Data retention addresses how the service stores and retains any data from the device or device's user(s). A data retention policy should be summarized in the overall privacy policy, and should clearly indicate:
- What data is stored/collected and archived
- When and how the data will be pushed or pulled from the device or mobile application
- When and how data is destroyed
- Any metadata or derived information that may be stored (aside from the IoT raw data)
- How long the information will be stored (both during and after the life of the account to which it pertains)
- If any controls/services are available to the end user to scrub any data they generate
- Any special mechanisms for data handling in the event of legal issues or law-enforcement ...