AI use and data retention: who owns it on each service model
What is sent to an AI model or kept in a service, for how long, and for what purpose it may be used. Your prompts, outputs and retention are yours; the provider's use of them for training is set by its terms.
The split by service model
| Service model | Owner | Why, and the clause |
|---|---|---|
| Infrastructure as a service | yours | What data goes into the service, for what purpose and how long it is kept is yours to decide and delete; the provider stores what you give it. ISO/IEC 27017 CLD.8.1.5 |
| Platform as a service | yours | What data goes into the service, for what purpose and how long it is kept is yours to decide and delete; the provider stores what you give it. ISO/IEC 27017 CLD.8.1.5 |
| Software as a service | shared | Retention and purpose settings in the service are yours to choose; how the provider itself retains and uses what you send is set by its terms, which you must read. ISO/IEC 27018 A.3.1 |
| Serverless functions and event services | yours | What data goes into the service, for what purpose and how long it is kept is yours to decide and delete; the provider stores what you give it. ISO/IEC 27017 CLD.8.1.5 |
| Hosted AI models and AI platforms | shared | Retention and purpose settings in the service are yours to choose; how the provider itself retains and uses what you send is set by its terms, which you must read. ISO/IEC 27018 A.3.1 |
Services that move the line
- Hosted large language model API: yours Your prompts, the outputs you keep and how long you keep them are yours to govern and delete; whether the provider may use them for training is set by its terms, which you must read (named, not quoted).
- AI assistant in a SaaS suite: shared The assistant reads what your users can already reach; which content it may use, and the retention setting, are yours to choose, while the provider's own use of prompts is set by its terms.
The clauses each framework attaches
9 quoted| Framework | Clause |
|---|---|
| Cloud Controls Matrix v4.0.1 | CCM-DSP-12 Limitation of Purpose in Personal Data Processing · CCM-DSP-16 Data Retention and Deletion |
| ISO/IEC 27017:2015 | ISO/IEC 27017 CLD.8.1.5 Removal of cloud service customer assets |
| ISO/IEC 27018:2019 | ISO/IEC 27018 A.3.1 Public cloud PII processor's purpose · ISO/IEC 27018 A.3.2 Public cloud PII processor's commercial use |
| SOC 2 Trust Services Criteria | SOC 2 P4.2 Personal information is retained for only as long as needed |
| ISO/IEC 27001:2022 Annex A | ISO/IEC 27001 8.10 Information deletion |
| CMMC 2.0 | CMMC AC.L2-3.1.22 Control Public Information |
| C5 cloud criteria catalogue | C5-PI-03 Secure deletion of data |
CCM-DSP-12 Limitation of Purpose in Personal Data ProcessingConfine personal data processing to the purposes declared to the data subject and permitted by applicable law, and be able to demonstrate that limit.
- The declared purposes per processing activity and the notice given to data subjects
- Controls that prevent processing outside the declared purpose
- Evaluation evidence such as a review of actual processing against declared purpose
- Records of new purposes and how consent or legal basis was re-established
- Data collected for one purpose reused for analytics without re-establishing a basis
- Declared purposes written so broadly they permit anything
- No review comparing actual processing to declared purpose
CCM-DSP-16 Data Retention and DeletionManage data retention, archiving and deletion against business requirements and applicable law, so data is neither kept longer nor destroyed sooner than allowed.
- The retention schedule by data type with the requirement behind each period
- Evidence retention periods are enforced technically
- Deletion records at end of retention
- Legal hold procedure and its interaction with deletion
- Retention schedule published with no technical enforcement
- Data retained indefinitely because deletion was never built
- Legal hold not accounted for, so data under hold is deleted
ISO/IEC 27017 CLD.8.1.5 Removal of cloud service customer assetsAssets of the cloud service customer that are on the cloud service provider's premises are to be removed, and returned where necessary, in a timely manner when the cloud service agreement ends. The provider should describe how customer assets are returned and deleted at termination, in what form and within what time; the customer should plan for termination from the start, including retrieval of its data in a usable format and confirmation of deletion.
- Provider termination and data return procedure with timescales
- Customer exit plan for the cloud service
- Confirmation of deletion after termination
- Data return window shorter than the customer's migration takes
- Provider deletes customer data with no confirmation, or keeps it in backups indefinitely
ISO/IEC 27018 A.3.1 Public cloud PII processor's purposePII to be processed under a contract should not be processed for any purpose independent of the instructions of the cloud service customer; the processor acts only on the customer's documented instructions and does not determine purposes of its own for customer PII.
- Contract clause restricting processing to customer instructions
- Internal rule and controls preventing secondary use
- Evidence of instruction-based processing
- Analytics or product improvement run on customer PII without instruction
- Instructions accepted informally with no record
ISO/IEC 27018 A.3.2 Public cloud PII processor's commercial usePII processed under a contract should not be used by the processor for the purposes of marketing and advertising without express consent, and such consent should not be a condition of receiving the service. This control is an addition to the general control in A.3.1 and is not intended to override it.
- Policy prohibiting marketing use of customer PII
- Consent mechanism, if any, separate from the service terms
- Marketing consent bundled into the service agreement
- Usage data derived from customer PII used to target advertising
SOC 2 P4.2 Personal information is retained for only as long as neededRetains personal information consistent with the entity's objectives related to privacy
- The retention schedule for personal information, with the period per data type and its legal or business basis
- Evidence of enforcement, such as automated deletion jobs, purge reports or records of manual disposal
- Evidence retention covers all copies, including backups, archives, replicas, exports and third party held data
- Records of legal holds or other justified exceptions, with approval and expiry
- Evidence of monitoring showing personal information beyond its retention period is identified and removed
- Retention schedule documented with no enforcement anywhere, so nothing is deleted
- Deletion performed in the production database while backups, data warehouses and exports retain the data
- Legal holds applied and never released, becoming permanent retention by default
- No monitoring, so overdue data is only discovered during an audit or an incident
ISO/IEC 27001 8.10 Information deletionDelete information in systems, devices and media when no longer required.
- Deletion policy
- Media disposal log
- System deletion audit
- Data retention schedule
- Retaining data beyond approved period
- No evidence of secure erase verification
- Policies not aligned with actual practice
- Incomplete media disposal records
CMMC AC.L2-3.1.22 Control Public Information Level 1 and 2Control CUI that is posted to or processed on publicly accessible systems so CUI is not released to the public.
- Review and approval process for content published publicly
- Designated reviewer authorizations and review records
- Evidence of periodic scanning of public sites for CUI
- Publication approval informal or undocumented
- No periodic check of already published content
- Public facing systems not identified as in scope
C5-PI-03 Secure deletion of dataErase customer data at the end of the contractual relationship in line with the agreed terms, covering the customer environment, metadata and backup copies, using methods that defeat recovery by forensic means.
- Erasure procedure spanning the live environment, metadata stores and backup media
- Completion confirmation issued for a terminated customer within the agreed period
- Technical description of the wiping or key destruction method relied upon
- Backup retention schedule showing when residual copies finally expire
- Live data removed while backup copies persist to the end of an unchanged retention cycle
- Metadata, audit trails and derived indexes retained after the content itself is gone
- Removal limited to deleting pointers, leaving content readable from the underlying media