FREE TEMPLATE
Data Retention and Disposal Policy
Data you no longer hold cannot be stolen, demanded in litigation, or reported in a breach. How long to keep things, and how to actually destroy them.
[COMPANY NAME]
Effective date: [DATE] · Owner: [NAME, TITLE] · Review: annually, or after any material change
Purpose
Data you no longer hold cannot be stolen, cannot be demanded in litigation, and does not have to be reported when there is a breach.
Most small businesses keep everything forever, because storage is cheap and deciding is work. This policy defines how long [COMPANY NAME] keeps things, and how they are destroyed when that time is up.
Scope
Applies to all company and customer records in any form — email, files, database records, accounting systems, backups, paper, and anything on a departing employee’s device.
Retention is a decision, not a default
How long a record is kept is set by law, contract, or a business reason — in that order. “We might need it” is not a business reason. Neither is “nobody told us to delete it.”
| Record type | Keep for | Why — law, contract or business | Where it lives |
|---|---|---|---|
| Financial and tax records | |||
| Payroll and employment records | |||
| Customer contracts | |||
| Customer personal data | |||
| Quotes and proposals not won | |||
| System and security logs | |||
| CCTV / access records | |||
| Job applications not hired | |||
| Backups |
Retention periods vary by state and by industry, and several of these are set by law. Have counsel or your accountant confirm the rows before you adopt this.
Legal hold overrides everything
If litigation, an investigation or a regulatory request is anticipated or under way, routine deletion of anything that might be relevant stops immediately and stays stopped until [NAME, TITLE] lifts the hold in writing.
Deleting on schedule during a hold is worse than never having had a schedule. Make sure whoever runs deletion knows who can impose one.
Deleting in cloud services is usually not deleting
Microsoft 365, Google Workspace and most SaaS platforms keep deleted items in recoverable form for a period you may not have set, and your own backups keep them longer.
When a record reaches the end of its retention, [POLICY OWNER] confirms it is gone from the live system, the recoverable or deleted-items area, and from backups once the backup retention window has passed — or documents deliberately that backup expiry is the disposal mechanism, which is acceptable if the window is known and short enough.
Disposal methods
| Media | Method |
|---|---|
| Files in a live system | Delete, then empty the recoverable area |
| Whole drives — encrypted | Cryptographic erase, key destroyed |
| Whole drives — not encrypted | Secure wipe to a recognized standard, or physical destruction |
| Failed drives | Physical destruction — a drive that will not wipe still holds data |
| Phones and tablets | Full factory reset with the account removed first |
| Paper | Cross-cut shred |
| Anything leaving on a leased or sold device | Wiped before it leaves the building, with a certificate |
A drive that will not power on is not a drive that has been erased. Destroy it or pay someone to, and keep the certificate.
Records of disposal
[POLICY OWNER] records what was destroyed, when, by what method, and by whom. For third-party destruction, the certificate is kept for [NUMBER] years.
This record is what you produce when someone asks whether the data still exists. Without it the honest answer is “probably not”, which is not an answer.
Departing staff
When someone leaves, their mailbox and files are retained for [NUMBER] months under the Access Control Policy, then disposed of under this one. Personal devices holding company data are handled under the Remote Work and BYOD Policy.
The common failure is a mailbox nobody ever closes, quietly retaining everything that person ever received, years after they left.
Minimize what you collect
The cheapest retention decision is not collecting it. Before adding a field to a form or a column to a spreadsheet, [POLICY OWNER] asks what it is for and how long it will then have to be protected.
Collecting a date of birth or a full card number “in case” converts a harmless record into a reportable one.
Responsibilities
[POLICY OWNER] maintains the schedule, runs disposal, keeps the records.
Business owner approves retention periods and imposes legal holds.
Everyone keeps company records in company systems, so they fall under this schedule rather than sitting in a personal drive nobody can find.
Review
Reviewed at least annually by [POLICY OWNER], and whenever a new system, regulation or contractual obligation changes what must be kept.
Template provided free by Cybertitans LLC, Woodbury, Minnesota. It is a starting point, not legal advice, and it has not been reviewed against your contracts, your industry’s regulations or your retention obligations. Have counsel review it before you adopt it. Downloading or using this template does not create a client relationship with Cybertitans, and Cybertitans makes no representation that adopting it satisfies any insurer, regulator, auditor or customer requirement.
EDITABLE VERSION
Want the Word version you can edit?
The policy above is free to read, copy and adapt — that is the point of publishing it. The Word file is the same text with every fill-in field marked and every table ready to complete, in our formatting. Tell us where to send it.
Free. About 20 seconds.
Where should we send it?
THE REST OF THE SET
Nine more, and someone to run them.
This is one of ten free templates written for businesses with no IT department. The others are on the resource library, and the editable Word versions are a name and an email away.
A policy nobody operates is a document. If you would rather someone owned this — and the offboarding, the backups and the MFA behind it — that is what TiTAN is.
