Treat prospect retention as a documented decision. Start with why the data exists, then check whether a rule or business purpose still justifies holding it. A company-wide timeout creates gaps because different purposes, data types, and obligations can call for different periods. The answer to "how long?" is a documented rule for each category, plus a review and disposal action when that rule ends. If you cannot explain the purpose or trigger, send the record into review before extending its life by habit.
Run the decision
Start with the record. Before choosing a period, identify what you hold and why it is still there.
| Stage | What you are trying to learn | Example question |
|---|---|---|
| Inventory | the personal data in the record and its purpose1 | Which fields are in this record, and what job does each field do? |
| Purpose | the original collection purpose and the purpose still in force | Why did we collect this, and what purpose remains? |
| Requirements | any legal, regulatory, contract, or operational constraint | Does a rule require us to keep it? |
| Period | the endpoint and the event that starts it | What event starts the retention period? |
| Action | whether the end action is erasure, anonymisation, or documented preservation | What happens when the period ends? |
Before choosing a date, review the purpose that led to collection. Reviewing the original collection purpose helps assess how long the data should be retained.2 Record the answer against the data category so another person can follow the decision.
Set the period
Use the purpose as the first boundary, then check whether another obligation changes the result. The period should come from the record's use and its end point.
Data protection law requires personal data to remain identifiable only for as long as necessary for the purpose for which it is processed.3 Consider and justify how long you keep it based on the purposes for holding it.4
Before setting the period, check for outside requirements. Some organisations have a legislative requirement to keep information for a specified amount of time.5 Laws, regulations, and contractual obligations can drive different retention periods.6 When no legislative requirement exists, the organisation needs to determine an appropriate period.7
The trigger can be the last entry, the end of a financial year, case or project closure, or the date the data is superseded, depending on the data and context.8 Choose the event that matches how the record is used, and write it into the schedule.
If the data helped make a decision about a person, retain it for the legally required period, or for a reasonable period where no such requirement exists, so the person can access it, understand the decision, and possibly challenge its basis.9 Personal data can be kept longer when it is kept only for public interest archiving, scientific or historical research, or statistical purposes.10 Treat that as a specific purpose decision and document it.
Write the rule down
A retention decision only works when someone can apply it consistently. Write the rule so the person handling the record knows what stays, for how long, and what happens at the end.
Set standard retention periods wherever possible to meet documentation requirements.11 Keep the policy and schedule plain enough to explain what counts as a record, what is maintained, how long different categories remain, and how expired records may be disposed of.12
Include the scope of the policy, key definitions, legal hold procedures, and approved destruction procedures.13 For each category, record a short description, its location, and the business function responsible for retaining and destroying it within the applicable period.14
Relevant business units should help set timeframes based on how the record is used, why it is used, and its contractual value.15 This gives the schedule a usable owner and keeps the stated purpose connected to the actual work.
Keep proof of consent
Consent records need their own entry in the schedule when they support an outreach decision. Preserve enough detail to explain what happened and when.
Where a prospect record relies on an authorisation, retain the consent form, when consent was given, and through whom it was obtained.16 For CEMs, keep signed or completed electronic consent forms, consent process documentation, compliance policies and procedures, and unsubscribe requests with their implementation in the record set.17
A separate telemarketing requirement calls for verifiable authorisations or records of express informed consent or express agreement to be retained for two years from production.18 Keep channel-specific records in the schedule with the rule that created the duty, so a general prospect retention period does not erase a separate recordkeeping requirement.
Review and dispose
Set a review point for each category and make the end action explicit. At review, decide the end action for each record and move expired records out of the same pool.
Periodically review the data you hold, then erase or anonymise it when you no longer need it.19 The policy should also define the procedures and requirements for deleting data that is no longer needed or required to be retained.20
If keeping the data longer could prejudice the person or increase the risk and exposure of a breach, consider safe disposal.21 Route any retention challenge through the documented review process, consider it carefully, and record the reasoning behind the outcome.22
What not to do
The common failures come from treating retention as a default storage setting. Keep these out of the process:
- Do not apply the same period to every prospect record. Retention requirements can vary with the organisation's business activities and the types of data it collects.23
- Do not treat an erasure request as irrelevant. An individual has a right to erasure when the organisation no longer needs the data.24
- Do not keep as much data as possible for as long as possible. That approach increases risk and can create negative consequences.25