All insights

Governance & Audit

Retention Policy for Agent Conversation Logs

· 9 minute read

Keep the reconstructable packet as long as the decision must be defended. Keep raw chats only as long as purpose and CERT-In require. Those are different clocks. Write both.

The SDC manager was proud: they had never deleted anything. Three years of helpdesk chats sat in a warm bucket, including passwords people had pasted, disease names, and a minister's relative's mobile number. The DPO asked for the purpose of year-one chats. There was none, except that storage was cheap. The cheap store was now a warehouse of personal data without a lawful remaining purpose, and an RTI magnet, and a leak waiting for a curious contractor.

Retention for agent logs is a stack, not a single number. Purpose limitation says stop when the purpose ends. CERT-In says keep specified ICT logs at least 180 days, in India. Departmental and DARPG/NAI record schedules say how long a class of official record lives. CAG reconstructability says the packet of a decision lives with the decision. If you pick one number for all of that, you will either destroy the file or hoard the widow's chat.

Template for DPOs and SDC owners. 16 August 2026. Not legal advice. Confirm the live CERT-In PDF and your office's retention schedule — accounts often follow GFR appendices; establishment follows DARPG common schedules; substantive functions need a departmental schedule vetted with the National Archives.

Split the stores

Different objects, different clocks. Do not put them in one bucket with one TTL.
ObjectTypical clock (write your own)Why
Raw conversation textShort: purpose + a buffer; often closer to months than yearsPersonal data; high leak value
Eight-field action log (minimised)At least CERT-In 180 days; longer if it is the only ICT traceCyber floor + operations
Reconstructable case packetSame as the underlying decision's record classCAG, court, appeal
Prompt/policy versionsAs long as decisions they influenced must be explainedWhat rule applied
Consent replay recordsAs long as processing on that basis continues, plus a bufferBoard inspection
SIEM security telemetryCERT-In floor, then your SOC policyIncidents

The never-delete bucket is how those objects infect each other. A packet that must live seven years should not be stored only as a full chat that you are afraid to touch. Extract the packet early. Then the chat can die on time.

Write the policy as clocks, owners and destruction

Each object gets a clock, an owner post, a store, a legal hook (purpose, CERT-In, schedule paragraph), and a destruction method with two persons. Destruction that is 'we will think about it' is hoarding. Destruction that is a silent lifecycle rule nobody can explain is how you lose the packet. Minutes of a quarterly destruction, like a weeding committee, belong on the file.

Legal holds (court, vigilance, live RTI, live grievance) freeze the relevant objects. Write the freeze as a ticket, not as a permanent exception that becomes the new default.

Erasure is not the same clock

A Data Principal may, when operational duties apply, ask for erasure. That right is not absolute. You may still need the packet for a legal claim, a statutory record, or a security investigation. The honest design is: raw chat can often go; the speaking order and its packet often cannot; say which, in the reply. The companion piece on sovereignty and erasure in this site's earlier cluster is the rights view. This article is the clocks view. They must agree.

Two buckets

Objections

SOC wants everything forever for threat hunting. Answer: hunt on minimised action logs and network telemetry, not on three years of pasted passwords.

A vendor wants chats to improve the model. Answer: that is training. No. And it is a transfer of personal data dressed as quality.

The PIO wants chats forever for RTI. Answer: RTI does not require you to keep what you do not need. It requires you to disclose what you hold. Hoarding increases what you must protect and what you may have to sever.

Leadership says storage is cheap. Answer: breach, RTI and purpose-limitation are not.

A four-week playbook

  • Week 1: inventory stores that hold chats, packets, action logs, versions, consent records.
  • Week 2: assign a clock, owner, legal hook and destruction method to each. Split any mixed bucket.
  • Week 3: implement packet extraction at case close so chats can die without eating the file.
  • Week 4: run a weeding rehearsal on a staging copy. Write the legal-hold procedure. Brief the Board folio with the clocks.

File note you can paste

Subject: Retention of agent conversation logs and related objects.

Conversation logs are often personal data. They will be purpose-limited and will not be kept merely because storage is available. Specified ICT logs will meet the CERT-In 180-day floor in Indian jurisdiction. Reconstructable packets will follow the record-retention schedule applicable to the underlying decision, which may be longer. These clocks will be written per object, not as a single TTL.

A quarterly weeding with two officers will destroy what has expired, except legal holds. Vendor training on logs is prohibited. This note is not legal advice.

A one-page schedule you can annex

Columns: object, store, clock, legal hook, owner, destruction method, legal-hold flag. Rows: raw chat, action log, packet, prompt versions, consent replay, SIEM telemetry. Fill it in a morning. Argue it for a week. Then implement the packet-extraction job so the chat row can be short without eating the packet row. The annex is the policy. A narrative without the table will be quoted selectively.

Account records still follow whatever GFR appendix your DDO already uses. Do not invent a shorter clock for a bill packet because it was drafted by an agent. The machine does not reduce the life of a voucher. It may increase the number of objects you must split.

Air-gapped weeding needs the same two-person discipline as media transfer. A delete job that only the vendor can run is not weeding. It is a request. If you cannot destroy without them, you cannot claim purpose limitation. You can only claim a tenant.

Publish internally the next weeding date. Officers who need a hold must ask before that date. Surprise deletions are how legal holds are missed and how trust in the DPO dies. Surprise hoarding is how the warm bucket returns. Dates make both visible.

  • Extract packets at close, not at weeding day, when the chat may already be gone.
  • Never apply one TTL to a mixed bucket.
  • Never keep chats to 'see if we need them for training'. You have already answered that question: no.

Informational template. Confirm live CERT-In directions, DPDP commencement, DARPG/NAI schedules, GFR account-record appendices and counsel before you destroy or hoard.

How this survives CAG, RTI or the Board

“Retention Policy for Agent Conversation Logs” is not a workshop slide. A P6 Compliance/DPO will have to reconstruct a decision after the officer who clicked approve has been transferred. Write the artefact that lets a stranger replay the case: the log fields, the approval, the override, the register row.

Keep the reconstructable packet as long as the decision must be defended. Keep raw chats only as long as purpose and CERT-In require. Those are different clocks. Write both. India AI Governance Guidelines (November 2025) are guidelines, not a statute. DPDP still allocates fiduciary duty. Delegation of Financial Powers still allocates who may spend. Do not hide those instruments behind the word governance.

If you cannot show who acted, on which purpose, with which data class, and who could have refused, you do not have accountability. You have a chatbot with a charter PDF.

  • Name the owner of “AI log retention policy” inside the department, not the vendor.
  • Keep CERT-In-relevant logs in India for the required period.
  • Store overrides with a reason an auditor can read.
  • Put the workflow on the AI register before it touches a citizen.

Close this loop before the next CAB

Put “Retention Policy for Agent Conversation Logs” on the next change-advisory or bid-opening agenda as a single line item with an owner. If it cannot earn a line item, it will not earn a control. The owner should be a P6 Compliance/DPO, not “the vendor.”

Revisit the item when the model, the GeM term, the region, or the SI changes. “AI log retention policy” is not a one-time workshop. It is a watch item. Date the last check. Unsigned watch items are souvenirs.

Questions this usually raises

Can we delete conversation logs after 180 days because of CERT-In?
CERT-In's 28 April 2022 directions set a 180-day floor for specified ICT logs, in Indian jurisdiction. A floor is not a ceiling. It is also not a licence to destroy the administrative packet of a speaking order you must still defend. Split the stores.
Are chat logs personal data?
Often yes. If a person is identifiable from the prompt, the answer, or the metadata, DPDP can reach the log. Purpose-limit and lock access. Do not treat 'telemetry' as non-personal by slogan.
What do we keep for CAG if we delete chats?
The reconstructable packet: who approved, what was retrieved (IDs/hashes), what was proposed (hash or official text), what the officer signed, versions, override. That packet follows the record schedule for that class of decision, not the chat TTL.
Does a citizen erasure request wipe the packet?
Not automatically. Erasure under DPDP has limits; public-record and legal-claim needs remain. Take counsel. Do not promise a chat-delete button that pretends the speaking order vanished.

Sources