Labeled archive boxes and binders on office shelving

ComplianceCybersecurityLifecycle Management

Data retention policy: What your small business should keep and delete

A former client’s file from 2014 sits in a shared folder nobody has opened in years. It holds a Social Security number, a bank statement and a signed engagement letter. Nobody needs it, and if that folder is ever exposed in a breach, it counts as much as the files you use every day. A data retention policy decides, in writing, what to keep, for how long, and how to get rid of it safely.

Keeping everything feels safe, and it creates its own risk. Some rules now require you to dispose of data on time. We write retention policies for our clients.

Key takeaways

  • How long to keep a record depends on the rule behind it, such as IRS guidance for tax records or state law for medical records. No single number fits everything.
  • Old data you no longer need gives a breach more to expose. The FTC Safeguards Rule also requires you to dispose of it on time.
  • Plan how to pause deletion (a legal hold) when you expect a lawsuit or an investigation.
  • Use Microsoft 365 and backup settings to follow the schedule automatically. Old devices count too when it’s time to dispose of data.

What a data retention policy must cover

  • Every type of record you hold and who owns it.
  • How long each type is kept, and the rule or reason behind that period.
  • Where each type lives: email, file shares, line-of-business apps, paper, backups.
  • What happens at the end of the period: archive, review or delete.
  • A legal hold process that pauses deletion.
  • How files, devices and paper are destroyed, and how you prove it.
  • A regular cleanup of old files, inactive accounts and unused apps.
  • A yearly review date.

Why keeping everything is a risk

Old data is a liability you pay to store. It costs money in cloud storage and backups, slows down searches and makes audits harder. Worse, every old spreadsheet with client details is one more thing an attacker can steal and one more record you may have to report after a breach.

Pile of shredded paper strips
  • The FTC Safeguards Rule requires covered financial businesses, including many accounting and tax firms, to have procedures to securely dispose of customer information no later than two years after it was last used to serve that customer, unless it is still needed for a legitimate business purpose or required by law.
  • Louisiana law requires businesses that own or license computerized personal information about Louisiana residents to take reasonable steps to destroy records containing personal information that are no longer to be retained, and to keep reasonable security procedures while they hold it.
  • HIPAA requires covered entities to keep appropriate safeguards in place for patient information for as long as they hold it, including when they dispose of it.

Deleting on schedule, done properly and documented, is part of protecting client data.

How long to keep common records

These are common reference points. Confirm them with your accountant or attorney before you lock them into policy, since your industry, state and contracts can change the answer.

Record typeReference point
Records supporting a tax return3 years in most cases, per the IRS
Tax records involving a loss from worthless securities or a bad debt deduction7 years
Tax records where income was underreported by more than 25%6 years
Employment tax recordsAt least 4 years after the tax is due or paid, whichever is later
Medical recordsSet by state law. HHS says HIPAA itself sets no retention period for the patient chart.
HIPAA security and privacy policies and documentation6 years from creation or the date last in effect, whichever is later
Customer information under the FTC Safeguards RuleSecurely disposed of no later than two years after last use, with the exceptions above
Engagement letters, contracts, personnel files and client work papersSet by professional rules, contracts, insurance carriers or employment law

A template outline you can adapt

  1. Purpose and scope: the systems, locations and record types the policy covers, including email, file shares, line-of-business apps, paper and backups.
  2. Roles: who owns each record type, who approves deletion, and who can issue a legal hold.
  3. Retention schedule: a table listing each record type, how long it stays active, when it moves to an archive, when it is deleted, and why.
  4. Legal hold: who can pause deletion when a lawsuit, audit or investigation is reasonably expected, and how the hold is applied in your systems.
  5. Disposal: approved methods for files, devices and paper, and the records that prove it was done.
  6. Cleanup: how often old files, inactive accounts and unused apps are reviewed and removed.
  7. Exceptions and review: how to request an exception, and the date of the next yearly review.

Give employees a one-page, plain-English version: what to save, where to save it, and what never belongs on desktops or personal drives.

Clean out old files, inactive accounts and unused apps

Clutter builds up between policy reviews. A digital cleanup once or twice a year shrinks what a breach can expose and what you pay to store.

  • Search shared drives, OneDrive and desktops for folders nobody has opened in years, then archive or delete them according to your schedule. Duplicate copies of the same client file count too.
  • Disable accounts that belong to former employees, old vendor logins and shared mailboxes nobody reads. Our offboarding checklist keeps new ones from piling up.
  • Cancel apps and subscriptions nobody uses, and remove their connection to your data in Microsoft 365. Unused licenses and duplicate SaaS tools are two kinds of waste we find at clients, and our post on forgotten cloud resources covers the rest.
  • Ask staff to clear work files out of downloads folders, personal drives and USB sticks and save them to approved locations.

Rollout tips

Let your systems enforce the schedule

A policy that depends on people remembering to delete files won’t be followed. In Microsoft 365, Microsoft Purview retention policies can apply keep and delete rules to Exchange mailboxes, SharePoint sites, OneDrive accounts and Teams chats. Retention labels can set different periods for specific documents, start the clock at an event such as a contract ending, and require a review before deletion. In Microsoft 365, retention wins over deletion: content under a retention setting or hold is preserved even when a user deletes it. Which features you get depends on your licensing.

Match your backups to the policy

If your backups keep data for ten years while your policy says three, your real retention period is ten years. Our clients’ server backups run hourly with a daily off-site copy, their Microsoft 365 and Google Workspace backups run three times a day, and both are immutable, so the retention period on those copies has to be set deliberately to match the policy. Our guide to secure data backup covers the rest.

Dispose of devices and paper properly

Deleting a file or emptying a recycle bin doesn’t always remove the data from the drive. Follow NIST Special Publication 800-88 Revision 2, published in September 2025, for wiping or destroying storage media. Include laptops, desktops, servers, phones, external drives and multifunction copiers, which often store scanned documents on internal drives. Get a certificate of sanitization or destruction tied to serial numbers, and use locked shred bins for paper. Retiring a device should trigger a wipe, an asset record update and a certificate every time, which is part of technology lifecycle management.

Check the policy at least once a year and after any major system change, and fold it into your broader compliance program.

Start with the oldest folder on your file share and ask who owns it. When you’re ready to turn the answer into a written schedule your systems actually enforce, book an intro call.

FAQ

Frequently asked questions

What is the purpose of a data retention policy?

It keeps the records you’re required to hold and gets rid of the ones you aren’t, on schedule. Old data costs money to store and is one more thing an attacker can steal or you may have to report after a breach. Some rules require timely disposal: the FTC Safeguards Rule requires covered financial firms to dispose of customer information no later than two years after last use, with exceptions.

How do you create a data retention policy?

List every type of record you hold, where it lives and who owns it. Set a retention period for each based on the rule behind it, such as IRS guidance for tax records or state law for medical records, and confirm those periods with your accountant or attorney. Add a legal hold process and approved disposal methods, then set Microsoft 365 retention policies and your backups to enforce the schedule.

What is a data retention policy?

A data retention policy is a written decision about what records you keep, for how long, and how you dispose of them safely when the time is up. It lists each type of record and its owner, the rule behind each retention period, a legal hold process that pauses deletion, and how files, devices and paper are destroyed.

Sources: IRS, How long should I keep records?; FTC Safeguards Rule, 16 CFR 314.4; HIPAA Security Rule documentation, 45 CFR 164.316; HHS, FAQ 580: HIPAA and medical record retention; Louisiana R.S. 51:3074; Microsoft Learn, Learn about retention policies and retention labels; Microsoft Learn, Learn about data lifecycle management; NIST SP 800-88 Rev. 2, Guidelines for Media Sanitization, 2025.

Talk to an advisor

Questions about your own environment?

Our team can walk through how this applies to your organization, with honest recommendations and no pressure.