Weak data retention, erasure, and access controls

https://taxonomy.eticas.ai/risk/weak-data-controls

Maturity: established

Insufficient policies or technical measures for data retention limits, secure deletion, and access restrictions, increasing the risk of unauthorized access or indefinite data persistence.

System type: ADM and LLM systems
Lifecycle stages: Pre Processing, Post Processing

Mappings to external frameworks

Standards & frameworks

Framework Reference
ISO/IEC 42001:2023 — AI Management System Privacy considerations for AI systems
AIUC-1 — AI Underwriting Company Standard Implement customer data policies