Developing a Retention Schedule: A Guide

Developing a retention schedule is a key part of preserving records until it is time to archive them or destroy them. In this article we will explore the key elements to developing a retention schedule and how to get started.

Contents

Why Have a Retention Schedule?

A retention schedule or retention period tells you how long to keep information depending on its type. Once the retention period is up you can then make a decision on whether to archive or destroy the record in question.

This is an important part of records management, which is the framework under which organisational records are curated.

Further Reading

  • learn more about records management here.

  • find out about destroying data and information here.

  • understand archiving records here.

  • you can find an introduction to information security here.

Understanding Retention Requirements

In the realm of information governance, the bedrock of a robust retention schedule lies in a clear comprehension of the legal and regulatory landscape that surrounds data management. Let’s delve into the intricacies of this foundational aspect.

The Legal and Regulatory Framework

At the heart of retention scheduling are the legal frameworks and regulations that govern data across various industries and jurisdictions. An understanding of these legal obligations is important for crafting a retention schedule that not only aligns with the law but also stands as a bulwark against legal pitfalls.

Data Protection Laws

Regulations such as the General Data Protection Regulation (GDPR) set stringent requirements for the handling and retention of personal data. Familiarity with the principles embedded in these laws is essential for compliance.

It is important, as part of GDPR compliance requirements, to know how long you will retain personal data for. You should also make appropriate arrangements for disposing of personal data when it is no longer needed.

Industry-Specific Regulations

Different sectors, from healthcare to finance, have industry-specific regulations governing data retention. Navigating this intricate web of rules ensures that the retention schedule is tailored to the unique demands of a particular business domain. These can provide guidance for your own organisation’s retention schedule. For example, the Department of Health and Social Care has a retention schedule for healthcare related data, which is available here.

Industry-Specific Compliance

The second layer of understanding retention requirements involves delving into industry-specific compliance standards. Many industries have their own set of rules and norms dictating how data should be handled, stored, and ultimately, disposed of. For instance:

Financial Services

Financial institutions are subject to regulations like the Sarbanes-Oxley Act (SOX), which mandates specific retention periods for financial records. Adhering to these regulations is imperative for regulatory compliance.

Navigating this intricate terrain requires a keen eye for detail and a proactive approach to stay abreast of evolving legal and regulatory landscapes. A comprehensive understanding of the legal and regulatory framework surrounding data retention lays the groundwork for creating a retention schedule that is not just compliant but resilient in the face of legal scrutiny

Inventory of Information Assets

Once the legal and regulatory landscape is understood the next step in developing a retention schedule involves taking stock of an organisation’s information assets. This process is akin to creating an inventory, cataloging the diverse types of data in play.

Identifying Types of Information

The first task is to identify the various types of information that an organisation handles. This includes everything from customer data and financial records to internal reports, emails, and even metadata associated with different datasets. Examples of records types include:

Estates

Estates information includes things like building plans, CCTV footage, leases and records of maintenance work.

Communications

Communications records include public consultations, public facing information, press releases and visitor records to your website.

Staff Records

Staff records range from applications received to data around pensions and will include training records, sick records and tax information.

Categorising Data Sensitivity

Not all data is created equal, and recognising the sensitivity levels of different types of information is fundamental to crafting a nuanced retention schedule.

Confidential Information

This category encompasses sensitive information, such as trade secrets or proprietary data, that requires a heightened level of protection and careful consideration in retention decisions.

Compliance-Related Data

Information that directly relates to compliance with legal or industry-specific regulations often demands specific handling and retention procedures.

This inventorying phase lays the groundwork for the subsequent steps in the retention scheduling process. By categorising and understanding the various types of information an organisation manages, one can tailor retention periods and security measures to suit the unique attributes of each data category.

Determining Retention Periods

With a comprehensive understanding of the legal landscape and a detailed inventory of information assets, the next critical step in developing a retention schedule involves determining the appropriate retention periods for each category of data. This process is not only influenced by legal mandates but also demands a delicate balance with operational needs.

Balancing Business Needs

While legal mandates provide a foundation, the intricacies of operational requirements and business needs must be carefully considered. Striking a harmonious balance between compliance and operational efficiency involves:

Operational Value of Information

Assessing the ongoing operational value of information is crucial. Data that actively contributes to business processes or decision-making may warrant a longer retention period.

Space and Resource Constraints

The practical aspects of data storage, including costs and resource constraints, should be factored in. Retaining data indefinitely may not be operationally or economically feasible.

This phase of determining retention periods requires a nuanced understanding of both the external regulatory environment and the internal dynamics of the organisation. The goal is to create a retention schedule that not only meets legal requirements but also aligns seamlessly with the practical needs and objectives of the business.

Factors Influencing Retention Decisions

Numerous elements influence the decision to retain or dispose of data:

Operational Value of Information

The usefulness of information in ongoing operations is a key factor. Valuable data may warrant longer retention. unnecessary records can be destroyed quickly, freeing up space and other resources. The table below sets out some types of records that may need short or long term retention:

Record Retention Period
Shift patterns Short
Board papers Long
HR records Long
Utility bills Short
Contracts Long

Potential Legal Risks

Assessing legal risks associated with retaining certain types of information is vital. It’s a delicate dance between risk aversion and operational necessity.

For example retaining personal data for longer than is reasonable causes a legal risk around GDPR compliance. Conversely deleting data, like financial information, too soon could mean you are unable to mount a defence if you are subject to legal challenges

Crafting a Comprehensive Policy

A well-documented document retention policy is the cornerstone of effective retention management. The policy will document for all staff

  • statutory and regulatory compliance requirements

  • the organisation’s approach to paper and electronic records management

  • link to the records retention schedule

  • the potential consequences of non-compliance

Documenting Retention Guidelines

Clear guidelines on how different types of information should be handled streamline decision-making processes. Even if the content is the same the medium may mean different approaches are taken. Physical records need different management to electronic records, for example in records storage requirements.

Incorporating Stakeholder Input

Including input from various stakeholders ensures that the policy is practical, aligns with business goals, and considers diverse perspectives. Examples of stakeholders include:

  • customers

  • suppliers

  • industry bodies

  • colleagues of business areas which handle different types of data

Ensuring Accessibility and Security

Retained data should be both accessible and secure. That means it needs to be:

  • stored in a way that makes it easy to find – having the right filing system

  • restricted to those who need access to it, and no-one else

  • maintained by the record owner or other accountable person

Access controls in particular are key for information security.

Balancing Access Needs and Security Measures

Striking a balance between allowing necessary access for business purposes and maintaining robust security protocols is critical. Examples of information security include:

  • access controls, and logs of access to records

  • physical and electronic security such as locks on doors and filing cabinets

  • avoiding duplication of records and keeping one set of master records

Training and Communication

People need to both understand retention periods and related policies, and know where to fine them. The key to this is a combination of training and communication.

Educating Employees on Retention Policies

Training programs that educate employees about information governance are important because they will enhance information security and data protection. As part of this people need to be taught about retention periods, data deletion and information archiving.

Regular Communication and Updates

Consistent communication and updates about changes in retention policies foster a culture of awareness and responsibility. Reminding people of their responsibilities, where supporting information like policies can be found, and who can help them will provide an audit trail of compliance.

Learn More About Information Governance

X

Training testimonial

Conclusion: Key Takeaways from Developing a Retention Schedule

Crafting a retention schedule is a meticulous process that demands a good understanding of legal landscapes, business needs, and technological solutions. It is a blueprint for responsible information management, ensuring that organisations navigate the complexities of data retention well. In an era where data is both a valuable asset and a potential liability, a well-developed retention schedule supports compliance, efficiency, and data stewardship.