What to Keep and For How Long
Four categories with different lifespans, and the deletion that has to actually happen.
Compliance · Procedure
Telematics produces several kinds of data with different useful lives and different sensitivities. One retention setting for all of them is wrong in both directions.
The four categories
Position: useful for days, sensitive, and the one platforms keep longest by default.
Engine and condition data: useful for years, low sensitivity, and the basis of maintenance and replacement decisions.
Maintenance and inspection records: governed by compliance obligations, commonly years, and frequently required to outlive the platform contract.
Incident data: held under its own rule, with a hold so it survives routine deletion.
Setting the periods
Per category, in days, written down.
Position short — the operational need is dispatch today, not history.
Condition data long, because the replacement curve needs years.
Compliance records to the statutory period, exported into your own systems.
And a hold mechanism for incidents, which is the one thing a flat retention policy cannot accommodate.
Deletion that happens
Automated, because manual deletion does not occur.
Verified: attempt to retrieve something past its period and confirm it is gone rather than hidden from a report.
Including the provider's copy, which needs to be in the contract.
Including exports, which is the leak nobody tracks: a month of positions downloaded to a spreadsheet sits outside every control.
The mismatch to check
Platform default retention against your compliance obligation.
Frequently the platform keeps position too long and maintenance records not long enough, which is exactly backwards.
Check both directions, because the first is a liability and the second is a compliance gap.
Access requests
Where position data is attributable to a person, it is subject to access requests.
Which means it has to be retrievable per person per period, and free of anything you would not want read.
A short retention makes this request small, which is a practical argument alongside the legal one.
The check
What is the configured retention per category, and was each chosen?
Has a deletion actually run, and did anyone verify it?
Could you produce the compliance records if the contract ended tomorrow?
Where are the exports?
Find the exports
Where the retention policy stops applying.
A month of positions downloaded to a spreadsheet sits outside every control.
So does a maintenance report emailed to a manager.
Ask who exports what and where it goes, then decide: logged and time-limited, or reporting done inside the systems.
Both work; the current arrangement of neither does not.
Turn the boundary into a test
For a concrete product reference, this documented connection can help turn this boundary into a test. Verify the current behaviour with representative fields and record what reaches the destination.