What is data retention?
Data retention is the set of rules and controls that determines how long information is kept and what happens when that period ends. A retention programme connects business need, legal obligations, contractual commitments, limitation periods and risk. It should define whether data is deleted, anonymised, archived or placed under a justified legal hold.
Retention should be linked to a specific purpose or event rather than an arbitrary period applied to every record. For example, the period may begin when a contract ends, an employee leaves, an account closes or a legal obligation expires. The same system may contain records with different retention requirements.
Why is retention important?
Keeping data longer than necessary increases the impact of breaches, expands the scope of rights requests and investigations, and creates storage and governance costs. Old information may also be inaccurate or used out of context. At the same time, deleting records too early can prevent an organisation from meeting statutory duties, resolving disputes or proving a transaction.
A defensible programme balances these considerations and records the reasoning behind the selected periods. It should not use vague statements such as “kept as long as necessary” without operational rules.
How is a retention schedule created?
Organisations identify record categories, owners, purposes, legal requirements and triggering events. Privacy, legal, records-management, security and business teams should agree the period and disposal method. The schedule should cover structured systems, documents, email, collaboration tools, logs, backups and vendors where relevant.
Exceptions such as litigation holds should be defined and controlled. A hold should preserve only the necessary information and should be released when the reason ends.
How are retention rules enforced?
Technical deletion, archive or anonymisation should be automated where possible. System owners should test that rules work and that copies in integrated platforms are addressed. Vendor contracts should require equivalent deletion or return and provide evidence when the service ends.
Metrics can track overdue deletion, systems without rules, exceptions and failed jobs. Retention schedules should be reviewed when laws, systems or purposes change.
Frequently asked questions
Is there one legal retention period for personal data?
No. Periods depend on the record, purpose, jurisdiction, sector and legal obligations. Each category requires a justified rule.
Do backups need to follow retention rules?
Yes, although immediate selective deletion may be technically difficult. Backups should have controlled cycles, restricted use and restoration procedures that reapply deletions.
Can data be kept indefinitely for analytics?
Not by default. The organisation should assess necessity and consider aggregation or anonymisation when individual-level data is no longer needed.
What is a legal hold?
It is a temporary suspension of normal deletion for records relevant to litigation, investigation or another defined legal need.
Who owns retention?
Business owners are responsible for their records, supported by legal, privacy, records, security and technology teams that define and enforce standards.



