Data governance Kiwi insights
What customer data should an early SaaS retain, export, and delete?
Define a purpose, retention period, export path, and complete deletion boundary for customer data before the first release accumulates unmanaged obligations.
Early products often collect data faster than they define responsibility for it. Every field, upload, event, backup, and support export creates an obligation: explain why it exists, protect it, keep it accurate enough for its purpose, and remove it when that purpose ends.
Give every data category a purpose and owner
Create a small inventory covering account data, customer-created records, files, billing references, support information, analytics, logs, and backups. For each category, name its purpose, source, storage locations, access roles, retention trigger, deletion behavior, and owner. If the team cannot explain why a field is needed, do not collect it by default.
Design export around usable customer records
An export should be understandable and complete enough for its stated purpose, not a dump that only the original engineering team can interpret. Define which user or administrator may request it, the format, related files, tenant boundary, delivery method, and how the request is authenticated and audited.
Define deletion across the real system
- Operational databases and object storage.
- Search indexes, caches, and derived records.
- Connected processors and third-party tools.
- Backups, including when deleted data ages out.
- Logs and analytics where identifiers may remain.
The ICO describes storage limitation as keeping personal data no longer than necessary and notes that erasure can require action where data has been made public or passed to others. Exact legal duties depend on context and jurisdiction, so product behavior must be reviewed by the appropriate privacy and legal owners.
Test lifecycle operations before onboarding
Create, export, and delete a representative test account. Verify authorization, completeness, status messages, audit evidence, and downstream cleanup. A policy that the product cannot execute is not a complete data-lifecycle design.
Kiwi can help model and implement scoped export and deletion workflows. Lawful basis, retention schedules, records obligations, and privacy compliance require qualified legal and privacy review.