Traceability and compliance
The deletion you do have to do
Keeping everything forever is not prudence: in some cases it is a breach.
The default reflex is to keep everything just in case, and for most documents that is reasonable. For those containing personal data it is not: keeping them beyond what is necessary stops being prudence and becomes a problem.
The three groups
| Group | Criterion | Examples |
|---|---|---|
| Kept by obligation | A legal period sets the minimum | Tax, employment, safety |
| Kept by interest | While a claim remains possible | Contracts, deliveries, evidence |
| Deleted | When no longer needed for the purpose collected | Rejected applications, visitor logs, ID copies |
Important
The third group is the one almost nobody has defined, and the only one where not acting is itself the breach. A CV from someone you did not hire four years ago is not kept out of prudence: it is kept because nobody decided what to do with it.
How to build a policy that runs itself
- 1
List the document types you hold
By type, not by document. Usually fewer than twenty.
- 2
Assign a period to each type
Using the criteria above and, when unsure, asking your advisers.
- 3
Have the clock start from an event, not from upload
"Four years from contract end", not "from when it was uploaded".
- 4
And review it annually
Obligations change and so do the document types you handle.
Watch out
The expensive mistake is automatic deletion with no exceptions. If there is open litigation or a live request, retention stops being your decision: you must be able to suspend deletion for what is affected, and know what that is.
What is not deleted when you delete
The first line matters: being able to show something was deleted when it should have been is as useful as being able to show it was kept.
Worth knowing
If someone exercises their right to erasure, this is already half done: you know where their material is, what can be deleted and what must be kept by obligation, which is exactly what you must tell them.
›How long must each thing be kept?
It depends on type and country. That is the part to check rather than improvise.
›What if I delete something that was needed?
Hence assigning periods by type and reviewing them; deleting without criteria is worse than not deleting.
›Can it be automated?
The warning yes. The decision to delete is better confirmed by a person.
A real case
The situation
A company keeps CVs from recruitment processes five years old.
What you do
- Defines periods by document type and start event
- Suspends deletion for anything caught by open litigation
What you get
Stops accumulating data it should not hold and can show when each item was deleted.
The situation
Everything is kept and grows unchecked.
What you do
- Reviews what has passed its period
What you get
The archive stops growing without criteria.
The situation
Things are deleted without checking whether they had to be kept.
What you do
- Checks the policy before deleting
What you get
Deleting stops being a gamble.
The situation
A client asks for their material to be deleted.
What you do
- Locates where it appears and acts on the policy
What you get
The request is handled on a basis.
The situation
Deletion happens and there is no record of it.
What you do
- Records what was deleted and when
What you get
What was done is demonstrable.
The situation
Nobody is responsible for reviewing the periods.
What you do
- Schedules the periodic review
What you get
Deletion happens because it is due, not because somebody remembers.
This article answers
- when personal data must be deleted
- document retention policy
- cannot keep everything indefinitely
- deleting documents with personal data