A data retention policy sets how long your organization keeps each category of records, where those records live, and when they get destroyed. A defensible one has to do two things at once: meet the federal and industry minimums that require you to hold certain records, and honor the privacy rules that cap how long you can hold personal data at all. Get either side wrong and the consequences are real: destroy too early and you face regulatory penalties or courtroom sanctions; keep too long and you inflate breach exposure, discovery costs, and storage bills.
The Two Pressures Your Policy Has to Balance
Most retention thinking starts and stops with minimums. That is half the picture. Federal statutes tell you the shortest period you can hold tax filings, payroll records, audit workpapers, and industry-specific documents. Privacy regulations tell you the longest period you can hold personal data once its original purpose is spent. A policy that only tracks the floors will keep you legal with the IRS and out of trouble under FLSA, and simultaneously expose you under GDPR, state privacy laws, and the FTC Safeguards Rule. Build the schedule so each category of data has both a floor and, where personal data is involved, a ceiling.
Federal Minimum Retention Periods
Tax Records
The IRS general statute of limitations for assessments is three years from the filing date.1Office of the Law Revision Counsel. 26 USC 6501 – Limitations on Assessment and Collection The IRS recommends holding records for at least that long when nothing unusual applies.2Internal Revenue Service. How Long Should I Keep Records
Longer windows kick in under specific circumstances. If you underreport gross income by more than 25 percent, the assessment window stretches to six years. Claims for losses from worthless securities or bad debt deductions call for seven years of records.2Internal Revenue Service. How Long Should I Keep Records There is no statute of limitations at all if the return was fraudulent or never filed.1Office of the Law Revision Counsel. 26 USC 6501 – Limitations on Assessment and Collection Most businesses default to six or seven years for routine tax files to cover the extended windows. Property records supporting basis calculations should be kept for as long as you own the asset and for at least three years after you dispose of it.
Employment and Payroll Records
Under the Fair Labor Standards Act, payroll records must be preserved for at least three years from the last date of entry. The same three-year floor applies to collective bargaining agreements, employment contracts, and related certificates.3eCFR. 29 CFR 516.5 – Records to Be Preserved 3 Years
Sarbanes-Oxley Audit Workpapers
Accountants who audit publicly traded companies must keep all audit and review workpapers for at least five years after the fiscal period ends under 18 U.S.C. § 1520; violations carry fines and up to 10 years in prison.4Office of the Law Revision Counsel. 18 USC 1520 – Destruction of Corporate Audit Records Separately, 18 U.S.C. § 1519 makes it a federal crime, punishable by up to 20 years, to knowingly destroy or falsify any record to obstruct a federal investigation or bankruptcy proceeding.5Office of the Law Revision Counsel. 18 USC 1519 – Destruction, Alteration, or Falsification of Records That second provision does not set a retention period, but it sets the stakes for how disposal is handled once trouble is on the horizon.
Employee Benefit Plans
ERISA requires plan sponsors to keep records supporting required filings for at least six years after the filing date. Employers must also keep records sufficient to determine benefits due to each employee; the penalty for failing to do so is $10 per affected employee.6Office of the Law Revision Counsel. 29 USC 1027 – Retention of Records
HIPAA Compliance Documentation
HIPAA does not set a retention period for patient medical records; those come from state law. What HIPAA does require is that covered entities and business associates retain their own compliance documentation, including written policies, procedure manuals, and records of required actions and assessments, for six years from creation or from the date the document was last in effect, whichever is later.7eCFR. 45 CFR 164.316 – Policies and Procedures and Documentation Requirements Organizations focused on protecting patient data sometimes miss that the six-year floor also applies to their internal policy paperwork.
Broker-Dealers
SEC Rule 17a-4 tiers records by type. Account records, trade blotters, and general ledgers must be kept for at least six years. Correspondence, bank statements, and trial balances require three years. Partnership articles, corporate charters, and registration documents must be kept for the life of the enterprise. Electronic copies must sit in a write-once, read-many format that prevents overwriting or erasure, or the firm must keep a complete time-stamped audit trail of every modification.8eCFR. 17 CFR 240.17a-4 – Records to Be Preserved by Certain Exchange Members, Brokers and Dealers
Hazardous Waste Manifests
Generators, transporters, and receivers of hazardous waste must keep copies of manifests for three years under EPA rules; users of the EPA’s electronic manifest system can satisfy the requirement through their online accounts.9US EPA. Frequent Questions About e-Manifest
Ceilings on Personal Data
Privacy laws work the opposite direction. Article 5 of the EU General Data Protection Regulation sets a storage limitation principle: personal data may only be kept in identifiable form for as long as necessary to fulfill its original purpose.10GDPR-Info.eu. General Data Protection Regulation – Art 5 GDPR Principles Relating to Processing of Personal Data The European Commission has stated that organizations should store data for the shortest time possible, factoring in the processing purpose and any legal obligation that sets a fixed period.11European Commission. How Long Can Data Be Kept and Is It Necessary to Update It Any U.S. business that collects data from EU residents is bound by these limits regardless of where it is headquartered.
Domestically, the FTC Safeguards Rule requires non-banking financial institutions to securely destroy customer information no later than two years after the data was last used to provide a product or service, unless the information is still needed for legitimate business operations or is required by another law. The rule also requires periodic reviews of retention practices to keep consumer data from accumulating unnecessarily.12eCFR. 16 CFR Part 314 – Standards for Safeguarding Customer Information More than 45 states and territories have enacted comprehensive consumer privacy laws as of early 2026, many including data minimization requirements. Indefinite retention of personal data is increasingly a compliance risk rather than a business asset.
Why Keeping Data Too Long Is Its Own Risk
Three concrete exposures follow from over-retention. Regulators are one. The FTC has pursued enforcement under its unfair-and-deceptive-practices authority, arguing that holding personal information far longer than necessary unreasonably increases the risk of disclosure and misuse; recent consent orders have required companies to delete data no longer needed and adopt retention schedules with defined maximums.
Breach exposure is another. Every gigabyte kept is a gigabyte that can be stolen. Reducing stored volume directly reduces the blast radius of an incident.
E-discovery is the third. When litigation hits, you have to search and produce all relevant electronically stored information. Organizations that destroy records on schedule end up with leaner data sets when a discovery request arrives. Those that keep everything pay attorneys and vendors to sift through years of files that should have been deleted.
Litigation Holds Override the Schedule
Routine retention stops the moment litigation is reasonably anticipated. A litigation hold is a formal directive suspending the destruction of any records that could be relevant to a pending or expected lawsuit, and it stays in effect until the matter resolves through judgment, settlement, or dismissal.13National Institutes of Health. NIH Policy Manual 1743-2 – NIH Litigation Hold Policy
Federal Rule of Civil Procedure 37(e) governs what happens if electronically stored information that should have been preserved is lost because a party failed to take reasonable steps. If the loss prejudices the opposing party, the court can order remedial measures. If the court finds the destruction was intentional, it can instruct the jury to presume the missing data was unfavorable, or dismiss the case, or enter default judgment.14Legal Information Institute. Federal Rules of Civil Procedure Rule 37 – Failure to Make Disclosures or to Cooperate in Discovery The gap between negligent loss and intentional destruction is enormous. Effective implementation means identifying every custodian who might have relevant data, notifying them in writing, suspending automated deletion, and periodically reminding them the hold is still active.
Building the Retention Schedule
Audit What You Have
Map every place your organization stores data: on-premises servers, cloud platforms, SaaS applications, email archives, employee laptops, physical filing cabinets. Audits routinely surface duplicate copies scattered across systems, forgotten archives from past projects, and stores no one actively manages. Finding these first stops them from becoming blind spots.
Sort Records into Categories
Group data so a single rule can cover a coherent class of records. Useful categories include:
- Personal identifiers such as Social Security numbers, dates of birth, and home addresses, which carry the strictest privacy scrutiny and need defined destruction dates.
- Financial records including tax filings, invoices, bank statements, and ledger entries, driven by IRS assessment windows and, in regulated industries, agency rules.
- Human resources files including employment contracts, performance reviews, benefit enrollment forms, and payroll, governed by FLSA, ERISA, and anti-discrimination statutes.
- Operational data such as system logs, internal emails, and project files, where relevance drops off quickly but litigation-hold triggers still apply.
- Legal documents including property deeds, long-term contracts, and corporate governance records, often kept for the life of the entity.
Within each category, separate active records used daily from inactive records held for compliance or history. Active records need accessible storage; inactive records can move to cheaper archival tiers.
Pull in the Right Stakeholders
A policy written by IT or legal alone will have gaps. Department heads know which records their teams use and for how long. Legal counsel knows the statutory floors and can flag categories where litigation risk justifies holding longer. IT knows the storage constraints. Finance knows what auditors ask for. Combining these views before drafting keeps the policy from being technically sound but operationally unworkable.
Set Floor, Ceiling, and Ownership for Each Category
For every category, identify the longest applicable legal requirement, add a reasonable buffer if business needs justify it, and set that as the floor. For personal data covered by privacy rules, also set a ceiling after which the data must be destroyed. Assign each category to a specific owner responsible for oversight, and define the transition points that move records from active storage to archive and from archive to disposal.
Destroying Records Defensibly
Digital Sanitization
NIST Special Publication 800-88 organizes media sanitization into three levels of increasing thoroughness:15NIST. NIST SP 800-88 Rev 1 – Guidelines for Media Sanitization
- Clear overwrites data using standard read-and-write commands or a factory reset. It protects against casual recovery but not laboratory-grade forensics.
- Purge uses physical or logical methods that make recovery infeasible even with advanced laboratory equipment. Cryptographic erasure, destroying the encryption key that protects the data, falls in this category for self-encrypting drives.
- Destroy physically renders the media unusable through shredding, disintegrating, or incinerating.
Match the level to sensitivity and to whether the media will be reused. Moderate-sensitivity data on a drive redeployed internally can be cleared. High-sensitivity data leaving your control should be purged or destroyed. When Clear or Purge fails verification, Destroy is the fallback.
Paper Records
Paper containing sensitive information should be cross-cut shredded or incinerated by a professional vendor. Whatever method you use, require a certificate of destruction documenting what was destroyed, when, and how.
Disposal Logs
Keep a permanent log of every disposal event, digital or physical. Each entry should record the data category, the volume or description of records destroyed, the destruction date, the method used, and the person or vendor who carried it out. Those logs are your proof of compliance if a regulator ever asks whether you followed your own policy. Review them on a set cycle to confirm disposals are happening on schedule.
Immutable Storage Where Authenticity Matters
Some records must be stored so they cannot be altered after the fact. SEC Rule 17a-4 requires broker-dealers to keep electronic records in non-rewritable, non-erasable form, commonly called WORM storage; the alternative is a system with a complete time-stamped audit trail of every modification, backup redundancy, and the ability to produce records for regulators on demand.8eCFR. 17 CFR 240.17a-4 – Records to Be Preserved by Certain Exchange Members, Brokers and Dealers Outside the securities industry, WORM storage is worth considering for any category where tamper-proofing matters, including contracts, compliance documentation, and audit workpapers held under the Sarbanes-Oxley five-year rule.4Office of the Law Revision Counsel. 18 USC 1520 – Destruction of Corporate Audit Records
Making the Policy Stick
A policy that lives in a shared drive and never reaches employees gives the illusion of compliance without the substance. Distribute it with signed acknowledgments confirming each employee understands their responsibilities for the records they handle. Those acknowledgments become your evidence of good faith if the policy is tested by an auditor or in litigation.
Training should go beyond handing people a document. Walk staff through identifying which records fall into which category, how to initiate a transfer to archive storage, and how to recognize when a litigation hold overrides normal disposal. Refresh the training at least annually. Management should audit disposal logs on a regular cycle to confirm the process is running as designed, not just documented.