Data Retention and Disposal Policy Template

FREE TEMPLATE

Data Retention and Disposal Policy

Data you no longer hold cannot be stolen, demanded in litigation, or reported in a breach. How long to keep things, and how to actually destroy them.

[COMPANY NAME]

Effective date: [DATE] · Owner: [NAME, TITLE] · Review: annually, or after any material change

Purpose

Data you no longer hold cannot be stolen, cannot be demanded in litigation, and does not have to be reported when there is a breach.

Most small businesses keep everything forever, because storage is cheap and deciding is work. This policy defines how long [COMPANY NAME] keeps things, and how they are destroyed when that time is up.

Scope

Applies to all company and customer records in any form — email, files, database records, accounting systems, backups, paper, and anything on a departing employee’s device.

Retention is a decision, not a default

How long a record is kept is set by law, contract, or a business reason — in that order. “We might need it” is not a business reason. Neither is “nobody told us to delete it.”

Record typeKeep forWhy — law, contract or businessWhere it lives
Financial and tax records
Payroll and employment records
Customer contracts
Customer personal data
Email
Quotes and proposals not won
System and security logs
CCTV / access records
Job applications not hired
Backups

Retention periods vary by state and by industry, and several of these are set by law. Have counsel or your accountant confirm the rows before you adopt this.

Legal hold overrides everything

If litigation, an investigation or a regulatory request is anticipated or under way, routine deletion of anything that might be relevant stops immediately and stays stopped until [NAME, TITLE] lifts the hold in writing.

Deleting on schedule during a hold is worse than never having had a schedule. Make sure whoever runs deletion knows who can impose one.

Deleting in cloud services is usually not deleting

Microsoft 365, Google Workspace and most SaaS platforms keep deleted items in recoverable form for a period you may not have set, and your own backups keep them longer.

When a record reaches the end of its retention, [POLICY OWNER] confirms it is gone from the live system, the recoverable or deleted-items area, and from backups once the backup retention window has passed — or documents deliberately that backup expiry is the disposal mechanism, which is acceptable if the window is known and short enough.

Disposal methods

MediaMethod
Files in a live systemDelete, then empty the recoverable area
Whole drives — encryptedCryptographic erase, key destroyed
Whole drives — not encryptedSecure wipe to a recognized standard, or physical destruction
Failed drivesPhysical destruction — a drive that will not wipe still holds data
Phones and tabletsFull factory reset with the account removed first
PaperCross-cut shred
Anything leaving on a leased or sold deviceWiped before it leaves the building, with a certificate

A drive that will not power on is not a drive that has been erased. Destroy it or pay someone to, and keep the certificate.

Records of disposal

[POLICY OWNER] records what was destroyed, when, by what method, and by whom. For third-party destruction, the certificate is kept for [NUMBER] years.

This record is what you produce when someone asks whether the data still exists. Without it the honest answer is “probably not”, which is not an answer.

Departing staff

When someone leaves, their mailbox and files are retained for [NUMBER] months under the Access Control Policy, then disposed of under this one. Personal devices holding company data are handled under the Remote Work and BYOD Policy.

The common failure is a mailbox nobody ever closes, quietly retaining everything that person ever received, years after they left.

Minimize what you collect

The cheapest retention decision is not collecting it. Before adding a field to a form or a column to a spreadsheet, [POLICY OWNER] asks what it is for and how long it will then have to be protected.

Collecting a date of birth or a full card number “in case” converts a harmless record into a reportable one.

Responsibilities

[POLICY OWNER] maintains the schedule, runs disposal, keeps the records.

Business owner approves retention periods and imposes legal holds.

Everyone keeps company records in company systems, so they fall under this schedule rather than sitting in a personal drive nobody can find.

Review

Reviewed at least annually by [POLICY OWNER], and whenever a new system, regulation or contractual obligation changes what must be kept.

Template provided free by Cybertitans LLC, Woodbury, Minnesota. It is a starting point, not legal advice, and it has not been reviewed against your contracts, your industry’s regulations or your retention obligations. Have counsel review it before you adopt it. Downloading or using this template does not create a client relationship with Cybertitans, and Cybertitans makes no representation that adopting it satisfies any insurer, regulator, auditor or customer requirement.

EDITABLE VERSION

Want the Word version you can edit?

The policy above is free to read, copy and adapt — that is the point of publishing it. The Word file is the same text with every fill-in field marked and every table ready to complete, in our formatting. Tell us where to send it.

Free. About 20 seconds.

THE REST OF THE SET

Nine more, and someone to run them.

This is one of ten free templates written for businesses with no IT department. The others are on the resource library, and the editable Word versions are a name and an email away.

A policy nobody operates is a document. If you would rather someone owned this — and the offboarding, the backups and the MFA behind it — that is what TiTAN is.

Book 20 Minutes