Data, GDPR and audit log
How long data is kept, how to turn purging on, and where to find who did what in the console.
Data retention
The setting is in GDPR (#/gdpr) or in the Data & GDPR tab of Settings.
| Setting | Default |
|---|---|
| Automatic deletion after expiry | off |
| Retention period | 90 days (1 to 365) |
| Archive data before deletion | no |
The purge runs every 6 hours over the detailed data of every module (events, flows, measurements, logs…). Some data is kept longer because it serves security or trend analysis:
| Data | Kept for |
|---|---|
| Hourly aggregates, SLA reports, compliance history | at least 365 days |
| Windows authentication failures | at least 1 year |
| Active Directory changes | at least 3 years |
| Console audit log | at least 365 days, up to 10 years |
| SIEM incidents | deleted only once resolved or closed |
| NetDiag network captures | 30 days |
A legal hold (retention required by legal proceedings) stops all purging until it is lifted.
Personal data
Most modules handle personal data: account names, IP addresses, a computer's network activity, file access. The most intrusive options are off by default and flagged in orange, such as open files and window titles in NetDiag. Lookups in Microsoft 365, Google Workspace, the directory and telecom lines are logged together with the name of the person looked up.
Remember to record each enabled module and its purpose (support, security, operations) in your register of processing activities. Connectors have Purpose (GDPR register) and Data concerned fields for this.
Audit log
The Audit Log (#/audit, administrators only) keeps a record of actions taken in the console: successful and failed sign-ins, two-factor authentication (including resets by an administrator), user creation and changes, role changes, settings changes, questions asked to the AI Assistant, sensitive lookups.
You can filter by action, entity, status and dates. The CSV export returns at most 10,000 rows.
Source: · FirstSI Docs · updated 2026-10-10