Sign In Try Free
Workflow-specific products Content, decks, briefs, proposals, legal, and sales each have a clearer buying path.
Review before delivery Draft, edit, collaborate, approve, and export in the same workspace.
Security + procurement path Security policy, support, and Azure Marketplace buying are public.

What is a data retention policy?

The written rule that decides how long your organisation keeps each kind of record, who owns that decision, and what happens when the period ends.

Start 14-day Lex trial View Lex pricing

Data retention policy meaning: a data retention policy is an internal document stating how long an organisation keeps each category of record, on what legal or business basis, where it is stored, who is accountable, and how it is disposed of at the end of that period. It is paired with a retention schedule — the table that lists each record category against its period and basis. The policy sets the rules; the schedule applies them.

WhatRecord categories in scope
How longPeriod and its basis
WhoNamed accountability
Then whatDisposal and legal hold

What a data retention policy must contain

A policy that an auditor accepts covers seven things: the scope and record categories, a retention period for each with the legal or business basis behind it, storage location and format, the disposal method, named ownership, how a legal hold overrides the schedule, and a review date. The weakest policies state periods without stating why — a number with no source is the first thing a reviewer challenges.

Retention policy or retention schedule?

They are different documents and both are needed. The data retention policy carries the principles, the authority and the accountability. The retention schedule is the operational table: each record category, its period, and the basis for that period. A policy without a schedule cannot be followed; a schedule without a policy has nothing standing behind it when someone asks why a record was destroyed.

How it differs from a privacy policy

A privacy policy faces outward: it tells data subjects what you collect, why, and — as a required section — how long you keep it. A data retention policy faces inward: it tells your own people when to delete. The two have to agree, and drift between them is common, because the privacy notice gets updated for a regulator while the internal schedule quietly does not. GDPR document drafting · compliance documentation

Where GDPR fits

Storage limitation is a GDPR principle in its own right: personal data may be kept only as long as the stated purpose requires. That makes retention a compliance obligation rather than a housekeeping preference, and it is why Article 30 records of processing carry retention and erasure time limits as an explicit field. If your Article 30 record says one period and your schedule says another, the inconsistency is the finding. What compliance management involves

Drafting one you can defend

Gixo Lex drafts a data retention policy as a reviewable first draft — retention is a required section of the privacy policy structure, retention and erasure limits are modelled in the Article 30 record, and a standalone policy can be drafted through the custom document path from the requirements you supply. The retention periods themselves must come from you or your counsel: Gixo does not determine statutory minimums, and the output goes to a qualified reviewer before adoption. Legal documents for startups

Frequently Asked Questions

What is a data retention policy?
A data retention policy is the written rule that states how long an organisation keeps each category of record, where it keeps it, who is responsible, and what happens at the end of that period. It exists so that retention is a decision made once and applied consistently, rather than a judgement made ad hoc by whoever happens to be holding the file.
Why does an organisation need one?
Three reasons, usually in this order: regulators and auditors ask for it, litigation makes undocumented deletion look like spoliation, and storage of data you no longer need is pure risk. Under GDPR, storage limitation is a principle in its own right — keeping personal data longer than necessary is itself a breach, not merely untidy.
What should a data retention policy include?
Scope and the record categories it covers, a retention period for each with the legal or business basis behind it, storage location and format, the disposal method, who owns each decision, how legal holds override the schedule, and a review date. The retention schedule — the table of category, period and basis — is the part auditors actually read.
How long should data be retained?
It depends on the record and the jurisdiction, and the honest answer is that the period should come from a stated source rather than a habit. Tax and accounting records commonly carry multi-year statutory minimums; employment records often run for the duration of employment plus a period after; personal data under GDPR should be kept only as long as the stated purpose requires. Take the actual periods from counsel or the applicable regulation, not from a template.
What is the difference between a data retention policy and a retention schedule?
The policy sets the rules, the principles and the accountability. The schedule is the table that applies them: each record category with its retention period and the basis for it. A policy without a schedule is a statement of intent; a schedule without a policy has no authority behind it.
Is a data retention policy the same as a privacy policy?
No. A privacy policy tells data subjects what you collect and why, and includes a retention section as one of its required parts. A data retention policy is internal — it tells your own people how long to keep things and when to destroy them. The two must agree, which is a common place for them to drift apart.
Can Gixo Lex draft a data retention policy?
Yes, as a reviewable first draft. Retention is a required section of the privacy policy type, retention and erasure time limits are modelled in the GDPR Article 30 records-of-processing structure, and a standalone retention policy can be drafted through the custom document path from the requirements and sources you supply. The periods must come from you or your counsel — Gixo does not determine statutory retention periods, and the draft goes to a qualified reviewer before it is adopted.