Data retention defines how long data is kept before deletion. The rules come from many sources. Regulations require financial records to be kept for seven years. Healthcare data has its own timelines. GDPR says personal data should be kept no longer than necessary. Legal holds require data to be preserved during litigation. Contracts with vendors specify retention periods. The organization must reconcile all of these into a coherent policy.
Retention is not just about compliance. It is about risk and cost. Every byte of stored data is a potential liability. A breach exposes everything you keep. A lawsuit can subpoena everything you keep. Storage costs money. Processing costs money. Old data slows down queries and complicates migrations. The instinct to keep everything forever is understandable and wrong. Retention policies should be specific. Not all data is the same. Transaction records, customer emails, server logs, and marketing analytics each have different requirements and different risk profiles. The policy should define retention periods for each category, specify how deletion happens, and verify that it actually occurs. Automated deletion is essential. Manual deletion does not happen. Data that should have been deleted years ago is still there, waiting to cause problems. Retention is about letting go. The data served its purpose. Keeping it longer serves nobody but the attacker.
Retention considerations
- Regulatory requirements — industry and jurisdiction specific
- Legal holds — preserve data when litigation is likely
- Business needs — how long the data is actually useful
- Risk — breach and discovery exposure
- Cost — storage and processing expenses
Retention is a balance. Keep too little and you lose history. Keep too much and you carry risk. The right answer changes by data type.
Comments
No comments yet. Be the first to share a thought.
Leave a comment