| Current-state assessment | Applications, stores, flows, existing rules, technical constraints, gaps, risks, and evidence quality. | Data, product, privacy, security, audit | Where remediation is needed and why |
| Retention schedule | Data category, purpose, trigger, duration, hold, archival, disposal, jurisdiction, owner, and source authority. | Legal, records, privacy, product | Which rule applies to each data class |
| Control requirements catalogue | Functional, technical, security, privacy, evidence, monitoring, and exception requirements. | Engineering, architecture, platform teams | What must be built or configured |
| Lifecycle and deletion design | Workflows for account closure, expiry, customer deletion, downstream copies, backups, failures, and reconciliation. | Product, engineering, operations | How approved policy becomes executable |
| Legal-hold and exception model | Authority, intake, scope, precedence, release, approval, logging, and escalation. | Legal, compliance, operations | When disposal must pause or vary |
| Implementation roadmap | Priorities, dependencies, work packages, owners, acceptance criteria, and sequencing. | Executives, programme and product leaders | What to implement first |
| Assurance and evidence pack | Test cases, results, sample evidence, limitations, unresolved risks, and remediation tracking. | Audit, customers, assurance, procurement | Whether controls operate as designed |
| Operating model and runbooks | Roles, procedures, monitoring, incident handling, reviews, reporting, and training requirements. | Operations, privacy, engineering | How controls remain effective after launch |