ETQ022
Define purpose-linked retention schedules for audit evidence and delete personal data once its assurance function ends to satisfy GDPR data-minimisation obligations.
CyberTRIZ analysis · Audit contradiction ETQ022 · one of 8,235 worked contradictions published by CyberTRIZ.AI
Regulations
Evidence Retention vs Data Minimization
Business ContextAudit functions retain evidence to support conclusions, regulatory requirements, future review, investigations, and quality assurance. Retaining excessive information increases privacy, cybersecurity, legal, storage, and information-governance exposure.
Audit TRIZ ResolutionRetain evidence according to its assurance function and required retention period rather than preserving all information collected during fieldwork. Sensitive or redundant data should be excluded, minimized, referenced securely, or removed when no longer necessary.
Applicable TRIZ Principles
Principle 2 – Taking Out removes unnecessary or redundant retained information.
Principle 7 – Nested Doll protects sensitive retained evidence within controlled access layers.
Principle 34 – Discarding and Recovering removes information when its required audit function has ended while preserving authorized retrieval where appropriate.
Expected Outcome
Sufficient audit evidence retention
Reduced privacy exposure
Lower cybersecurity risk
Better information governance
Decision Indicators
Audit repositories contain entire datasets when only selected evidence supports conclusions.
Sensitive personal information is retained without a defined purpose.
Evidence is preserved indefinitely because deletion rules are unclear.
Data-minimization efforts remove information needed to defend conclusions.
Audit retention practices differ substantially between engagements.