openskills.info
Course Preview

Data Retention

Data retention defines how long an organization keeps different types of data and what happens when that period expires. It balances legal requirements, business needs, storage costs, and privacy obligations through policies that specify retention periods and disposal methods.

itStorage, backup, and data protection

Data Retention

Data retention is the controlled keeping and disposal of data over time. It answers a deceptively practical question: When should this data stop existing here?

The answer is rarely one number. A customer invoice, security log, product metric, employee file, and database backup serve different purposes. Different rules may apply. Each copy may also have a different technical path to deletion.

A sound retention program turns those differences into explicit decisions. You identify a data category, explain why it exists, choose a retention trigger and period, define exceptions, and assign an owner. You then implement those decisions across every system that stores a copy.

The result is a retention schedule. The schedule connects governance to system behavior. A policy may say that the organization limits retention. The schedule says which data, for how long, starting from which event, under whose authority, and with what final action.

Why retention exists

Keeping data can preserve evidence, support operations, enable recovery, and satisfy legal or contractual duties. Deleting data can reduce privacy exposure, security impact, discovery burden, and storage cost.

These goals create tension:

  • Delete too early, and you may lose records, recovery points, or evidence that you still need.
  • Keep too long, and you carry data without a current purpose or authority.
  • Apply one period to everything, and you ignore meaningful differences between data categories.
  • Delete only the visible copy, and versions, replicas, exports, or backups may remain.

Retention is therefore a risk decision, not a storage cleanup project. It needs input from the data owner, records or legal specialists, privacy staff, security staff, and system operators.

Start with purpose and authority

A retention decision starts with the reason for keeping the data. Common reasons include an active business process, a records requirement, a contract, security monitoring, recovery, or an approved research purpose.

Continue the course

This section is part of the paid course.

See pricing to subscribe, or log in if you already have access.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources