Outbound Wiki

Prospect data retention periods

Setting different maximum holding periods for prospect records based on data type, relationship status, and jurisdiction.

Prospect data does not have one expiry date. Set the rule at the record level: what the record contains, why it is held, who it concerns, which jurisdiction applies, and what event ends the need. The retention clock may start at an operational event such as the last entry, case closure, or supersession, so a record's age is not automatically measured from collection.1 There is no single retention period for every business or data set, and different data categories need different periods.23

Start with purpose

Before choosing a period, write down what the record is still for. If you cannot name that purpose, send the record to review.

Personal data must not be kept longer than needed.4 You need to justify how long you keep it by reference to the purpose for holding it.5 Use a policy with standard retention periods wherever possible.6 That gives each record a default rule while allowing for a documented exception.

Build the schedule

Turn the policy into steps that a rep, operator, or reviewer can follow. Move to the next stage only after the current record has a clear answer.

Stage What you are trying to learn Example question
Inventory the personal data held and why it is needed7 What personal data do we hold, and why do we need it?
Category which records serve separate purposes Is this a profile, consent record, activity record, or recording?
Relationship whether the current relationship changes the purpose Is this contact still active for the purpose that justified keeping the record?
Jurisdiction which operating locations and obligations apply Where do we operate, and which rules apply to this record?
Period how long the stated purpose or obligation lasts What would make us stop needing this record?
Trigger what event starts the retention clock Does the period begin after the last entry, closure, or supersession?
Expiry what happens when the period ends Will we erase, make the record anonymous, or review it?

Record the answer beside the category, purpose, period, trigger, and expiry action. A schedule with only a date does not explain why that date applies.

Set rules by record type

Keep records separate when they serve different jobs. A prospect profile, consent record, activity record, and recording can stop being useful at different points.

Keep opt-in records while the contact is active, with a retention buffer for late complaints.8 Set the exact period with legal counsel based on the applicable jurisdiction.9 Email, voice recordings, and meeting recordings can have their own retention and deletion schedules.10

Records connected to a statutory obligation need a period that reflects that obligation.11 Data processed while preparing a legal claim can continue to be stored as the legal proceedings develop.12 Put that reason in the schedule so a legal or compliance hold does not look like an unexplained extension.

Account for jurisdiction and status

Retention requirements depend on where the business operates, the type of data collected, and how the business uses it.13 Geographic, industry-specific, and privacy rules can combine to create the applicable obligations.14

The GDPR does not prescribe a fixed retention period for each type of data.15 Use the purpose and applicable statutory duties to set the period, then record the reasoning.

Under the CPRA, a business controlling the collection of California consumers' personal information must disclose at or before collection how long it intends to retain each category, or the criteria used to set the period.16 The CPRA also prohibits retaining personal information or sensitive personal information longer than reasonably necessary for the disclosed collection purpose.17

When the relationship changes, revisit the purpose and the trigger. A contact becoming inactive can end one purpose while leaving a consent record or a legal obligation with a separate reason to remain.

Run review and expiry

A retention date should prompt a decision. Include the decision and disposal method in the policy.

Your policy should define what data to retain, how long to retain it, the format to use, and the requirements and procedures for deleting it.18 Write procedures for destruction and apply them consistently.19

When the identified purpose ends, the record should be destroyed, erased, or made anonymous.20 Dispose of or destroy it carefully so unauthorised parties cannot gain access.21 Cover both physical and electronic forms of the record.22

Review the data you hold periodically and erase or anonymise it when you no longer need it.23 An individual has a right to erasure when the organisation no longer needs the data.24 The review should also check whether a new purpose, statutory duty, or legal proceeding has changed the decision.

What not to do

Treating retention as storage by default creates avoidable failures. Keep these practices out of the schedule.

  • Do not keep prospect information merely in case it becomes useful later.25
  • Do not retain massive amounts of personal information indefinitely, because doing so increases the risks and consequences of a potential data breach.26
  • Do not dismiss a challenge to keeping a record. Consider the challenge carefully.27

Sources

  1. 1
    “The retention period is defined as the specified time following the last entry, financial year, case or project closure or the date the data is superseded, depending on the type of data and or its context.”
  2. 2
    “The answer isn't one-size-fits-all.”
  3. 3
    “Different data categories require different retention periods.”
  4. 4
    “You must not keep personal data for longer than you need it.”
  5. 5
    “You need to think about – and be able to justify – how long you keep personal data. This will depend on your purposes for holding the data.”
  6. 6
    “You need a policy setting standard retention periods wherever possible, to comply with documentation requirements.”
  7. 7
    “☐ We know what personal data we hold and why we need it.”
  8. 8
    “For as long as the contact is active, plus a retention buffer for late complaints.”
  9. 9
    “Set the exact period with your legal counsel based on your jurisdiction; many businesses retain consent logs for several years.”
  10. 10
    “You will be able to set up an email, voice recording, and meeting recording retention and deletion schedule as follows:”
  11. 11
    “organisations must have regard to any statutory obligations imposed on them as a data controller when determining appropriate retention periods.”
  12. 12
    “their storage can and should legitimately last depending on the institution and subsequent evolution of the legal proceedings.”
  13. 13
    “It depends on where you operate, what kind of data you collect, and what your business does with it.”
  14. 14
    “In practice, you'll likely juggle a mix of geographic, industry-specific, and data privacy regulations that together create your compliance obligations.”
  15. 15
    “the General Data Protection Regulation (GDPR) does not stipulate specific retention periods for different types of data”
  16. 16
    “The CPRA brings this fundamental tenet stateside, providing that “[a] business that controls the collection of consumer’s personal information shall, at or before the point of collection, inform consumers as to . . . the length of time the business intends to retain each category of personal information, or if that is not possible, the criteria used to determine such period.””
  17. 17
    “The law also affirmatively prohibits businesses from “retain[ing] a consumer’s personal information or sensitive personal information for each disclosed purpose for which the personal information was collected for longer than is reasonably necessary for that disclosed purpose.””
  18. 18
    “Specifically, it defines what types of data should be retained, how long the data should be retained and in what format, and the requirements and procedures to delete data when it is no longer needed.”
  19. 19
    “Organizations shall develop guidelines and implement procedures to govern the destruction of personal information.”
  20. 20
    “personal information that is no longer required to fulfil the identified purposes should be destroyed, erased, or made anonymous.”
  21. 21
    “Moreover, Paragraph 4.7.5 specifies that care shall be used in the disposal or destruction of personal information, to prevent unauthorized parties from gaining access to the information.”
  22. 22
    “This information can be in physical or electronic forms.”
  23. 23
    “You should also periodically review the data you hold, and erase or anonymise it when you no longer need it.”
  24. 24
    “Individuals have a right to erasure if you no longer need the data.”
  25. 25
    “the days of keeping customer information "just in case" are firmly behind us.”
  26. 26
    “The capacity and desirability to retain massive amounts of personal information indefinitely increases the risks and consequences of a potential data breach.”
  27. 27
    “You must carefully consider any challenges to your retention of data.”