Skip to main content

Data lifecycle

The complete journey of data, from when it is first created or collected, through how it is used and stored, to when it is eventually deleted.

The Simple Version

The complete journey of data, from when it is first created or collected, through how it is used and stored, to when it is eventually deleted.

Detailed Explanation

The data lifecycle typically encompasses: creation or capture, storage, usage and sharing, archival, and destruction. Each stage has associated governance controls: creation requires quality validation and metadata assignment; storage requires security and access control; usage requires purpose limitation and audit logging; archival requires retention policy compliance; destruction requires secure erasure and documentation. For AI systems, lifecycle management extends to training datasets that may need to be retained for audit purposes under the EU AI Act's ten-year documentation requirement, while inference data may need to be deleted under GDPR retention principles.

Key Characteristics

  • Five core stages: creation, storage, use, archival, and destruction
  • Each stage has distinct governance, quality, and security requirements
  • GDPR and EU AI Act impose competing retention obligations that must be reconciled
  • Lifecycle policies must be documented and enforced as part of data governance

Why It Matters

AI governance programmes must map training and inference data against lifecycle policies, ensuring that retention requirements for regulatory audits do not conflict with privacy obligations to delete personal data.

Real-World Analogy

Like the lifecycle of a printed document, from printing, through filing and use, to archive, and ultimately shredding, with specific rules at each stage about who can access it and when it must be destroyed.

Common Misconceptions

  • Data lifecycle management is only about deletion, it covers all stages including creation quality, usage governance, and archival retention.
  • Cloud storage makes lifecycle management automatic, cloud tools can enforce storage policies, but lifecycle rules must first be defined through governance processes.

Related Terms

Related Articles

Sources & Further Reading