The complete journey of data — from when it is first created or collected, through how it is used and stored, to when it is eventually deleted.
The complete journey of data — from when it is first created or collected, through how it is used and stored, to when it is eventually deleted.
The data lifecycle typically encompasses: creation or capture, storage, usage and sharing, archival, and destruction. Each stage has associated governance controls: creation requires quality validation and metadata assignment; storage requires security and access control; usage requires purpose limitation and audit logging; archival requires retention policy compliance; destruction requires secure erasure and documentation. For AI systems, lifecycle management extends to training datasets that may need to be retained for audit purposes under the EU AI Act's ten-year documentation requirement, while inference data may need to be deleted under GDPR retention principles.
AI governance programmes must map training and inference data against lifecycle policies — ensuring that retention requirements for regulatory audits do not conflict with privacy obligations to delete personal data.
Like the lifecycle of a printed document — from printing, through filing and use, to archive, and ultimately shredding — with specific rules at each stage about who can access it and when it must be destroyed.
The complete journey of data — from when it is first created or collected, through how it is used and stored, to when it is eventually deleted.
The data lifecycle typically encompasses: creation or capture, storage, usage and sharing, archival, and destruction. Each stage has associated governance controls: creation requires quality validation and metadata assignment; storage requires security and access control; usage requires purpose limitation and audit logging; archival requires retention policy compliance; destruction requires secure erasure and documentation. For AI systems, lifecycle management extends to training datasets that may need to be retained for audit purposes under the EU AI Act's ten-year documentation requirement, while inference data may need to be deleted under GDPR retention principles.
AI governance programmes must map training and inference data against lifecycle policies — ensuring that retention requirements for regulatory audits do not conflict with privacy obligations to delete personal data.