Storage got cheap, and we all quietly changed our habits because of it. Nobody deletes anything anymore. The mailbox goes back eleven years. The file server has a folder called “Old Server” that contains a folder called “Old Server 2.” None of it costs enough per month for anyone to bother.
We would like to argue the other side. Before we do, a plain statement: this is general information, not legal advice. Retention requirements come from tax law, employment law, industry regulation, contracts, and litigation obligations, and only an attorney who knows your business can tell you what you must keep and for how long. What follows is how we think about the operational side, and why holding everything forever is a decision most businesses have made without noticing.
Old Data Is Still Data You Can Lose
Here is the simplest way to put it. Every record you hold is a record that can be exposed. Data you deleted five years ago cannot appear in a breach notification or be produced in discovery. Data you kept because deleting felt risky is available for both.
The math on a breach makes this concrete. The Office of the Texas Attorney General states that a business must notify the Attorney General of a data breach affecting 250 or more Texans, no later than 30 days after discovering the breach, under the Texas Identity Theft Enforcement and Protection Act. Notice that the count is of people, not of recent people. A customer list from 2011 you never needed again still counts if it was in the system that got hit. That is arithmetic, not a scare tactic.
The Federal Trade Commission’s guide Protecting Personal Information: A Guide for Business makes the same point as a principle. Its second rule is Scale Down: keep only what you need for your business. As the guide puts it, if you have a legitimate business need for the information, keep it only as long as it is necessary. Its fourth rule is Pitch It: properly dispose of what you no longer need.
The Tension Nobody Resolves Cleanly
Retention is genuinely hard, and we will not pretend otherwise. Four forces pull in different directions.
- Business need. The reason you would keep something even if no law existed. Warranty history, project files you reference, the record that lets you answer a question in one call.
- Legal and regulatory requirements. Tax records, employment files, industry obligations. These set floors, and they vary by industry and record type. Attorney territory.
- Legal hold. When litigation is reasonably anticipated, the normal schedule stops for the affected material. A hold overrides your policy, and deleting on schedule during one is a serious problem. Your attorney says when it starts and when it lifts.
- Privacy pressure in the other direction. Texas House Bill 4, which created the Texas Data Privacy and Security Act, tells covered controllers to limit collection of personal data to what is adequate, relevant, and reasonably necessary for the purposes of processing. Whether that applies to you is a legal question, but the instinct is sound for anyone.
Most businesses resolve this tension by doing nothing, which always resolves in favor of keeping everything. We would rather see a company make the call deliberately, write it down, and revisit it yearly.
Build a Schedule by Category, Not by File
The mistake we see most often is trying to decide file by file. That project never finishes. Work in categories instead, and accept a category being slightly wrong over never deciding at all.
- List the categories you actually have. Financial records, employment and payroll files, customer records, project or job files, vendor contracts, email, marketing lists, security logs. Eight to fifteen categories covers most small businesses.
- Ask your attorney and accountant for the floors. For each category, the minimum you must keep. Do not guess at this. Write down what they tell you and the date they told you.
- Set a business need period on top of the floor. This is your call as the owner, and it is usually shorter than instinct suggests.
- Name an owner for each category. A schedule with no name next to it is a suggestion.
- Write down how each category gets disposed of. Deletion method for electronic records, shredding for paper, and what happens to backups. The FTC’s business guidance recommends a written records retention policy identifying what must be kept, how to secure it, how long to keep it, and how to dispose of it securely.
On disposal method, the standard is not complicated. The FTC’s Disposal Rule guidance, which applies to businesses that use consumer reports, describes reasonable measures as burning, pulverizing, or shredding papers, and destroying or erasing electronic files or media, so the information cannot be read or reconstructed. Whether that rule covers your business is another attorney question, but the standard is a sensible one to adopt regardless. If you hire a disposal contractor, that same FTC guidance describes due diligence including reviewing independent audits, obtaining references, and evaluating the contractor’s security policies.
Archiving Is Not Deleting
This distinction trips up more businesses than any other part of the topic. Archiving moves data somewhere cheaper and less accessible. Deleting removes it. Archived data is still yours, still discoverable, and still capable of appearing in a breach. Moving eleven years of email into an archive tier reduces your storage bill. It does not reduce your exposure by one record.
Archiving is the right answer when you have a genuine reason to keep something but no reason to have it readily available. It is the wrong answer when it is used to avoid the harder decision. Backups deserve the same honesty. If your schedule says customer records go away after seven years but your backup retention keeps a full copy indefinitely, the records did not go away. Ask your IT provider how long backups are held and whether deleted material ages out of them. Old copies in places nobody tracks are the same problem we described in our article on shadow IT and the hidden risk inside your own organization.
A Policy You Follow Beats a Perfect One You Ignore
We have read beautiful forty-page retention policies at companies where nothing had been deleted in a decade. We have also seen a two-page document taped inside a supply closet that the office manager followed every quarter. The second one is worth more, and it is not close.
An unfollowed policy is worse than no policy, because it documents a standard you did not meet. Start with something small enough to execute. One page, your categories, a period for each, a name, and a disposal method. Add a calendar reminder. Improve it next year. The businesses in the worst position after an incident are rarely the ones with imperfect policies, they are the ones with no defensible reason for what they had lying around, which is part of why we keep returning to what the Stryker cyberattack tells us about the threats facing every business.
The Bottom Line
Keeping everything is not caution, it is a decision to carry risk you are not using. Pick your categories, get the legal floors from a professional, set a period you can defend, name an owner, and write down how things get destroyed. Then follow it. Requirements change, so review the schedule annually and confirm the current rules rather than trusting a document you wrote once.
To say it once more: this is general information, not legal advice. Retention obligations depend on your industry, your contracts, your tax situation, and any active litigation, and an attorney must confirm what applies to your specific business before you delete anything.
Where we can help is the mechanical part: finding every place a category of data actually lives, understanding what your backups are really holding, and setting up disposal that runs the same way every quarter. If your retention plan is currently “we keep everything,” we would be glad to help you change that. Contact us today.
Sources:
Comments are closed