A data record does not live in one database row. Copies can appear in search indexes, cached responses, browser storage, export artifacts, worker queues, logs, and backups. A deletion action that removes only the primary row may leave several usable copies. This track maps those stores, ties each copy to a retention purpose, treats export and erasure as authorized jobs, and prevents old backups from resurrecting deleted records. Product and legal policy set actual retention periods; the lessons focus on the engineering contracts needed to implement and verify those decisions.
Topics in this track
- Retention Inventory and Expiry Workflows — Map every copy of a private record and make expiry observable across primary and derived stores.
- Export and Erasure Job State — Represent data requests as authorized jobs with terminal evidence and recoverable failure states.
- Backup Restore with Deletion Tombstones — Prevent old snapshots from reviving data that was removed after the backup was taken.
- Browser Storage Cleanup on Account Change — Clear private browser state when identity changes without making client cleanup the only security control.
Prerequisite paths
Browser Security and Data Stewardship; Backup and Restore Drills; Large Export Download and Integrity.
Neighbor track
Authorization and Tenant Boundaries.
Practice path
Build Project: verified data expiry and check decisions in Web Development: authorization and data lifecycle decisions quiz.
