Data retention policy template with a value review before deletion
A data retention policy template sets how long each class of company records is kept, who owns it, how legal holds pause deletion and how records are destroyed. This version adds a pre-disposal value review, so a mid-sized company checks holds, privacy promises, archive cost and possible licensing value before deleting old systems or mailboxes.
When to use this data retention policy template
Use this template when a mid-sized company has no written retention rules, or has rules that no system actually enforces. The usual prompts are a system migration, a push to cut storage or former-employee mailbox costs, an audit or lender request, a privacy review, or a new owner asking what records exist.
A data retention policy says how long each class of records is kept, who is responsible for it, how deletion stops when litigation or an investigation is likely, and how records are destroyed when their time is up. This version adds a step most templates skip: a pre-disposal value review that asks whether old records are worth keeping before anyone deletes them, including whether the company could license them.
Retention policy, retention schedule and deletion policy: what is the difference?
The terms get used interchangeably, but they are four different documents. Mid-sized companies often combine them into one, which is what this template does.
| Document | What it does | Who usually owns it |
|---|---|---|
| Retention policy | Sets principles, roles, the legal hold process and disposal rules | CFO or general counsel, approved by the CEO |
| Retention schedule | Lists each record class with its retention period and the event that starts the clock | Controller with department heads and counsel |
| Deletion or disposal procedure | Explains how records are destroyed and how destruction is logged | IT lead or managed service provider |
| Legal hold notice | Suspends deletion for specific records when a dispute or inquiry is reasonably anticipated | Counsel |
The data retention policy template
Copy each block into your policy document and replace every placeholder in braces.
1. Purpose and scope
2. Roles
3. Retention schedule
4. Legal hold
5. Pre-disposal value review
6. Disposal
7. Exceptions and review
Appendix A: retention schedule template
Set each period with your counsel and tax adviser. Federal, state, contractual and industry requirements differ, so the template uses placeholders rather than numbers.
| Record class | Example systems | Owner | Retention trigger | Retention period | Disposal action |
|---|---|---|---|---|---|
| Financial and tax records | {accounting_system}, payroll | Controller | Fiscal year-end | {period_set_with_tax_adviser} | Secure delete and log |
| Contracts and amendments | Contract folder, e-signature tool | COO or counsel | Contract expiry | {period} | Review, then delete |
| Customer and sales records | {crm_system}, quoting tool | Head of sales | Last account activity | {period} | Value review, then archive or delete |
| Support tickets and chat transcripts | Help desk, live chat | Head of support | Ticket closure | {period} | Value review, then archive or delete |
| Email and internal chat | Mail platform, {chat_system} | IT owner | Message date or employee departure | {period} | Value review, then archive or delete |
| Engineering records | Code repositories, issue tracker | CTO | Project end | {period} | Value review, then archive |
| HR and personnel files | HRIS | HR lead | Employee departure | {period} | Secure delete |
| Consumer personal information | Any system | Privacy lead | Purpose fulfilled | {period_disclosed_in_privacy_notice} | Secure delete |
Privacy law can set the outer limit for personal information. The California Consumer Privacy Act requires a covered business to tell consumers at collection how long it intends to keep each category of personal information, and to keep it no longer than is reasonably necessary for the disclosed purpose; see the CCPA statute text, including Civil Code section 1798.100. Whether it applies depends on the company's size and activities. This is general information, not legal, tax or financial advice. Confirm periods and obligations with your own counsel and tax adviser before adopting the schedule.
Appendix B: the pre-disposal value review
Run this checklist for each record class or system before deletion. It usually takes one conversation with the system owner and, for anything flagged, one with counsel.
- Hold check: no legal hold, audit request or open dispute touches these records.
- Obligation check: no law, contract or customer agreement requires keeping them longer.
- Promise check: deletion, and any other future use, matches what the privacy policy, terms of service and customer contracts promised.
- Cost check: the yearly cost of keeping a complete export in low-cost archive storage is known.
- Value check: the records span several years, connect to other systems and show outcomes, such as tickets resolved, deals won or lost and approvals given or refused.
- Export check: someone can still produce a complete, readable export with attachments and metadata.
- Decision logged: the policy owner signs off on the outcome.
The promise check matters most if the company might ever license records. FTC staff wrote in January 2024 that promises not to use customer data for undisclosed purposes, such as training AI models, are enforceable, whether they sit in a privacy policy, terms of service or marketing materials. That is staff guidance rather than a rule, but it is a good reason to read what the company told customers before keeping anything for that purpose.
How to act on the review
| Result | What it means | Next action |
|---|---|---|
| Hold or obligation applies | The records must be kept | Keep in place or archive; set a review date |
| No value, no obligation | The records have run their course | Dispose of them under section 6 and log it |
| Some value, low archive cost | Worth keeping cheaply | Take a complete export to archive storage before retiring the system |
| Long, connected history with outcomes | Possible licensing interest | Keep a complete export and run a preliminary fit screen before deciding |
For the last row, the company fit checker offers an initial, non-binding view of whether the company matches what AI labs and data buyers look for. If the owner wants to weigh it properly, the data licensing business case template frames the decision, and the CFO checklist for evaluating a data licensing agreement covers what to examine if an offer follows.
How to personalize the template
| Section | What to change | Who should decide |
|---|---|---|
| Scope | Name your actual systems, including archives, backups and retired tools | IT owner with the controller |
| Roles | Use titles rather than names so the policy survives turnover | CEO |
| Schedule periods | Replace every placeholder with a period your advisers confirm | Counsel and tax adviser |
| Value review | Set a size or age threshold below which no review is needed | Policy owner |
| Review cycle | Pick a fixed cycle and add event triggers for migrations and acquisitions | Policy owner |
When to revisit the policy
- At fiscal year-end close, when the controller already confirms which records the year produced.
- Before any system migration, mailbox clean-up or chat-plan downgrade; the guides on former employee mailboxes in Microsoft 365 and what a Slack or Teams downgrade does to message history show where history tends to disappear.
- After an acquisition, when the acquired company's archives arrive with their own rules.
- Whenever the privacy notice or standard customer contracts change.
What never to put in a retention policy
- Periods the company does not follow in practice, such as a deletion rule no system enforces.
- Real confidential records, customer names or sample data used as examples.
- A commitment to license, sell or share records. That decision belongs to the owner and a signed agreement, not to a policy.
- Periods copied from another company's policy without advice.
Next step
Adopt the policy with the value review in place, then start with the oldest systems. If a client's records look valuable and the company has 50+ full-time employees at peak (contractors excluded), see how fractional CFOs make referrals, then register as a partner to make an introduction.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
How long should a business keep records?
There is no single answer. Each record class has its own period, set by federal and state law, tax rules, contracts, industry regulators and the company's own needs, and personal information should not be kept longer than its disclosed purpose requires. Build the schedule class by class with counsel and a tax adviser, and start each period from a clear trigger such as fiscal year-end or contract expiry.
Should email have a fixed retention period?
Most companies set one, often with longer periods for specific roles or mailboxes such as executives, finance and legal. A single short period for everyone is simple but risky: it can destroy records that a hold, a contract or the business still needs. Whatever the period, run the value review before mailboxes of departed employees are deleted, since they often hold the longest unbroken history.
What is the difference between archiving and retaining records?
Retention is the rule that says how long a record must or may be kept. Archiving is where and how it is kept once it is no longer in active use, usually in cheaper storage with restricted access. A record can be retained in its original system or in an archive; what matters is that the archive is complete, readable and covered by the same holds and disposal rules.
Who should own the data retention policy at a mid-sized company?
Usually the CFO or general counsel, with the CEO approving it. The owner needs authority over budgets and risk, because retention decisions trade storage cost against legal exposure and business value. Day-to-day work sits with department records coordinators and the IT lead or managed service provider, who apply the settings and log disposal.
Can records kept under a retention policy be licensed to AI developers?
Possibly, if the company created them, its contracts and privacy promises allow it, and the owner chooses to. Licensing does not transfer ownership: the company licenses an agreed dataset under a signed agreement, with de-identification and redaction rules agreed before any work begins. A retention policy should never commit to licensing; it should only make sure valuable records are not deleted before the owner can decide.
Related pages
- Check Company Fit for Data Licensing
- One-page business case template for a new revenue stream, with a data license example
- A CFO checklist for evaluating a data licensing agreement
- Former employee mailboxes in Microsoft 365: cut license cost without losing records
- Before downgrading Slack or changing Teams retention, check your message history
- Referral opportunities for fractional CFOs
Free resources
- Client data licensing eligibility checker — A transparent preliminary screen for one company.
- Enterprise value calculator — Enterprise value from equity value, debt and cash.
- Earnout scenario calculator — Probability-weighted earnout value and its present value.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment