Skip to content

In 2030, someone asks about 2008. How long will it take to get an answer?

Retention requirements aren’t a storage problem. They’re an access problem with a burden of proof. This white paper shows how retention, deletion, and proof converge in a single dataset and what your archiving solution needs to be able to do to handle it.

✓ Three obligations: retain, delete, prove
✓ Standards landscape sorted: AO, HGB, GoBD, GDPR, ISO 27001
✓ Eight requirements as an evaluation framework for every archiving tool

For CDOs, CIOs, compliance officers, IT architecture, and quality management leadership
Database Archiving · Application Retirement · Data Governance

whitepaper-data-governance-en

 

 

 

 

 

 

 

 

 

 

 

70%
of the data in production databases consists of historical records that are no longer needed for operations but continue to incur costs.
7 digits
is the total annual cost when five to ten legacy systems continue to run solely as data repositories.
up to 50 years
Statutory retention periods apply. Data must remain retrievable, readable, and verifiable throughout this period.
The Real Thing

The exam isn't the time to start writing about the topic.

An application has technically reached the end of its lifecycle but cannot be shut down because its data is subject to a retention requirement. It continues to run, serving solely as a data repository, and ties up resources such as licenses, maintenance, operations, hardware, and specialized expertise—all of which are becoming increasingly scarce within the organization.

The second cost factor is invisible and relates to compliance: When a regulatory inquiry is received, the search begins in legacy systems, exported data, and spreadsheets. What on paper was a retention requirement turns out, in practice, to be a research task that takes anywhere from days to weeks.

Typical orders of magnitude
€50,000 – €200,000
per year for a legacy business process or ERP module to be phased out while continuing to operate
€1–5 million
per year for an inventory management mainframe at an insurance company
Days to weeks
Research per audit or information request, as long as the data remains in the legacy system
See the white paper for figures
MAIN THESIS OF THE WHITE PAPER

“Anyone who has the data but cannot make it retrievable, readable, and verifiable within a reasonable amount of time has failed to fulfill their obligation.”

white-paper-data-governance-chronos
Contents

What's in the white paper

From the three regulatory obligations, through the complex landscape of standards and the conflict of objectives between immutability and the obligation to delete data, to the calculated business case. Including the sections where we explain what our own tool cannot do.

Request the full white paper

The Three Obligations

Retention, deletion, and proof apply simultaneously and relate to the same dataset.

The Standards Landscape at a Glance

Four clusters ranging from AO and HGB to GoBD and GDPR, through ISO 27001, DORA, MDR, and industry-specific regulations.

Why the Standard Answers Aren't Enough

Backup, keep the legacy system running, DMS, or a custom solution. Four answers that don’t solve the problem.

Eight Requirements as a Checklist

Specific evaluation questions for each archiving tool, ranging from retention policies to procedural documentation.

The Conflict of Objectives

Immutability versus the obligation to delete data on the same storage medium, and the only reasonable responses to this conflict.

The Business Case

Where the ROI comes from, with a sample calculation over five years and three real-world case studies.

Get the whitepaper

THE SWITCH SETTING

Three Responsibilities, One Mechanism.

In many organizations, three different departments handle these responsibilities using three different tools. As long as these are separate processes, each audit is a project. Data governance for structured data brings them together around a single dataset.

01 Storage

Retention periods ranging from 6 to 50 years

Commercial law, tax law, industry-specific laws, and product liability laws prescribe retention periods. The retention period applies to the content itself, not to the application in which it was created.


TYPICAL SCOPE OF RESPONSIBILITY

To date: IT via backup and storage

02 Delete

GDPR Art. 5 and Art. 17

Personal data may not be retained longer than necessary and must be deleted upon request. This does not contradict the requirement to retain data, but rather represents an equally important obligation with a different focus.


TYPICAL RESPONSIBILITIES

Previously: Data protection through policies and lists

03 Proof

When, by whom, and on what basis

Both obligations are meaningless if their fulfillment cannot be verified. An auditor does not ask whether you deleted the data, but rather when, by whom, and whether the data record has been modified in the meantime.


TYPICAL RESPONSIBILITIES

Previously: Audit based on retrospective reconstruction

FROM PRACTICE

Three projects, three proven results.

Application Retirement and Database Archiving with CHRONOS. The complete case studies are available in the white paper.

BMW Group
3.75 million
records archived monthly

Growing production databases drove up licensing, storage, and operating costs, while traceability requirements prevented the system from being shut down.

Maintain traceability in accordance with IATF 16949 · Access without legacy systems
Anton Schlecker
7 legacy systems
decommissioned, 0% data loss

Insolvency proceedings with continuous access for courts, government agencies, and social security providers. Other providers considered the project unfeasible.

AS/400, Navision, Teradata, and others · 100% compliance with legal archiving requirements
KLS Martin Group
90%
Savings on storage and licenses

IT realignment following a merger: multiple legacy ERP systems consolidated centrally; compliance requirements automatically met.

Permanent access to archived data · after system migration
The follow-up question that keeps the conversation going
“If, in 2030, someone asks about a process from 2008: will a clerk simply click on a PDF, or will a legacy system have to be booted up again?”
From the chapter “Why Standard Answers Aren’t Enough”
35+ years
of shop floor experience
50 years
Audit-proof documentation
200+ plants
in active operation worldwide

Get the white paper, and then sign up for your live demo.

In 30 minutes, we’ll use your own data to show you how retention, deletion, and proof-of-compliance all come together in a single dataset. Specifically, using your data.