Getting Data In

Log Retention - Legal Considerations

daniel333
Builder

Hello,

We are currently establishing a foothold in Europe and retention of logs can very greatly I am told. Does anyone have a good ref document for this to begin my conversation with our legal team? Or a template I can work with to get started?

thanks in advance,
-Daniel

Tags (3)

martin_mueller
SplunkTrust
SplunkTrust

First of all, IANAL... legal disclaimer here, yada yada.

There are a million and one variations depending on why you're collection what kind of data where, who gets to see it, who agreed to what extent of their data being collected, and so on. Retention time is only one resulting aspect of these considerations... good thing you're already bringing a legal team 😄

Assuming you're talking about personally identifiable information, the best ref documents are the relevant local privacy laws and - obviously - EU regulations.

Here's a starter document for the German legal space: http://www.gesetze-im-internet.de/bdsg_1990/ (in German, has an official English translation)
Your legal team should be familiar with this... if not, get a better legal team.

Much further beyond this blows the scope of Splunk Answers. If you need on-site help in Europe let me know.

Edit: This was all about maximum retention times, laws putting limits on how long you may store stuff. The opposite exists as well, minimum retention times where the laws require you to store stuff for at least X years. That's a whole new can of worms.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...