A data retention policy is an organization’s written rules for how long it keeps each type of record and data, where those records are kept and how they are disposed of when the retention period ends. It usually takes the form of a retention schedule listing record categories, such as invoices, contracts, employee files, emails, call recordings and system logs, with a period and an owner for each, plus rules for legal holds and secure deletion. A good policy balances two pressures: keeping records long enough to meet legal, regulatory and business needs, and not keeping them longer than necessary. This entry is an overview, not legal advice.
At a glance
- A retention policy sets minimum and often maximum periods for each record type, plus disposal methods.
- Periods are driven by laws, regulations, contracts, litigation risk and business need, and they vary by jurisdiction and industry.
- Legal holds pause deletion for records relevant to litigation, investigations or audits.
- Privacy laws in many places discourage or limit keeping personal data longer than needed.
- Policy and technology must match: SaaS, email, phone and backup settings need to enforce the schedule.
What problem it solves
Without a retention policy, organizations tend to fall into one of two traps. Some keep everything forever, which raises storage costs, slows discovery in lawsuits, and enlarges the amount of data exposed in a breach. Others delete data inconsistently, so a record a regulator or court expects is gone, or deletion happens after a lawsuit was foreseeable.
A retention policy gives each record type a defensible period, a named owner and a disposal method. It also helps buyers configure the many systems that now hold records, such as Microsoft 365, Google Workspace, UCaaS call recordings, contact center platforms and CRM, each of which has its own default retention behavior.
How it works
Inventory record types. Work with legal, finance, HR and IT to list the categories of records you create and where they live. Data classification helps identify sensitive and regulated types such as protected health information (PHI).
Set periods. For each category, counsel identifies legal and regulatory minimums, contract requirements and any maximums from privacy laws such as the General Data Protection Regulation (GDPR), then the business adds operational needs. The result is a retention schedule.
Define disposal. Specify how records are deleted or destroyed at the end of the period, for paper and electronic records, including copies held by providers.
Handle legal holds. Define who can issue a hold, how it is applied in each system and how it is released. Holds override routine deletion.
Configure systems. Apply retention labels and policies in email, file storage, collaboration and communications platforms; set log retention for audit trails; and confirm what each SaaS provider keeps and deletes by default.
Review. Revisit the schedule when laws, systems or business lines change, and check periodically that systems actually follow it, as part of data governance.
When it matters for buyers
- When choosing SaaS, UCaaS, contact center or email providers. Check default retention, configurable periods, export options and deletion at contract end.
- When buying backup or archiving. Decide which tool holds records for compliance and which holds recovery copies; see backup as a service (BaaS) and SaaS backup.
- When a regulator, auditor or litigation asks for records. You need to know what exists and where.
- When leaving a provider. Make sure records you must keep come with you before the provider deletes them.
Our governance, risk and compliance and backup as a service overviews cover tools for retention, archiving and recovery.
Questions to ask vendors
- What is your default retention for our data, messages, recordings and logs, and can we change it per data type?
- Can we apply legal holds, and do holds override user and admin deletion?
- How long after contract termination do you keep our data, and how do we export it first?
- How do you dispose of our data, including copies in your backups, and can you confirm deletion?
- Do you support retention labels or policies that match our schedule?
- Where is retained data stored, and does that affect our privacy obligations?
How it differs from backup retention
Backup retention is how long a backup system keeps recovery copies, such as daily, weekly and monthly restore points, so you can recover from failure, deletion or ransomware; immutable backup protects those copies from change. A data retention policy decides how long business records must or may exist at all. The two need to be coordinated: backups kept far longer than the retention schedule can undermine deletion commitments, and relying on backups as the records archive can make it hard to find, hold or produce specific records. Many organizations use an archive or the platform’s own retention features for records, and backups for recovery.
