Prospect data does not have one expiry date. Set the rule at the record level: what the record contains, why it is held, who it concerns, which jurisdiction applies, and what event ends the need. The retention clock may start at an operational event such as the last entry, case closure, or supersession, so a record's age is not automatically measured from collection.1 There is no single retention period for every business or data set, and different data categories need different periods.2, 3
Start with purpose
Before choosing a period, write down what the record is still for. If you cannot name that purpose, send the record to review.
Personal data must not be kept longer than needed.4 You need to justify how long you keep it by reference to the purpose for holding it.5 Use a policy with standard retention periods wherever possible.6 That gives each record a default rule while allowing for a documented exception.
Build the schedule
Turn the policy into steps that a rep, operator, or reviewer can follow. Move to the next stage only after the current record has a clear answer.
| Stage | What you are trying to learn | Example question |
|---|---|---|
| Inventory | the personal data held and why it is needed7 | What personal data do we hold, and why do we need it? |
| Category | which records serve separate purposes | Is this a profile, consent record, activity record, or recording? |
| Relationship | whether the current relationship changes the purpose | Is this contact still active for the purpose that justified keeping the record? |
| Jurisdiction | which operating locations and obligations apply | Where do we operate, and which rules apply to this record? |
| Period | how long the stated purpose or obligation lasts | What would make us stop needing this record? |
| Trigger | what event starts the retention clock | Does the period begin after the last entry, closure, or supersession? |
| Expiry | what happens when the period ends | Will we erase, make the record anonymous, or review it? |
Record the answer beside the category, purpose, period, trigger, and expiry action. A schedule with only a date does not explain why that date applies.
Set rules by record type
Keep records separate when they serve different jobs. A prospect profile, consent record, activity record, and recording can stop being useful at different points.
Keep opt-in records while the contact is active, with a retention buffer for late complaints.8 Set the exact period with legal counsel based on the applicable jurisdiction.9 Email, voice recordings, and meeting recordings can have their own retention and deletion schedules.10
Records connected to a statutory obligation need a period that reflects that obligation.11 Data processed while preparing a legal claim can continue to be stored as the legal proceedings develop.12 Put that reason in the schedule so a legal or compliance hold does not look like an unexplained extension.
Account for jurisdiction and status
Retention requirements depend on where the business operates, the type of data collected, and how the business uses it.13 Geographic, industry-specific, and privacy rules can combine to create the applicable obligations.14
The GDPR does not prescribe a fixed retention period for each type of data.15 Use the purpose and applicable statutory duties to set the period, then record the reasoning.
Under the CPRA, a business controlling the collection of California consumers' personal information must disclose at or before collection how long it intends to retain each category, or the criteria used to set the period.16 The CPRA also prohibits retaining personal information or sensitive personal information longer than reasonably necessary for the disclosed collection purpose.17
When the relationship changes, revisit the purpose and the trigger. A contact becoming inactive can end one purpose while leaving a consent record or a legal obligation with a separate reason to remain.
Run review and expiry
A retention date should prompt a decision. Include the decision and disposal method in the policy.
Your policy should define what data to retain, how long to retain it, the format to use, and the requirements and procedures for deleting it.18 Write procedures for destruction and apply them consistently.19
When the identified purpose ends, the record should be destroyed, erased, or made anonymous.20 Dispose of or destroy it carefully so unauthorised parties cannot gain access.21 Cover both physical and electronic forms of the record.22
Review the data you hold periodically and erase or anonymise it when you no longer need it.23 An individual has a right to erasure when the organisation no longer needs the data.24 The review should also check whether a new purpose, statutory duty, or legal proceeding has changed the decision.
What not to do
Treating retention as storage by default creates avoidable failures. Keep these practices out of the schedule.
- Do not keep prospect information merely in case it becomes useful later.25
- Do not retain massive amounts of personal information indefinitely, because doing so increases the risks and consequences of a potential data breach.26
- Do not dismiss a challenge to keeping a record. Consider the challenge carefully.27