Data has a defined life cycle that spans creation, active management, and eventual retirement or destruction — each stage carrying distinct security and compliance responsibilities. Understanding how data moves through this cycle is essential for protecting sensitive information and limiting organizational risk.
Data Life Cycle
Data also has a life cycle. Data's life cycle has a beginning, its creation; a middle, how we manage it; and then an end, how we dispose of it. Let's talk about how we manage it in the middle of that process, how we have a data loss prevention or DLP, and then talk about data destruction.
Somehow data needs to be created, and then at that point in time we have to manage that data, and then at some point in time we should think about retirement of that data.
When it comes to creation, it could be entered in. This could look like a customer entering their information into our website or creating an account. It could be an employee who creates a document. So there's some sort of entering. Or it could be collected: maybe when a customer comes to our website, we're actually collecting information about where that customer has been by looking at their cookies, or maybe there's some sort of information we're pulling like their IP address. And then that information gets compiled. We start compiling information — well, they came to our website, they came from this part of the country, and this is what they purchased — and so we can use that data to start compiling it to figure out different pieces of information.
Once we've got that, then we're going to start using that data. Perhaps we're sharing out that data with others. There's probably some sort of storage, whether it's in a database or a file management system. We may want to transfer that data and move that data around. There could be a copying of that data — we could have multiple copies of it. A backup is a form of copy, because we're going to want to make sure we don't lose that data. Maybe there's some sort of versioning, so when that data changes, when that document changes, then we keep a record of that change.
And then finally there's that retirement side of this. It could go into archive, where we still keep a copy, a long-term copy, but we put it in some sort of back storage system that doesn't cost as much and maybe it's a little bit longer to retrieve, but we don't care because we're saving a little bit of money and we really don't want to be able to access it. Or maybe we need to destroy it completely and just not have access to it at all.
When it comes to data creation, we think about where and how and when it's created. A big problem with this data creation is that you have a lot of shadow IT that happens. You've told your employees, your users, we're only going to use this software — maybe you're a Microsoft shop — and somebody decides to go out and use Google and has not let anyone know that they're using this other platform. Now data is going onto this other platform that you're unaware of. So even on the creation side of this, you need to think about how it's being created and where it's being stored at, and whether there is shadow IT happening where it's being created in spots that you're unaware of.
There's also the data management side of it. Where are we storing this data? How are we storing it? Are we storing it in encrypted means? Are we preventing access to that?
There is also something called data loss prevention. These are solutions out there, software solutions out there, that will help us manage our data, or more specifically help prevent loss of that data. It will analyze to see if people are trying to access that data who shouldn't have access to it, who are trying to make copies of that data, who are possibly trying to steal that data. These solutions can help us do that management process and help enforce confidentiality.
The solution could look like software that's installed on servers that's analyzing who's accessing the information and what they're trying to do with that information. Or perhaps it's a piece of hardware that sits on your network or on the edge of your network to analyze traffic that's going through it to prevent this. Some of it will actually analyze the traffic and see if somebody's trying to publish certain information, and stop that from being published if it's categorized as certain types of documents.
Then there's the idea around data retirement. What happens when we're done with this data? What happens to the documents? What happens to the customer information? The problem is that we hold on to it. We don't do a lot of cleanup, and what happens is this data just keeps stacking up. It's feasible to do this nowadays because storage is relatively cheap compared to the way it used to be, and so we just start storing more and more of it.
But the problem with doing that is that this information, even if it's not highly sensitive, if it gets out there might be disclosures that could damage the reputation of the company. So holding on to this information isn't good. You have to have some sort of plan for retirement of this data when it's no longer being used.
We even have to think about how we destruct data. If we have data and we are deleting the data and we don't do anything else with it, there are opportunities where others can look at that and be able to extract the data back out of that. That is, I can't just delete information off of my personal laptop and donate it, because somebody could grab the information off of that laptop that I thought was deleted. Same thing with your businesses: you don't want customer data to get out there because you donated a bunch of hard drives that didn't have the data properly deleted.
So here are some long-term storage technologies, how a lot of them work, and what to watch out for. What happens is there's a part on these drives that actually stores the data. Let's say that each one of these is a little file here, and we'll talk about a specific file — maybe it's file number four here, and it's outlined in the blue right here. It's actually in different parts of the drive as well. It's not all in one spot; it actually is sprinkled throughout this drive. Now, up here we've got pointers to how to access this file. A lot of systems, what they'll do is when you go and delete a file, it just deletes this pointer and not the actual data. It's as simple as taking a software, and it's really easy to do — you can download this software — it takes a look at the data that still exists on this drive and it can extract that, or restore that pointer up here. So now they have access to that data.
There are processes and special software that will actually help us do the erasing or wiping. If we just did a standard format, that would wipe out just parts of this disc, still leaving a lot of the data behind. What we have to do is a more in-depth formatting of the drive, or an official erasing or wiping of the drive. What that will do is write out ones and zeros on here to go and officially wipe out the data and not have that data on there. There's special software that can help you do this.
Now, with businesses, a lot of times we have these RAID systems that have tons of hard drives on them, and so it becomes really cumbersome to deal with this on any small scale. So sometimes what we do, rather than erasing or wiping the drives, is we actually go through a degaussing, which is using magnets to be able to wipe out those ones and zeros. Or a shredding, where the drives actually get crushed or shredded. We can do incineration, where we actually burn this. Or some sort of drilling, where we actually drill the media so that way there's a bunch of holes in it and it makes it more difficult to recover this data.
A lot of hard drives are actually pretty hard to damage. I've taken drives before and I've tried to drill them, and it's really hard metal that they use. So a lot of times what we'll do is outsource this to some sort of third party, somebody that's certified in the proper destruction of this media. We'd actually call them up and say, hey, we've got an order for you, can you come pick it up? And they would actually come pick it up and then physically shred it, or have some sort of official process that they would go through to properly destruct the data and make sure that it's unrecoverable.
So data has a life cycle to it. It has a creation point, it has a point at which we need to manage it, and then we have a destruction point, and we need to think about that destruction and how we destruct it. Not only that, but a lot of times it's because we're getting rid of a piece of equipment, and it's more of a reactive, now it's time to get rid of this data and destruct it properly. But we really should be thinking about things along the way, of how we get rid of data so we're not holding on to it for longer than its useful life.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →