Agent skill

Backup Retention Erasure

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Manages backup and archive data under retention schedules and erasure obligations.

Apache-2.0Auto-check passedLegal & Compliance

Install Backup Retention Erasure

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill backup-retention-erasure -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills backup-retention-erasure --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/backup-retention-erasure .claude/skills/backup-retention-erasure && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
backup-retention-erasure
GitHub stars
301
Token cost
~3.6k tokens
SKILL.md length
1,188 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Manages backup and archive data under retention schedules and erasure obligations.

  • Works in 4 steps: Put the backup data "beyond use" —… → Ensure the data is deleted when the… → Document the approach and timeframe. → …
  • Tasks that involve Backup and disaster recovery
  • SKILL.md covers Overview, Legal Context, Backup System Types and… and Backup Retention Alignment, plus 4 more sections
  • Runs Python scripts from its folder

What it does

Backup Retention Erasure is an agent skill from mukul975/Privacy-Data-Protection-Skills. Manages backup and archive data under retention schedules and erasure obligations. Covers the technical infeasibility exception for backup deletion, backup cycle alignment with retention periods, restore-and-delete procedures, and interim protective measures during backup retention. Activate for backup deletion, archive erasure, backup retention, restore and delete, technical infeasibility queries.

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Backup and disaster recovery and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Backup and disaster recovery
  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the backup-retention-erasure skill to manage backup and archive data under retention schedules and erasure obligations”
  • “/backup-retention-erasure”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Put the backup data "beyond use" — ensure it cannot be accessed or used for any purpose.
  2. Ensure the data is deleted when the backup is next overwritten or rotated.
  3. Document the approach and timeframe.
  4. Inform the data subject of the backup deletion timeline.

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Backup Retention Erasure loads about 3.6k tokens when it runs, and up to ~5.1k if it reads all its reference files. Until then it costs about 107 tokens; SKILL.md has 1,188 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,188 words, ~3,608 tokens.

Download SKILL.mdSave it as .claude/skills/backup-retention-erasure/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
backup-retention-erasure
description
Manages backup and archive data under retention schedules and erasure obligations. Covers the technical infeasibility exception for backup deletion, backup cycle alignment with retention periods, restore-and-delete procedures, and interim protective measures during backup retention. Activate for backup deletion, archive erasure, backup retention, restore and delete, technical infeasibility queries.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
data-retention-deletion
metadata.tags
backup-retention, archive-erasure, restore-and-delete, technical-infeasibility, backup-lifecycle

Backup Retention and Erasure Management

Overview

Backup and archive systems present unique challenges for data retention and erasure compliance. Unlike primary systems where individual records can be selectively deleted, backup media typically stores data as monolithic sets that cannot be surgically modified without restoration. When a data subject exercises the right to erasure under GDPR Article 17 or when a retention period expires, the organization must address personal data residing in backups. The technical infeasibility of granular deletion from backups is a recognized limitation, but it does not exempt organizations from their obligations — it requires documented interim measures and eventual deletion through backup rotation or restore-and-delete procedures. This skill provides the operational framework for managing backup data under retention and erasure obligations.

GDPR Recital 66 — Erasure in Online Environments

The right to erasure should extend to cases where the controller has made the personal data public — the controller should take reasonable steps to inform other controllers processing the data. In the backup context, this principle requires that erasure obligations extend to backup copies even when immediate deletion is technically infeasible.

GDPR Article 17(1) — Right to Erasure

The controller shall erase personal data "without undue delay." The EDPB and national DPAs have acknowledged that backup systems may require a longer timeframe, but have not granted an indefinite exception. The expectation is that backup deletion occurs within the next backup rotation cycle.

ICO Guidance on Backup Deletion

The UK ICO has stated that where it is not technically feasible to erase data from backup systems immediately, the organization should:

  1. Put the backup data "beyond use" — ensure it cannot be accessed or used for any purpose.
  2. Ensure the data is deleted when the backup is next overwritten or rotated.
  3. Document the approach and timeframe.
  4. Inform the data subject of the backup deletion timeline.
EDPB Position

The European Data Protection Board has acknowledged in various guidelines that backup systems may present technical challenges for erasure. The general position is:

  • Immediate deletion from live/primary systems is expected.
  • Backup deletion should occur within a reasonable timeframe aligned with the backup rotation cycle.
  • During the interim period, the data in backups must be "beyond use" — not accessed for any purpose.

Backup System Types and Erasure Approach

Erasure Strategy by Backup Type
Backup TypeDescriptionGranular Deletion Possible?Erasure ApproachTypical Cycle
Full backup (disk-based)Complete copy of all data to disk storageGenerally no (restoring full backup and selectively deleting is possible but resource-intensive)Wait for rotation cycle; implement restore-and-delete for urgent requestsWeekly-Monthly
Incremental backup (disk-based)Only changes since last backupNoWait for rotation cycleDaily
Differential backup (disk-based)Changes since last full backupNoWait for rotation cycleDaily
Tape backup (LTO)Data written sequentially to magnetic tapeNo (tape is sequential; selective deletion impossible without full rewrite)Wait for tape rotation cycle; for extended retention tapes, consider restore-and-deleteMonthly-Annual
Cloud backup (managed)Cloud-based backup service (e.g., AWS Backup, Azure Backup, Veeam Cloud Connect)Depends on vendor — some support item-level recovery and deletionCheck vendor capability; if no granular deletion, wait for retention policy expiryPer configured policy
Snapshot-based backupPoint-in-time copies of storage volumesNo (snapshot is immutable)Wait for snapshot retention policy expiry; ensure policy aligns with retention scheduleDaily-Weekly
Database backup (logical)SQL dumps, export filesNo (dump file is a single file)Wait for rotation; or restore to temporary environment, delete, re-exportDaily-Weekly
Archive (cold storage)Long-term archival in cold/offline storage (e.g., AWS Glacier, Azure Archive, tape vaults)NoRestore-and-delete for erasure requests; or wait for archive retention policy expiryAnnual-Multi-year

Backup Retention Alignment

Aligning Backup Cycles with Retention Schedule

The backup retention period must not exceed the longest applicable data retention period. If backups retain data beyond the retention schedule, the organization holds data in violation of the storage limitation principle.

Backup Retention Configuration for Orion Data Vault Corp
Backup LevelRetention PeriodRotation CycleAlignment with Retention Schedule
Daily incremental30 daysOldest daily deleted after 30 daysShorter than all data category retention periods — compliant
Weekly full90 daysOldest weekly deleted after 90 daysShorter than all data category retention periods — compliant
Monthly full12 monthsOldest monthly deleted after 12 monthsShorter than most retention periods; CCTV (30 days) and unsuccessful applicant data (6 months) may need specific exclusion
Quarterly archive24 monthsOldest quarterly deleted after 24 monthsCovers marketing data (2 years); need to verify no shorter-retention categories are included unnecessarily
Annual archive7 yearsOldest annual deleted after 7 yearsAligned with longest statutory retention (financial records: 6-7 years)
Show full SKILL.md (425 more words)Show less
Gap Analysis
[For each data category in the retention schedule]
         │
         ▼
[What is the retention period?]
         │
         ▼
[Is this data included in backup sets that are retained longer than the retention period?]
   │
   ├── No ──► Compliant — backup rotation will delete data before or at retention expiry
   │
   └── Yes ──► COMPLIANCE GAP
               │
               ├── Option A: Exclude this data category from long-retention backup sets
               │     (segregate data by retention tier; back up separately)
               │
               ├── Option B: Reduce backup retention to match the shortest data category
               │     (may conflict with business continuity requirements)
               │
               └── Option C: Accept interim retention in backups with protective measures
                     (document "beyond use" controls; delete at next rotation)
                     MAXIMUM acceptable overshoot: 90 days beyond retention period

Restore-and-Delete Procedure

For situations where backup deletion cannot wait for the rotation cycle (e.g., urgent Art. 17 requests, DPA enforcement):

PROCEDURE: RESTORE-AND-DELETE
Organization: Orion Data Vault Corp
Procedure ID: BKP-RAD-001

TRIGGER: Art. 17 erasure request where data exists only in backups
         and backup rotation will not occur within an acceptable timeframe

PREREQUISITES:
- All primary system deletion confirmed complete
- Backup system granular deletion confirmed infeasible
- DPO has approved restore-and-delete approach
- Next backup rotation > 90 days away

PROCEDURE:

Step 1: Identify Relevant Backup Sets
   - Query backup catalog for sets containing data subject's data
   - List all relevant backup sets with dates and storage locations
   - Estimated effort: [hours/days]

Step 2: Provision Isolated Restore Environment
   - Create isolated network segment (no connectivity to production)
   - Provision temporary storage sufficient for backup restoration
   - Apply access controls (authorized personnel only)
   - Enable full audit logging

Step 3: Restore Backup to Isolated Environment
   - Restore the backup set(s) to the isolated environment
   - Verify restoration integrity (checksum validation)

Step 4: Execute Granular Deletion
   - Identify and delete the data subject's records from the restored data
   - Verify deletion (query for data subject's identifiers — zero results expected)

Step 5: Create Replacement Backup
   - Export the cleaned data as a replacement backup set
   - Verify replacement backup integrity
   - Store replacement backup in the same tier as the original

Step 6: Destroy Original Backup
   - Delete or overwrite the original backup set containing the data subject's data
   - If tape: degauss and destroy the original tape
   - If disk: secure overwrite of original backup files
   - Generate destruction confirmation

Step 7: Decommission Restore Environment
   - Securely wipe the isolated restore environment
   - Release temporary storage
   - Disable the isolated network segment

Step 8: Documentation
   - Record all steps in the deletion confirmation record
   - Update the data subject's erasure request file with backup deletion confirmation
   - Log total time and resources consumed (for future planning)

ESTIMATED TIMELINE: 5-15 business days depending on backup size
ESTIMATED COST: [Track for each execution — informs cost-benefit analysis]

Interim Protective Measures ("Beyond Use")

While personal data remains in backups pending rotation or restore-and-delete, the following interim measures must be in place:

"Beyond Use" Controls
ControlImplementationVerification
Access restrictionBackup restoration requests require DPO approval for any data that has been deleted from primary systems or has exceeded retentionQuarterly audit of backup restoration requests
Purpose restrictionBackup data may only be accessed for disaster recovery or business continuity — not for operational use, analytics, or data subject requestsPolicy documented; staff trained
Restoration screeningIf a backup containing deleted data must be restored for DR purposes, the deleted records must be re-deleted from the restored environment before it goes into productionRestoration procedure includes deletion checklist
Suppression listMaintain a suppression list of data subjects whose data has been deleted from primary systems. Cross-reference against any backup restoration to ensure re-deletionSuppression list checked at every restoration event
EncryptionAll backup media is encrypted (AES-256). Encryption keys are managed separately. In extreme cases, destruction of the encryption key can render backup data irrecoverableAnnual key management audit
LoggingAll backup access, restoration, and deletion events are logged in an immutable audit trailMonthly audit log review

Backup Restoration Procedure (with Erasure Compliance)

When a backup must be restored for disaster recovery and it contains data that has been deleted from primary systems:

[Disaster Recovery Event — Backup Restoration Required]
         │
         ▼
[Select Appropriate Backup Set for Restoration]
         │
         ▼
[Check: Does this backup pre-date any completed erasure requests or retention expiry deletions?]
   │
   ├── No ──► [Restore normally — no erasure compliance action needed]
   │
   └── Yes ──► [Retrieve Suppression List]
               │
               ▼
         [Restore backup to production environment]
               │
               ▼
         [IMMEDIATELY execute deletion of all records matching suppression list]
               │
               ├── Automated: Run deletion script against suppression list
               │   (pre-built script must exist — test quarterly)
               │
               └── Manual (if automated script fails): Assign to data team
                   with 24-hour SLA for completion
               │
               ▼
         [Verify deletion — zero records for suppressed data subjects]
               │
               ▼
         [Log re-deletion event in erasure confirmation records]
               │
               ▼
         [Resume normal operations]

Compliance Monitoring

Quarterly Backup Retention Audit
CheckMethodExpected Result
Backup retention periods align with retention scheduleCompare backup retention configuration against current retention scheduleNo backup tier retains data longer than the longest applicable retention period
"Beyond use" controls activeReview access logs for backup restoration; verify DPO approval obtained for all restorations of post-deletion backupsZero unauthorized restorations
Suppression list currencyVerify suppression list includes all data subjects deleted from primary systems since the oldest backup set date100% coverage
Rotation complianceVerify oldest backup set date matches expected rotation dateWithin 7 days of expected rotation
Encryption verificationVerify all backup media is encrypted100% encryption coverage
Restore-and-delete executionFor any pending restore-and-delete operations, verify progress and timelineAll operations within committed timeline
Metrics Reported to DPO
MetricTargetFrequency
Average backup retention overshoot (beyond retention schedule)≤ 90 daysQuarterly
Restore-and-delete completion time≤ 15 business daysPer execution
Suppression list size (active entries)Track trendMonthly
Backup restoration events requiring re-deletionTrack countQuarterly
Backup sets containing data beyond retention periodZero (after rotation cycle)Monthly

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/backup-retention-erasure of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Backup Retention Erasure next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Backup Retention Erasure compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Backup Retention Erasure this skillmukul975/Privacy-Data-Protection-Skills301—~3.6kAutomated safety check: PassApache-2.0
Twinmind Security Basicsjeremylongshore/tons-of-skills-marketplace2.8k—~932Automated safety check: PassMIT
Add Session Recordinggotempsh/temps833—~1.9kAutomated safety check: PassApache-2.0
Storage S3 Resiliency Expertiseaws/tools-for-devops-agent103—~2.8kAutomated safety check: PassApache-2.0
Policy OpaAgentSecOps/SecOpsAgentKit2201 repos~3.5kAutomated safety check: PassCustom licence
Backup Recoverysickn33/agentic-awesome-skills47k2 repos~3kAutomated safety check: WarnMIT

Similar skills

  • Twinmind Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Security best practices for TwinMind: on-device audio processing, encrypted cloud backups, microphone permissions, and data privacy controls.

    2.8k GitHub stars~932 tokensUpdated yesterday
    Media & CreativeAuto-check passed
  • Add Session Recording

    gotempsh/temps

    Add privacy-aware session recording and replay to React applications using the Temps SDK.

    833 GitHub stars~1.9k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Storage S3 Resiliency Expertise

    aws/tools-for-devops-agent

    Official

    S3 resiliency, security, and data protection review. An agent skill from aws/tools-for-devops-agent.

    103 GitHub stars~2.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Policy Opa

    AgentSecOps/SecOpsAgentKit

    Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

    220 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed
  • Backup Recovery

    sickn33/agentic-awesome-skills

    Implement backup and recovery strategies. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~3k tokens
    DevOps & CloudAuto-check: warnings
  • Protects data itself rather than the systems around it — classifying what you hold, encrypting in transit and at rest and understanding what each actually defends against, managing keys and their…

    2k GitHub stars~1.3k tokensUpdated 23 days ago
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Backup Retention Erasure

What does Backup Retention Erasure do?

Manages backup and archive data under retention schedules and erasure obligations. Backup Retention Erasure is an agent skill from mukul975/Privacy-Data-Protection-Skills. Manages backup and archive data under retention schedules and erasure obligations.

When should I use Backup Retention Erasure?

Backup Retention Erasure fits situations like: tasks that involve Backup and disaster recovery; tasks that involve Privacy and GDPR.

How do I install Backup Retention Erasure in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill backup-retention-erasure -a claude-code`. Or copy the skill folder (skills/privacy/backup-retention-erasure in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/backup-retention-erasure in your project. Claude Code loads it when a task matches its description.

How do I install Backup Retention Erasure in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill backup-retention-erasure -a codex`. Or copy the skill folder (skills/privacy/backup-retention-erasure in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/backup-retention-erasure in your project. Codex loads it when a task matches its description.

Can I use Backup Retention Erasure in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill backup-retention-erasure -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/backup-retention-erasure, .gemini/skills/backup-retention-erasure, .github/skills/backup-retention-erasure and .opencode/skills/backup-retention-erasure in your project.

What does Backup Retention Erasure need to run?

Going by SKILL.md and its folder, Backup Retention Erasure needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Backup Retention Erasure access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Backup Retention Erasure safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Backup Retention Erasure use?

Backup Retention Erasure is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Backup Retention Erasure use?

About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Backup Retention Erasure?

Skills that share tags, products or a category with Backup Retention Erasure: Twinmind Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Add Session Recording (gotempsh/temps, 833 stars), Storage S3 Resiliency Expertise (aws/tools-for-devops-agent, 103 stars) and Policy Opa (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Backup Retention Erasure?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.