A data retention policy decides how long records remain available, why they are kept, when the clock starts, and how deletion is verified. The useful version is not a page of vague promises. It is a schedule connected to systems, owners, legal holds, backups, and repeatable disposal.
This guide is not legal advice. Required periods depend on jurisdiction, industry, contracts, record type, disputes, audits, and investigations. Confirm mandatory periods with qualified counsel and the responsible business owner before deletion.
Why "keep everything" is not a safe default
Unlimited retention increases breach impact, discovery burden, storage cost, access complexity, and the chance that obsolete data will be reused incorrectly. Deleting too soon can also violate a duty or destroy records needed for operations, taxes, claims, security, or a legal hold. The goal is a defensible period tied to a real purpose.
The FTC's business data guidance recommends keeping sensitive information only while there is a legitimate business need and disposing of it securely. That principle still requires an organization-specific schedule.
1. Inventory record categories, not random files
Group records by purpose and obligations. Examples include prospects, customer contracts, service records, invoices, tax documents, employee records, support messages, account profiles, uploads, call recordings, analytics events, security logs, consent records, backups, and system audit trails.
For each category, identify the system of record, copies, exports, integrations, owner, sensitivity, people with access, and the event that should start retention. Use the website privacy mapping checklist to discover online collection points.
2. Separate four reasons for retention
| Reason | Question | Evidence |
|---|---|---|
| Operational | How long is the record needed to deliver or support the service? | Process map and service owner decision |
| Legal/regulatory | Does a rule require a minimum or maximum period? | Counsel-reviewed requirement register |
| Contractual | What do customer, vendor, insurer, or funding terms require? | Current contract clause and owner |
| Risk/evidence | What period supports claims, fraud review, security, or audit? | Documented risk rationale |
Do not let the longest period from one category become the default for all data. A tax record, an unresolved contract, a marketing lead, and a failed login event have different purposes and consequences.
3. Define the trigger as carefully as the period
"Keep for seven years" is incomplete without a starting event. Possible triggers include creation, last activity, transaction completion, contract end, account closure, employment end, consent withdrawal, issue resolution, supersession, or incident closure.
Use a trigger the system can detect. If nobody can reliably determine when a relationship ended, the schedule will not run. Add fields or workflow events before promising automated deletion.
4. Write the schedule
Retention schedule row
Record category: ______
System of record and known copies: ______
Business owner: ______ Technical owner: ______
Purpose and authority: ______
Trigger: ______ Period: ______
Hold rule: ______
Deletion or anonymization method: ______
Backup treatment and verification evidence: ______
5. Design legal and investigation holds
A hold suspends normal deletion for records relevant to a dispute, investigation, audit, incident, or other defined matter. Document who can issue and release a hold, its scope, affected systems, custodians, notification, preservation steps, review date, and release evidence.
Do not make every record subject to an indefinite informal hold. Overbroad holds defeat the schedule. Counsel should direct legal holds; security and compliance owners may need parallel procedures for incidents and audits.
6. Account for backups and derived data
Deleting a production row may not instantly remove it from protected backups. Document the backup rotation, restore restrictions, isolation, expiration, and what happens if an older backup is restored. A common control is to prevent ordinary access to expired data in backups and reapply deletion rules after restoration, subject to applicable obligations.
Also identify caches, search indexes, analytics aggregates, data warehouses, exported spreadsheets, email attachments, logs, sandbox copies, and machine-learning datasets. The schedule should say whether data is deleted, irreversibly anonymized, aggregated, or retained under a different justified category.
7. Choose a disposal method that matches the medium
- Use application and provider deletion mechanisms that remove active access and propagate to replicas as documented.
- Securely destroy paper and retired media containing sensitive information.
- Revoke links, tokens, shares, and access grants associated with deleted records.
- Validate that vendor termination includes return or deletion of data.
- Keep enough evidence to prove the process ran without retaining the deleted content itself.
8. Minimize data at intake
Retention is easier when collection is deliberate. The service-business call intake template shows how to capture enough information for action without inviting sensitive detail into free-text notes. For social evidence, the proof-without-oversharing guide applies the same minimum-necessary principle.
9. Automate carefully and keep exceptions visible
- Test the rule on a report before deleting.
- Exclude active holds and document the exclusion logic.
- Start with a narrow category whose trigger and owner are reliable.
- Log counts, rule version, run time, failures, and approver.
- Sample results and verify downstream copies.
- Provide a controlled pause and rollback for configuration errors, not a permanent archive of deleted data.
10. Review the schedule as systems change
Review at least annually and whenever a new system, data type, vendor, law, contract, acquisition, incident, or business process changes the rationale. Connect the schedule to the cybersecurity inventory and response plan so teams know what exists before an incident.
Quality gate
- Every category has a business and technical owner.
- Every period has a documented purpose or requirement.
- Every trigger can be determined from a system or controlled record.
- Holds can suspend and release deletion without ambiguity.
- Backups, exports, vendors, and derived stores are addressed.
- Deletion is tested, logged, and reviewed.
- Public disclosures do not promise behavior the schedule cannot perform.