Skip to main content

Using expiry

Set an end date on data rules when the access has a temporary purpose.

When to use this​

  • Use it for projects with a start and an end.
  • Use it for investigations, one-off audits, or temporary cover.
  • Use it when the access is sensitive and should be revisited automatically.

Before you start​

  • Decide on the date or period needed.
  • Confirm whether the user or group will need to renew the access afterwards.
  • Tell the requester about the agreed deadline.

Step by step​

  1. When creating or editing a rule, find the expiry option.
  2. Choose the access's end date.
  3. Check that the deadline matches the purpose.
  4. Simulate the rule where available.
  5. Save it and tell the requester the deadline.

What happens next​

  • The access stops applying when the expiry is reached.
  • The rule stays traceable for auditing.
  • The user has to request a renewal if they still need the data.

Common errors​

  • Too short an expiry: it can interrupt work in progress.
  • Too long an expiry: it raises exposure unnecessarily.
  • Forgetting to communicate the deadline: it comes as a surprise when the access ends.

Good practice​

  • Use standardized deadlines per request type.
  • Review rules with no expiry more often.
  • Prefer renewing with justification over granting an indefinite period.

Next steps​