Outbound Wiki

Data retention

How long prospect data may be kept, and how to document the basis for holding it.

Treat prospect retention as a documented decision. Start with why the data exists, then check whether a rule or business purpose still justifies holding it. A company-wide timeout creates gaps because different purposes, data types, and obligations can call for different periods. The answer to "how long?" is a documented rule for each category, plus a review and disposal action when that rule ends. If you cannot explain the purpose or trigger, send the record into review before extending its life by habit.

Run the decision

Start with the record. Before choosing a period, identify what you hold and why it is still there.

Stage What you are trying to learn Example question
Inventory the personal data in the record and its purpose1 Which fields are in this record, and what job does each field do?
Purpose the original collection purpose and the purpose still in force Why did we collect this, and what purpose remains?
Requirements any legal, regulatory, contract, or operational constraint Does a rule require us to keep it?
Period the endpoint and the event that starts it What event starts the retention period?
Action whether the end action is erasure, anonymisation, or documented preservation What happens when the period ends?

Before choosing a date, review the purpose that led to collection. Reviewing the original collection purpose helps assess how long the data should be retained.2 Record the answer against the data category so another person can follow the decision.

Set the period

Use the purpose as the first boundary, then check whether another obligation changes the result. The period should come from the record's use and its end point.

Data protection law requires personal data to remain identifiable only for as long as necessary for the purpose for which it is processed.3 Consider and justify how long you keep it based on the purposes for holding it.4

Before setting the period, check for outside requirements. Some organisations have a legislative requirement to keep information for a specified amount of time.5 Laws, regulations, and contractual obligations can drive different retention periods.6 When no legislative requirement exists, the organisation needs to determine an appropriate period.7

The trigger can be the last entry, the end of a financial year, case or project closure, or the date the data is superseded, depending on the data and context.8 Choose the event that matches how the record is used, and write it into the schedule.

If the data helped make a decision about a person, retain it for the legally required period, or for a reasonable period where no such requirement exists, so the person can access it, understand the decision, and possibly challenge its basis.9 Personal data can be kept longer when it is kept only for public interest archiving, scientific or historical research, or statistical purposes.10 Treat that as a specific purpose decision and document it.

Write the rule down

A retention decision only works when someone can apply it consistently. Write the rule so the person handling the record knows what stays, for how long, and what happens at the end.

Set standard retention periods wherever possible to meet documentation requirements.11 Keep the policy and schedule plain enough to explain what counts as a record, what is maintained, how long different categories remain, and how expired records may be disposed of.12

Include the scope of the policy, key definitions, legal hold procedures, and approved destruction procedures.13 For each category, record a short description, its location, and the business function responsible for retaining and destroying it within the applicable period.14

Relevant business units should help set timeframes based on how the record is used, why it is used, and its contractual value.15 This gives the schedule a usable owner and keeps the stated purpose connected to the actual work.

Consent records need their own entry in the schedule when they support an outreach decision. Preserve enough detail to explain what happened and when.

Where a prospect record relies on an authorisation, retain the consent form, when consent was given, and through whom it was obtained.16 For CEMs, keep signed or completed electronic consent forms, consent process documentation, compliance policies and procedures, and unsubscribe requests with their implementation in the record set.17

A separate telemarketing requirement calls for verifiable authorisations or records of express informed consent or express agreement to be retained for two years from production.18 Keep channel-specific records in the schedule with the rule that created the duty, so a general prospect retention period does not erase a separate recordkeeping requirement.

Review and dispose

Set a review point for each category and make the end action explicit. At review, decide the end action for each record and move expired records out of the same pool.

Periodically review the data you hold, then erase or anonymise it when you no longer need it.19 The policy should also define the procedures and requirements for deleting data that is no longer needed or required to be retained.20

If keeping the data longer could prejudice the person or increase the risk and exposure of a breach, consider safe disposal.21 Route any retention challenge through the documented review process, consider it carefully, and record the reasoning behind the outcome.22

What not to do

The common failures come from treating retention as a default storage setting. Keep these out of the process:

  • Do not apply the same period to every prospect record. Retention requirements can vary with the organisation's business activities and the types of data it collects.23
  • Do not treat an erasure request as irrelevant. An individual has a right to erasure when the organisation no longer needs the data.24
  • Do not keep as much data as possible for as long as possible. That approach increases risk and can create negative consequences.25

Sources

  1. 1
    “☐ We know what personal data we hold and why we need it.”
  2. 2
    “Reviewing the purpose for having collected the personal information in the first place is generally helpful in assessing how long certain personal information should be retained.”
  3. 3
    “Data protection law requires that ‘Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed’.”
  4. 4
    “You need to think about – and be able to justify – how long you keep personal data. This will depend on your purposes for holding the data.”
  5. 5
    “For some organizations, there is a legislative requirement to keep information for a certain amount of time.”
  6. 6
    “As noted previously, laws, regulations, and contractual obligations will drive the data retention period, and these can often be different.”
  7. 7
    “In other instances, there may be no legislative requirement, and an organization needs to determine the appropriate retention period.”
  8. 8
    “The retention period is defined as the specified time following the last entry, financial year, case or project closure or the date the data is superseded, depending on the type of data and or its context.”
  9. 9
    “If personal information was used to make a decision about an individual, it should be retained for the legally required period of time thereafter – or other reasonable amount of time in the absence of legislative requirements – to allow the individual to access that information in order to understand, and possibly challenge, the basis for the decision.”
  10. 10
    “You can keep personal data for longer if you are only keeping it for public interest archiving, scientific or historical research, or statistical purposes.”
  11. 11
    “You need a policy setting standard retention periods wherever possible, to comply with documentation requirements.”
  12. 12
    “Clear & Complete. A record retention policy and corresponding retention schedule should be plain and simple so that any employee within the company can review and understand the company’s expectations as to: (i) what is a record under the policy; (ii) what records are maintained; (iii) how long different kinds of records should be retained; and (iv) acceptable practices for disposing of the records when their retention periods have expired.”
  13. 13
    “Ideally, the retention policy should include the scope of the policy, key definitions, legal hold procedures, and approved destruction procedures.”
  14. 14
    “Similarly, the accompanying retention schedule should cover all relevant categories of records and include summary descriptions of each category, where they are located, and the business function that is responsible for retaining (and destroying) the record in accordance with the retention schedule’s timeframe.”
  15. 15
    “But relevant business units should be involved in determining the appropriate timeframes for retention based on how the particular record is used and for what purpose or the contractual value of the record.”
  16. 16
    “Further, in addition to storing consumer contact information, businesses must retain the consent forms, information as to when consent was given, and through whom.”
  17. 17
    “organizations that send CEMs should retain records, such as any signed consent forms or completed electronic forms from individuals, documentation of the organization's consent processes, records of their policies and procedures in respect of CASL compliance, and a record of all unsubscribe requests and their resulting implementation.”
  18. 18
    “all verifiable authorizations or records of express informed consent or express agreement.”
  19. 19
    “You should also periodically review the data you hold, and erase or anonymise it when you no longer need it.”
  20. 20
    “Data Deletion – A key component of a data retention policy includes the procedures and requirements to delete data that is no longer needed or required to be retained.”
  21. 21
    “If retaining personal information any longer would result in a prejudice for the concerned individual, or increase the risk and exposure of potential data breaches, the organization should consider safely disposing of it.”
  22. 22
    “You must carefully consider any challenges to your retention of data.”
  23. 23
    “Often, these requirements can vary based on the business activities of the organization and the types of data collected.”
  24. 24
    “Individuals have a right to erasure if you no longer need the data.”
  25. 25
    “While it may seem like a good idea to hold on to as much data as possible for as long as possible, such a strategy comes with increased risk and potentially negative consequences.”