— a multi-niche blog

How e-Pragati structures its data retention schedule

e-Pragati started as an enterprise architecture push inside the Government of Andhra Pradesh, stitching together dozens of departments onto a single ICT backbone. The platform's data retention schedule sits at the heart of that effort, setting out how long different classes of information stay on servers, when they move to archive storage, and when they get destroyed. For anyone outside India, the document is best read as a working reference rather than binding law, and the e-Pragati blog publishes it alongside other unofficial reference material to help practitioners compare approaches.

Australian readers will find familiar echoes in the schedule. The five-year tax recordkeeping window enforced by the ATO, the seven-year horizon used by the National Archives of Australia for administrative records, and the retention rules baked into state archives like State Records NSW and the Public Record Office Victoria all sit comfortably alongside what e-Pragati prescribes. The platform's catalogue is broad enough to be useful as a checklist for ICT managers in Sydney councils, Melbourne universities, or Brisbane hospitals who are reviewing their own recordkeeping policies.

Why a retention schedule matters for large ICT platforms

A retention schedule is not the same as a backup policy. Backups protect information from being lost; a schedule decides when information should no longer be kept at all. For a platform serving millions of citizens, the difference is critical. Without a clear schedule, databases grow without bound, legal holds become harder to apply, and the cost of storage creeps up year after year. e-Pragati's schedule addresses these pressures by tagging each dataset with a lifecycle, from creation through active use, archival, and eventual disposal.

The Australian experience mirrors this. When the My Health Record system was being rolled out, retention questions dominated public debate, with the Digital Health Agency eventually settling on a long retention horizon for adult records to match the long tail of medical relevance. e-Pragati's schedule is less dramatic but more granular, distinguishing between transient logs, operational metadata, and substantive records that document government decisions.

For IT teams working on shared services or whole-of-government platforms, the schedule offers a template. It separates concerns that are often blurred in practice: how long to keep working copies, how long to keep authenticated versions, and how long to keep metadata needed for audit trails. That separation matters when an incident occurs and investigators need to reconstruct events without combing through years of irrelevant data.

Record categories and how long they last

The e-Pragati schedule breaks its information assets into roughly a dozen classes. Application logs, security event logs, and system monitoring data carry the shortest retention windows, typically 90 days to one year, because they are high-volume and low-value once their immediate diagnostic purpose is served. Identity records for citizens and employees sit in a middle band, generally five to seven years after the relationship ends, which aligns with what most Australian agencies would consider a defensible minimum.

Financial records, project files, and policy documents occupy the longer end. These are kept for ten years or more, reflecting both statutory limitation periods and the practical need to refer back to major decisions. In Australia, the ATO requires tax-related records to be kept for five years from the date of preparation or transaction, and many government agencies extend that to align with the National Archives' general administrative records disposal authority. e-Pragati's ten-year floor for financial data is therefore on the conservative side, which is why some Australian practitioners treat the schedule as a ceiling rather than a baseline.

A small but interesting category covers reference data and public information assets. The e-Pragati blog itself maintains a running feed of commodity prices, and the https://e-pragati.org/gold-rate-today page is a good example of how the platform treats short-lived reference data. Historical rate data is kept for analytical purposes, but the operational logs behind the page refresh on a much shorter cycle. Distinguishing between the data product and the operational metadata around it is one of the more useful habits the schedule encourages.

What starts the retention clock

Retention periods are meaningless without a clear trigger. The e-Pragati schedule defines several starting points, depending on the record type. For project records, the clock starts when the project is formally closed. For employee records, it starts when the person leaves the organisation. For financial records, it starts at the end of the financial year in which the transaction was recorded. For complaint and grievance records, it starts when the matter is resolved, with extensions if a review is still open.

Australian agencies tend to follow similar logic, though the wording varies. The National Archives' general retention authorities use the concept of a reference date, which is usually the date of last action or the date the record ceases to be in active use. State records authorities in NSW, Victoria, and Queensland use comparable language. e-Pragati's contribution is to make the trigger explicit for each class, which removes the ambiguity that often plagues internal retention policies in mid-sized Australian councils and agencies.

One subtle point is that triggers can be paused. If a record becomes subject to a legal hold or a freedom-of-information request, the disposal timer stops until the hold is released. This is standard practice in Australian jurisdictions too, but the e-Pragati schedule spells it out for each category, which helps administrators avoid the common mistake of disposing of records that are still needed for active litigation.

How e-Pragati compares with international and Australian standards

The schedule draws heavily on ISO 15489, the international standard for records management, and on the principles behind ISO 27001 for information security. It maps each data class to a control objective, which makes it easier for auditors to verify compliance. Australian government agencies operating under the PSPF and the Information Security Manual will recognise the same structural logic, even if the specific control numbers differ.

Privacy is where the comparison gets interesting. Australia has progressively strengthened protections around automated decision-making and clarified the operation of the Australian Privacy Principles, particularly APP 11 and APP 12, which govern data security and access. e-Pragati's schedule reflects an earlier regulatory environment, but the underlying principles of purpose limitation and disposal are compatible. Australian practitioners reading the schedule should treat it as a structural reference, then overlay the current APP requirements on top.

There is also a practical crossover with consumer reporting. Retention decisions affect not just government data but also the information that flows into credit reports, insurance assessments, and identity verification. A clear-eyed look at how long various records should live is useful context for anyone reviewing their own data footprint, which is partly why pieces like why your credit report matters have become popular reading among Australian consumers trying to understand their digital trail.

Practical takeaways for Australian ICT teams

The most useful exercise for an Australian ICT team is to map its own data assets against the e-Pragati categories. Most teams will find they have at least one class of record that has no defined retention period at all, which is a compliance gap under the Archives Act 1983 for Commonwealth agencies and under the various state records acts for public sector bodies. The e-Pragati list provides a starting point for filling those gaps.

Another takeaway is the value of tagging data at creation rather than at disposal. e-Pragati's schedule assumes that records are classified when they enter the system, with metadata that travels with them through their lifecycle. Australian agencies moving to cloud-native architectures under the Whole-of-Government Hosting Strategy often struggle with this, because legacy systems were not designed to carry classification metadata through data lakes and API exports. The schedule is a good prompt to revisit classification schemes, and frankly it saves a lot of headaches down the track when someone in the audit team asks why a particular dataset has no disposal date attached.

Finally, the schedule is a reminder that disposal is a positive act, not a failure of archiving. Keeping everything forever is not a virtue; it is a liability under the Privacy Act and a cost under any storage model. The e-Pragati approach of explicit, time-bounded retention is one that Australian privacy officers have been pushing for years, and seeing it codified in a working platform provides useful ammunition for internal conversations.

Finding the schedule and related resources

The full schedule is published on the e-Pragati blog as part of its reference library, and the most reliable entry point is the https://e-pragati.org/sitemap, which lists every document, guide, and data feed available on the site. The sitemap is updated regularly and is the fastest way to locate the most recent version of the retention table, along with associated guidance on classification, disposal authorities, and audit trails.

Readers who want to dig deeper into the platform's overall structure can use the same sitemap to find material on enterprise architecture, the associated academy programmes, and procurement frameworks. The blog also publishes background pieces on cybersecurity, leadership in digital transformation, and practical references for ICT managers. Because the site is explicitly an unofficial reference rather than an official government publication, the materials are best treated as comparative reading rather than authoritative interpretation.

For ongoing reference, Australian readers may also want to bookmark the Australian Signals Directorate's Essential Eight guidance, the OAIC's guidance on the Notifiable Data Breaches scheme, and the retention authorities issued by their own state or territory records office. Used together with the e-Pragati schedule, these resources form a reasonably complete picture of how long public sector information should live, and when it should be allowed to go.

Record class e-Pragati retention Typical Australian equivalent Common trigger
Application and system logs 90 days to 1 year 90 days to 1 year (PSPF, ISM) Date of generation
Identity and access records 5–7 years after relationship ends 7 years (Privacy Act, APP 11) End of access relationship
Financial and procurement records 10 years 5 years (ATO); 7 years (Archives Act) End of financial year
Project and policy records 10+ years 7+ years (state records acts) Project closure
Complaint and grievance records 5 years from resolution 5–7 years Date of resolution
Reference and public data feeds Varies; product kept, logs short Varies by agency Last refresh or last reference

If you're an Australian practitioner working on retention policy in a public sector context, the e-Pragati schedule is a useful comparative document, but it should be read alongside the National Archives' retention authorities, the ATO's recordkeeping rules, and the relevant state or territory archives guidance. The e-Pragati blog is a convenient place to start, and the sitemap is the easiest way to navigate the available material. Spend an afternoon mapping your own data assets against the e-Pragati categories and you'll quickly see where the gaps are. It's a fair dinkum way to get your house in order before the next audit cycle rolls around, and it will leave you better prepared when the OAIC comes knocking or when a freedom-of-information request lands on someone's desk at 4:45 on a Friday arvo.

— get in touch

Have a question or want to reach out?