Businesses collect an unbelievable amount of data during their operations, but rarely stop to review and even delete data.
A data retention policy defines how long your business keeps different types of information, why it keeps them, who can access them, and how they should be deleted when they are no longer needed. For small and midsize businesses, it’s one of the most practical ways to reduce compliance risk without overcomplicating day-to-day operations.
Many companies keep data for longer than necessary because deletion feels risky. Old customer records stay in a CRM. Former employee files remain in shared drives. Contracts sit in inboxes for years. Exported spreadsheets are saved “just in case.” Over time, the business ends up storing more personally identifiable information (PII), financial records, and internal information than it can properly govern.
That creates a problem under GDPR. The storage limitation principle means personal data should not be kept for longer than necessary for the purpose it was collected. A retention policy helps turn that principle into a working system: what you keep, for how long, where it lives, who owns it, how it is removed, and how access to retained data is protected.
That matters because weak passwords remain one of the most common vulnerabilities for businesses of all sizes, and retained data is still exposed if access controls are weak.
What is a data retention policy?
Why is a data retention policy important?
What kind of data needs a retention schedule?
UK data retention requirements: what SMBs should know
Data retention policy template for SMBs
Access control and retained data
Common data retention policy mistakes
Turn retention rules into everyday practice
What is a data retention policy?
A data retention policy is a set of rules that defines how long different categories of data should be kept within a business, and what happens when the retention period ends. It usually covers personal data, customer records, employee files, financial documents, contracts, communications, operational records, and business-critical documents.
A useful policy should answer these four questions:
- What type of data do we hold?
- Why do we need to keep it?
- How long should we keep it?
- How will we delete, anonymize, or archive it securely?
The GDPR does not set specific time limits for every type of data, so organizations need to decide what is necessary for their own purposes, document that reasoning, and be prepared to justify it.
A data retention policy is more than a list of dates. It’s a record of the decisions behind those dates. If someone asks why customer data was kept for three years or applicant records were deleted after six months, a business must be able to point to a clear reason.
Why is a data retention policy important?
A retention policy helps with compliance, security, and operational clarity. It protects a business in three ways:
- It reduces the amount of data that could be exposed in a breach
- It lowers legal and compliance risk from keeping information longer than necessary
- It cuts storage costs tied to outdated records.
From a compliance perspective, it supports GDPR data retention obligations by showing that your business doesn’t keep personal data indefinitely without a reason. In the UK, the ICO is clear that personal data should not be retained on a “just in case” basis, but only for as long as it is necessary for the relevant purpose.
From a security perspective, less unnecessary data means less exposure. If your business suffers a breach, every outdated customer record, old payroll file, unused export, or forgotten inbox attachment may increase the amount of information affected.
That is why retention should be part of your broader approach to data breach prevention. How long you keep data directly affects exposure: the longer unnecessary records stay in your systems, the more there is for an attacker to access, steal, or expose.
From an operational perspective, retention rules reduce guesswork. Employees should know what to keep, where to store it, when to delete it, and who owns the decision. That is especially important for growing teams where data may be spread across email, cloud storage, HR systems, finance software, CRMs, shared drives, and vendor platforms.
What kind of data needs a retention schedule?
A data retention schedule is the working part of a data retention policy. It maps each data category to a retention period, owner, storage location, deletion method, data breach protection measures, and reason for keeping it.
SMBs should start with the data categories they use every day.
Employee records
Employee records don’t all follow the same retention logic. Some need to be kept because of statutory requirements, some because they may be needed to resolve disputes, and others only while there is a clear business reason.
For example, ACAS(new window) says employers must keep holiday records for at least six years from the date they were made, while GOV.UK(new window) guidance on staff records says employee information should only be kept for as long as the business has a clear need for it, then disposed of securely.
Customer and prospect data
Customer data may include contact details, purchase history, support tickets, billing information, contracts, account records, and communication history. Prospect data may include marketing leads, event signups, newsletter subscriptions, and sales notes.
Keep customer data for as long as you need it to provide the service, meet contractual obligations, handle disputes, comply with accounting rules, or meet legal requirements. Marketing data needs particular care because consent, legitimate interest, unsubscribe requests, and purpose limitations all affect how long it should be retained.
Financial and tax records
Financial records include invoices, receipts, payroll records, bank statements, expense claims, VAT records, accounting records, tax documentation, contracts and purchase orders, audit reports, credit card and loan records, and employee benefit or pension records where relevant.
In many jurisdictions, company and tax law sets a minimum period for keeping accounting and financial records, though the exact length varies by country and by company type.
Contracts and legal documents
Contracts, statements of work, vendor agreements, client agreements, leases, and legal correspondence may need to be retained for the contract term and for a period afterward in case of disputes.
The exact period depends on the contract, limitation periods, sector requirements, and legal advice. The policy should define an owner for these records, usually legal, finance, operations, or leadership.
Email communications and internal documents
Business email is often where retention policies are tested. Inboxes can hold contracts, personal data, attachments, customer complaints, invoices, candidate information, passwords, and confidential business decisions.
A retention schedule should define what belongs in email, what should be moved to an approved system, and when old messages should be deleted or archived. The same logic applies to internal documents, exported reports, spreadsheets, shared folders, and chat attachments. But the policy also needs an enforcement mechanism.
Retention rules should be tied to approved systems, automated deletion settings where feasible, archive rules, and ownership checks so data doesn’t remain indefinitely just because nobody acted when the retention period ended.
Credentials, access records, and security logs
Retention also applies to security records. This may include access logs, audit trails, password records, recovery codes, admin activity, incident reports, and authentication records.
Some security records need to be kept for investigation, compliance, or operational review. Others should only be retained for a defined purpose and a documented period, then deleted or archived according to the policy, especially when they reveal how your systems work or expose sensitive access details.
Data retention, credential management, and access control overlap: retained security records need strong access controls because they can reveal how your business systems work.
UK data retention requirements: what SMBs should know
UK data retention requirements vary. They depend on the type of data, the reason for keeping it, and the legal, tax, contractual, or business obligation behind it.
For GDPR data retention, the starting point is storage limitation: personal data should only be kept for as long as necessary for the purpose. UK GDPR doesn’t have one fixed period for every category, so businesses need to set their own retention periods and justify them.
Some records have clearer rules. Limited companies generally need to keep accounting records for six years from the end of the financial year they relate to, and sometimes longer in specific circumstances. Staff records vary by record type, so sensitive employment data should be categorized carefully and reviewed with legal or HR advice where needed.
Ultimately, it isn’t possible to apply one retention period to everything. Data should be separated by category, reason for keeping it defined, and document why each period is appropriate.
Data retention policy template for SMBs
Use this structure as a simple data retention policy template. Adapt the wording to your business, sector, and legal requirements.
1. Purpose and scope
Template copy: This data retention policy explains how [Company Name] stores, retains, archives, deletes, and protects business and personal data. It applies to employees, contractors, vendors, systems, and services that collect, process, store, or access company data.
2. Data categories
Template copy: [Company Name] groups data into categories, including customer data, prospect data, employee records, financial records, contracts, operational records, security logs, and internal communications. Each category must have an owner, storage location, retention period, and deletion method.
3. Retention schedule
Template copy: Data must only be kept for as long as required for business, legal, regulatory, contractual, or security purposes. Each data category must be listed in the retention schedule with a defined retention period and reason.
Example schedule:
| Data category | Example records | Suggested retention approach | Owner | Deletion method |
| Customer data | Account records, support tickets, service history | Keep while customer relationship is active, then retain only as needed for legal, contractual, or dispute purposes | Operations or customer success | Delete or anonymize from CRM and support systems |
| Financial records | Invoices, receipts, payroll, tax documents | Generally keep for six years after the relevant financial year, unless longer retention is required | Finance | Archive securely, then delete |
| Employee records | Contracts, payroll, holiday records, HR files | Retain based on record type, statutory rules, and business need | HR or operations | Delete securely from HR systems and shared storage |
| Contracts | Client agreements, vendor contracts, statements of work | Keep for contract term plus a defined dispute period | Legal, finance, or leadership | Archive securely, then delete |
| Security logs | Access logs, admin activity, incident records | Keep for investigation, security, and accountability needs, then delete or archive based on risk | IT or security owner | Delete or archive securely |
| Marketing data | Leads, newsletter lists, campaign records | Keep while there is a valid purpose and suppression rules are respected | Marketing | Delete, anonymize, or suppress as appropriate |
4. Access controls
Template copy: Access to retained data must be limited to people who need it for their role. Sensitive data must be stored in approved systems, protected by strong authentication, and reviewed regularly. Shared credentials must not be used to access retained data unless they are managed through an approved business password manager.
This section is where retention connects directly to credential management. Data that must be kept still needs protection. If old contracts, payroll files, customer records, or security logs remain accessible to people who no longer need them, the retention policy is only solving half the problem.
A business password manager supports access control by helping teams create strong credentials, store them securely, and share access only with authorized people. Proton Pass for Business helps teams manage credentials in encrypted vaults and use secure sharing, so retained data is less likely to be exposed through reused passwords or informal access.
5. Deletion and disposal
Template copy: When the retention period ends, data must be securely deleted, anonymized, or archived according to the retention schedule. Paper records must be shredded or disposed of securely. Digital records must be deleted from approved systems, shared drives, backups where appropriate, and any unmanaged storage locations. Deletion should be documented for sensitive data. Employees should also know where not to store information, such as personal drives, unapproved spreadsheets, or chat threads. If a data category becomes subject to a legal hold, dispute, audit, or investigation, deletion must be paused until legal or leadership authorizes the next step.
6. Responsibilities
Template copy: Each data category must have an owner responsible for retention decisions, access reviews, deletion, and policy updates. Employees are responsible for storing data in approved systems and reporting data they believe is outdated, duplicated, or stored in the wrong place.
7. Review cadence
Template copy: This policy and retention schedule will be reviewed at least annually, and sooner if [Company Name] introduces new systems, changes legal obligations, experiences a security incident, or changes how it collects or processes personal data.
Access control and retained data
A retention policy should never be separated from access control. Keeping data for a valid reason does not mean everyone should be able to reach it.
Retained data often includes sensitive information: employee files, customer records, tax documents, contracts, security logs, and incident reports. If access is unmanaged, older data can become an easy target during an account compromise. It can also create internal risk if employees can open records unrelated to their role.
Access controls should answer:
- Who can access each retained data category?
- Which systems store it?
- Which credentials protect it?
- Is MFA enabled?
- Are shared credentials controlled?
- When was access last reviewed?
- What happens when someone leaves or changes roles?
- Are third-party vendors and suppliers granted access, and is it controlled?
Data retention is connected to credential management. For breach prevention, access control also reduces blast radius. If an attacker compromises one account, they should not automatically reach years of archived customer data, old contracts, or employee records. Creating a password policy can help teams define rules for password creation, sharing, access management, and authentication.
For breach prevention, access control also reduces blast radius. If an attacker compromises one account, they should not automatically reach years of archived customer data, old contracts, or employee records. Proton’s guide to data breach protection for businesses explains why limiting access and reducing unnecessary exposure are important before an incident happens.
A business password manager such as Proton Pass for Business can also help teams control and review access to the credentials that unlock retained data, with centralized management, secure sharing, and clearer ownership through the admin panel.
Common data retention policy mistakes
Many SMBs already have informal retention habits, but not a reliable policy. The most common mistakes are easy to make: keeping too much data, applying one rule to every record, forgetting copies in everyday systems, deleting without checking legal holds, or keeping retained data accessible to too many people.
| Mistake | Why it creates risk | What to do instead |
| Keeping everything forever | Storing data “just in case” can increase compliance risk and breach exposure. | Keep data only while there is a clear legal, contractual, security, or business reason. |
| Using one retention period for everything | Financial records, employee files, marketing leads, contracts, and logs serve different purposes. | Define retention periods by data category. |
| Forgetting email, spreadsheets, and exports | Copies may remain in inboxes, downloads folders, shared drives, or unmanaged files. | Include secondary storage locations in the policy. |
| Deleting without checking legal holds | Some data may need to be preserved for disputes, audits, investigations, or regulatory obligations. | Add a review step before deletion. |
| Ignoring access to retained data | Kept data can still be exposed if too many people can access it. | Assign owners, restrict permissions, and review access regularly. |
Turn retention rules into everyday practice
A practical policy starts with the data your business already holds and turns it into a schedule people can follow. Each category should have a reason for being kept, an owner, a review cadence, and a clear deletion process. While that data remains in your systems, access should stay limited to the people who genuinely need it.
For many SMBs, credential management is one of the easiest places to make improvements. Strong passwords, secure sharing, and controlled access help make sure retained data is only available to the people who need it.
Control who can access retained data in your business with a secure business password manager.






