- Exit export record and chain-of-custody evidence
- Secure data destruction certificate
Applicability
This document states PCL One’s public assurance baseline. A customer agreement, service schedule, applicable law or regulator requirement may set additional or stricter obligations; those terms take precedence for the applicable service. Service-specific architecture, residency and retention settings are documented in the relevant service schedule.