Operator data deleted within 30 days of contract termination
SOC2.C1.RETENTION · GLOBAL · data_protection
Requirement
Within 30 days of an operator contract ending, all operator-specific evidence ledger entries, evaluation records, and connector configuration must be deleted from primary storage and from backups on the next backup rotation.
Source: AICPA TSC — C1 Confidentiality (retention on contract end)
Evidence specification
| Evidence type | Connector | Spec | Acceptance criteria |
|---|---|---|---|
doc_presence | doc-sharepoint | {
"path": "/audit-trail/deletion-log.csv",
"required_fields": [
"operator_id",
"terminated_at",
"deleted_at",
"confirmed_by"
]
} |
|
Recent evaluations (Apollo Gaming Ltd.)
No evaluation history for this control yet.