
What Is a Data Retention Policy & Which Frameworks Require One? + Template
Anna Fitzgerald
Senior Content Marketing Manager
Rob Gutierrez
Senior Cybersecurity and Compliance Manager, CISA, CCSK, CMMC RP
A data retention policy is a documented set of rules that defines which data an organization keeps, how long it keeps each type, how that data is stored, and how it is securely disposed of once it is no longer needed. It is a critical piece of documentation that translates your legal, regulatory, contractual, and business requirements into specific retention periods and disposal methods that employees and systems can apply consistently.
Most major security and privacy frameworks require organizations to have one. Some set a fixed minimum for specific records, like the six years HIPAA requires for security documentation. Others, including GDPR, CCPA, and PCI DSS, require organizations to keep data no longer than necessary and then securely delete it.
Getting this policy right is key to any organization’s cybersecurity and compliance program, but it’s becoming harder as AI adoption changes how long organizations want to keep data. According to a survey by Seagate and Recon Analytics, 90% of business leaders who have adopted AI believe longer data retention improves the quality of AI outcomes, and 93% say their data retention requirements have changed because of AI.
This guide explains what a data retention policy is, what major frameworks require one, and how to create your own using a sample policy, real-world examples, best practices, and our free template.
Key takeaways
- A data retention policy sets how long each category of data is kept and how it is disposed of when that period ends.
- Few regulations set one universal retention period. Most require you to define periods based on legal, regulatory, and business need, then dispose of data once that need ends.
- Retention, backup, and archiving are different practices, but backups and archives still need to follow your retention schedule.
- Auditors typically look for a published policy, annual employee acknowledgment, and evidence that deletion actually happens as stated (i.e., disposal logs and screenshot/export of retention settings in your email and backup system).
- For defense contractors, media sanitization, audit log retention, and incident evidence preservation make this policy a key part of NIST 800-171 compliance and CMMC readiness.
What is a data retention policy?
A data retention policy, sometimes called a data retention and destruction policy or a records retention policy, governs the lifecycle of your data from storage through disposal. It specifies how long each category of data must be kept, where and how it is stored during that period, who can access or delete it, and how it is securely destroyed when the retention period expires. The goal is to keep what you are required or need to keep, and nothing more.
Many frameworks require one. For example, PCI DSS requirement 3.2.1 calls for data retention and disposal policies that keep stored account data to a minimum and securely remove it once it is no longer needed. ISO 27001 includes Annex A controls for protecting records and for deleting information when it is no longer required. Some frameworks also set minimums for specific data, such as PCI DSS requirement 10.5.1, which requires organizations to keep audit log history for at least 12 months.
In practice, a data retention policy is how an organization shows regulators, auditors, and customers that it made deliberate, documented decisions about its data rather than keeping everything indefinitely by default.
System, backup, and database configurations must match the data retention requirements laid out in the policy. The policy defines the rules, responsibilities, and disposal methods, but the configuration settings actually apply those rules to specific data such as invoices, employee records, customer data, system logs, database audit logs, and copies such as replicas and exports.
Recommended reading

How to Write an ISO 27001 Data Retention Policy + Template
How does data retention relate to backup and archiving?
A data retention policy defines how long data is kept, where, and when it is destroyed in your organization. It should be broad in scope, covering when data is kept, moved, and destroyed in production systems, active storage, databases, backups, and archives.
This matters most at the disposal stage of the data management lifecycle. Deleting a record from a production system does not remove it from last month's backup, so a policy that ignores backups and archives can leave data in place long after the organization believes it is gone.
Think of data retention, backup, and archiving as three ways of preserving data for different purposes, each of which should be considered and reflected in your data retention policy:
- Data retention stores data for a defined period of time for the purpose of audits, transparency and accountability, and legal discovery. Data can be retained in production systems, staging environments, caches, local endpoints, and databases as well as backups and archives.
- Data backup creates copies of active systems so you can restore them in cases of accidental loss, ransomware attacks, or other disasters.
- Data archiving moves inactive data into a secure, searchable repository for long-term storage where it can still be retrieved for purposes of historical reference, audits, and legal discovery.
| Data retention | Data backup | Data archiving | |
|---|---|---|---|
| Primary purpose | Preserve data for a specific period of time in order to meet regulatory, legal, or business requirements | Store data short-term for purpose of restoring quickly after accidental loss, corruption, or an incident | Store inactive data long-term for reference, legal, or compliance needs |
| What it covers | All data categories the organization handles | Copies of active systems, databases, and files | Records no longer used day to day |
| Typical timeframe | Set per data category by law, contract, and/or business need | Rolling window, often days to months | Often years, based on the retention schedule |
| How data is accessed | Can be in production storage, live databases, backups, and archives | Can be restored in bulk and rapidly when needed | Searched and retrieved individually |
| Relationship to the others | Governs how long data is kept in all places, including backup and archives | Must not keep data longer than the policy allows without a documented reason | Holds retained data until its disposal date specified in policy |
Recommended reading

Disaster Recovery Plan (DRP): Which Frameworks Require It & How to Write One [+ Template]
Why have a data retention policy?
A data retention policy is more than good business practice or regulatory checkbox. It is a critical component of governance and cybersecurity maturity, ensuring that an organization’s data is stored, managed, and disposed of effectively while meeting legal, operational, and security requirements.
Here are some key benefits of having a data retention policy in place:
1. Compliance with laws and frameworks
Regulations and frameworks such as GDPR, PCI DSS, HIPAA, and SOC 2 set rules for how long organizations can or must retain certain types of data (see the requirements by framework below). A data retention policy helps you meet these requirements and avoid fines, legal disputes, and reputational damage.
For example, one of GDPR's data protection principles is storage limitation: businesses should keep personal data only as long as necessary for the purpose it was collected. A clear data retention policy helps you apply that principle consistently.
2. Reducing the risk and impact of data breaches
The less data you store, the less there is to expose in a data breach. By eliminating outdated or unnecessary data, a data retention policy minimizes the volume of sensitive information vulnerable to cyberattacks. If a breach does occur, the impact is typically less severe because less data was retained.
3. Improving business continuity
By defining what data should be stored and for how long, a data retention policy streamlines data organization and management. This helps ensure critical information is available when needed, such as during a disaster recovery scenario, which improves business continuity and minimizes downtime.
4. Enhancing data quality
Outdated, duplicate, or irrelevant data clutters storage systems, making it harder to find and use valuable information. A data retention policy helps organizations regularly purge unnecessary data so that retained data stays accurate, relevant, and high quality. This improves decision-making and operational efficiency.
5. Optimizing storage costs and efficiency
Storing excessive amounts of data can drive up costs, whether you use on-premises storage or cloud services. By retaining only the data you need and disposing of the rest, you can reduce storage expenses and improve system performance.
6. Establishing accountability and transparency
A data retention policy provides clear guidelines for employees and stakeholders, so everyone understands their responsibilities for data management. This transparency builds trust with customers, partners, and regulators by demonstrating a commitment to ethical and lawful data practices.
Taken together, these benefits make a data retention policy a practical way to reduce compliance risk and operating costs at the same time, while making it easier to adapt as regulatory and business requirements change.
Recommended reading
Understanding Security Frameworks: 15 Frameworks & The Sector, Data, or Threats They Align With
Data retention policy requirements by framework
A data retention policy can help meet requirements across over a dozen federal and commercial frameworks.
The table below gives a plain-language overview of what each requirement asks for. It is not exhaustive: a single policy contributes, at least partially, to requirements related to information and media protection, general policy and procedure, asset management, and privacy notices. But it is not the only control or evidence that must be in place to meet the requirement.
The table also includes where major regulations and frameworks land on how long data must, or may, be kept when possible. However, most frameworks do not prescribe one universal retention period. Instead, they require organizations to define retention periods based on legal, regulatory, contractual, and business needs, securely dispose of data once those needs end, and document the process. Only a handful set specific timeframes and only for specific types of records.
| Framework | Specified types of data | Specified data retention periods | What it asks for | Requirement(s) |
|---|---|---|---|---|
| CMMC Level 1 | FCI | No | Sanitize or destroy media containing Federal Contract Information (FCI) before disposal or reuse. | MP.L1-b.1.vii |
| NIST SP 800-171 Rev 2 / CMMC Level 2 | CUI | No | Sanitize or destroy media containing CUI before disposal or reuse. Create and keep audit logs long enough to investigate unauthorized activity (you define the time period). Describe how each requirement is implemented, including retention and disposal, in the system security plan (SSP). | MP.L2-3.8., AU.L2-3.3.1, CA.L2-3.12.4 |
| DFARS 252.204-7012 | Images of affected systems and monitoring or packet capture data after a cyber incident | At least 90 days | After reporting a cyber incident, preserve images of affected systems and relevant monitoring and packet capture data for at least 90 days. | Paragraph (e), media preservation and protection |
| NIST SP 800-53 Rev 5 / FedRAMP Rev5 | Federal data | No | Retain, sanitize and dispose of information, media, and system components in line with applicable laws and requirements and your policies and procedures using organization-defined frequencies. | MP-1, MP-6, SI-12, SR-12 |
| SOC 2 | Confidential and personal information in scope | No | Put expectations into policies and procedures. Make data unrecoverable before removing protections from physical assets. Identify and keep confidential information as needed, then dispose of it. Retain and securely dispose of personal information in line with privacy objectives. | CC5.3, CC6.5, C1.1, C1.2, P4.2, P4.3 |
| ISO 27001:2022 | Records and information in scope of the ISMS | No | Protect records from loss, falsification, and unauthorized access or release. Verify that storage media are wiped before equipment is disposed of or reused. Delete information when it is no longer required. | Annex A 5.33, 7.14, 8.10 |
| HIPAA Security Rule | Security policies, procedures, and required documentation such as risk analyses | At least 6 years from creation or the date last in effect, whichever is later | Track hardware and media containing ePHI as it moves in and out of facilities. Define how ePHI and the media it is stored on are finally disposed of. Remove ePHI before media is reused. Keep required security documentation for six years. | 164.310(d)(1), (d)(2)(i), (d)(2)(ii); 164.316(b)(2)(i) |
| PCI DSS v4.0.1 | Stored account data | No | Document and communicate policies for protecting stored account data. Keep account data storage to a minimum with defined retention periods, secure deletion, and a quarterly check for expired data. Destroy hard-copy and electronic media with cardholder data when no longer needed. Do not store any sensitive authentication data after authorization. | 3.1.1, 3.2.1, 3.3.1, 9.4.6, 9.4.7 |
| GDPR | Personal data of individuals in the EU | No | Keep personal data in identifiable form no longer than necessary. Implement, and be able to demonstrate, appropriate measures, including data protection policies. | Articles 5(1)(e), 24(1), 24(2) |
| CCPA/CPRA | Personal information of California consumers | No | Tell consumers, at or before collection, how long you will keep each category of personal information (or how you will decide), and do not keep it longer than reasonably necessary. | §1798.100(a)(3) |
| NYDFS (23 NYCRR 500) | Nonpublic information held by covered entities | No | Address data retention in your approved cybersecurity policy. Periodically and securely dispose of nonpublic information you no longer need, unless you are required to keep it. | 500.3, 500.13(b) |
| FTC Safeguards Rule | Customer information held by non-bank financial institutions | Dispose of it no later than 2 years after it was last used to serve the customer, with limited exceptions | Dispose of customer information within two years of its last use, with limited exceptions, and periodically review your retention policy to minimize unnecessary retention. | 16 CFR 314.4(c)(6) |
| CIS Controls v8.1 | Any sensitive data | No | Document a data management process that includes retention limits and disposal requirements. Enforce both minimum and maximum retention timelines. Securely dispose of data in line with its sensitivity. | 3.1, 3.4, 3.5 |
| NIST CSF 2.0 | Any sensitive data | No | Maintain inventories of data, and manage data throughout its life cycle. | ID.AM-07, ID.AM-08 |
| SOX (SEC Rule 2-06) | Audit workpapers and records relevant to audits of public company financial statements | 7 years after the auditor concludes the audit or review | Financial records must be retained for at least 7 years in tamper-proof formats with executive certification of accuracy. | 17 CFR 210.2-06 |
Mapping one policy to many requirements is what makes a data retention policy efficient: a single, well-written document can support requirements across several frameworks at once.
Recommended reading
Control Mapping: What It Is & How It Can Help Simplify Your Compliance Efforts
What other evidence do you need to prove you’re meeting data retention requirements?
A written policy alone rarely satisfies a requirement. That’s because, even with a policy in place, your systems may still hold data well past its retention period due to misconfiguration or human error.
That’s why you typically need at least three types of controls and evidence in place:
- a published, current data retention policy
- proof that employees have accepted it
- evidence that the retention and disposal rules are actually followed in your systems.
Whether you’re pursuing compliance with a framework that requires audits or certifications, or trying to self-assess your implementation accurately, here are some examples of how you might need to prove you’re properly retaining and disposing of data.
| Evidence | What it shows |
|---|---|
| Published data retention and disposal policy with an owner and review date | The policy exists, is approved, and is maintained |
| Annual policy acknowledgments from in-scope employees and contractors | Personnel know and accept the rules |
| A log of deletion requests that show documented retention and deletion procedures were followed | Deletion is tracked and consistent, not ad hoc |
| System records showing stored data falls within defined retention periods | Storage does not exceed what the policy allows |
| Sanitization or destruction records, such as certificates of destruction or cryptographic erase logs | Disposed data cannot be recovered |
| Database audit logs of data additions, modifications, and deletions, plus log retention settings | Changes to data are traceable and logs are kept as long as required |
| Backup configurations showing frequency, successful backups, and backup retention | Data can be recovered without being kept longer than intended |
Collecting this evidence once is manageable. Keeping it current across every system and framework is where most teams struggle, which is why continuous evidence collection and monitoring matters just as much as the policy itself.
Sample data retention policy: what to include
A data retention policy typically includes a purpose statement, scope, retention periods for each data category, disposal methods, and sections covering responsibility, exceptions, enforcement, and review. To illustrate how these sections fit together, let's break down an example inspired by the Virginia Office of Data Governance and Analytics.
Purpose
A data retention policy typically begins by defining its objective, such as ensuring compliance with state or federal laws.

Scope
Next, the policy should specify who and what assets or data it applies to. It may apply to all assets used by employees, contractors, and third parties on behalf of your organization.

Data retention periods
The policy should outline how long each type of data is stored. For example, financial records may be retained for seven years, while marketing data is kept for three years. If all data should be kept for the same period of time, that should be defined as well.

Data disposal
The policy must include methods for securely deleting data once the retention period expires. This section may be titled data disposal, data destruction, data deletion, or something similar.
Many organizations align their methods with NIST SP 800-88 Rev 2, which groups sanitization into three categories: clear (overwriting user-accessible storage), purge (techniques such as cryptographic erase that resist laboratory recovery), and destroy (physically shredding or incinerating media).

Responsibility, review, and audit
A data retention policy will also typically include several sections covering:
- The responsibility of all employees to comply with the policy
- What will happen if employees do not comply
- How to report policy violations
- How exceptions are approved
- How often the policy will be reviewed and updated

Framework-specific addenda
Organizations subject to several frameworks often keep one base policy and add a short addendum for each framework with unique requirements. This keeps the core policy readable while still capturing detailed obligations.
For example, a HIPAA addendum would:
- List the documents that must be kept for at least six years, such as security policies, training records, business associate agreements, risk analyses, breach documentation, contingency plan tests, and records of hardware and media movements.
- Cover retention of ePHI access logs and forensic data, sanitization methods for media containing PHI, and business associate agreements with vendors that repair drives containing PHI.
PCI DSS addendum, on the other hand, would:
- define which cardholder data elements may be stored after authorization and which never can,
- set rules for masking the primary account number (PAN) when displayed, and
- require a quarterly review to delete stored cardholder data that exceeds retention requirements.
Now that we have a better sense of what a data retention policy covers, let's break down the step-by-step process for creating one.
Data retention policy template
Ready to create your data retention policy? Download our free data retention policy template. This template includes categories of data it can and cannot store, retention periods for each category, guidelines for secure disposal, and a PCI DSS addendum.

Data retention policy template
Creating a data retention policy from scratch can be overwhelming. To simplify the process, we’ve developed a free data retention policy template you can customize to fit your organization’s needs.
How to create a data retention policy
Creating a data retention policy involves identifying your data, determining which requirements apply to it, setting retention periods and disposal methods, and building the controls and review process to enforce them. Follow these steps to make your policy comprehensive and effective:

1. Identify and classify the types of data your organization collects
Begin by cataloging all data your organization collects, stores, and processes. This may include:
- Customer data
- Employee data
- Intellectual property
- Operational data
- Supplier and vendor records
- Protected health information (PHI)
- Educational records
- Email and communications records
- Financial and tax records
- Personal data
- Federal data, such as FCI and CUI
- Security data, such as system and audit logs
Next, classify this data by its sensitivity and purpose to understand its retention needs. This foundational step ensures your policy addresses every type of data and sensitivity level your organization handles. Don't forget copies of data in backups, archives, SaaS tools, and test environments.
Recommended reading
Data Classification: Explaining the What, Why, and How [ + Free Template]
2. Determine legal, regulatory, and contractual requirements
Research the data retention laws, regulations, and frameworks relevant to your industry, location, and the data you process. For example, healthcare organizations in the US must comply with HIPAA, public companies and their auditors are subject to SOX record retention rules, and organizations that collect personal data from people in the European Union (EU) may need to comply with GDPR. Use the requirements by framework above as a starting point.
Don't overlook contracts. Customer agreements, business associate agreements, and government contract clauses like DFARS 252.204-7012 can set retention or disposal obligations of their own. Understanding all of these obligations helps prevent non-compliance and ensures data is retained or deleted as required.
3. Establish retention periods for each data type
Set clear retention timelines for every type of data based on its legal, operational, and historical value. For example, financial records are often kept for seven years to cover common tax and audit lookback periods, while marketing data might only be retained for 12 months. Where more than one requirement applies to the same data, the longest required period generally wins unless another law requires earlier deletion.
Also define how legal holds work. When litigation, an investigation, or an audit is reasonably anticipated, relevant data must be preserved even if its retention period has expired, so your policy should state who can issue and release a hold. Clearly defined retention periods and hold procedures ensure consistency and prevent both over-retention and premature deletion.
4. Define secure disposal methods
Plan how your organization will securely dispose of data once it is no longer needed. Common methods include cross-cut shredding physical documents, cryptographically erasing or wiping drives, physically destroying media, and deleting files from cloud storage. Align these methods with NIST SP 800-88 Rev 2 based on the sensitivity of the data, and keep records such as certificates of destruction as proof.
If you rely on cloud or hosting providers, document how they remove your data from their systems and destroy decommissioned hardware. Secure disposal helps your organization reduce the risk of data breaches and maintain customer trust.
5. Implement access controls and data management processes
Access controls determine how data is accessed, who can access it, and when access is granted. These controls should restrict access to sensitive data and ensure that only a limited number of authorized personnel can modify or delete it.
In addition to implementing access controls, establish processes for tracking and auditing data, including logs of data additions, modifications, and deletions, to maintain visibility over its lifecycle. Proper data management safeguards against accidental deletions or unauthorized access.
6. Develop a policy enforcement plan
Outline how your organization will ensure compliance with the policy. This may include requiring employees to read and accept the policy when they start and at least annually, training employees, implementing automation tools, regularly auditing data retention practices, and disciplining employees who violate the policy.
An enforcement plan ensures that the policy remains effective and aligns with evolving business and regulatory needs.
7. Regularly review and update the policy
Schedule periodic reviews of your data retention policy, at least annually, to account for changes in laws, technology, or business operations. This step helps you stay compliant and ensures your policy remains relevant. Involve key stakeholders, such as legal, IT, and security teams, in the review process to cover all critical areas.
By following these steps, you can create a data retention policy that protects your organization's data while meeting legal and operational requirements.
Recommended reading
A Guide to Regulatory Change Management & How Software Can Simplify It
Data retention policy best practices
Following these best practices can help improve your data retention policy:
- Follow NIST guidelines: Align your policy with trusted framework requirements and controls, like the NIST 800-53 SI-12 control for information management and retention and NIST SP 800-88 for media sanitization, to ensure strong retention and disposal practices.
- Implement a zero data retention approach when possible: With this approach, you delete data once its primary purpose has been fulfilled, without intentionally storing it for future use. While this approach must be balanced with other data requirements, like GDPR's right of access and rectification, it can help ensure an organization only retains data that is absolutely necessary.
- Set maximum retention periods, not just minimums: Many policies say how long data must be kept but not when it must be deleted. Frameworks like CIS Controls and PCI DSS expect both.
- Plan for legal holds: Define who can place and release a hold and how holds override scheduled deletion, so data relevant to litigation or investigations is preserved.
- Incorporate regular audits: Schedule periodic reviews to confirm adherence to the policy and identify gaps in your data management processes before they become compliance issues.
- Document everything: Maintain detailed records of data retention and disposal activities, including deletion requests and certificates of destruction, for accountability and compliance.
- Stay updated on regulations: Regularly monitor changes in data privacy laws like GDPR and CCPA and update your policy accordingly.
- Use automation tools: Use automation to schedule deletions, flag data past its retention period, and reduce the human error associated with manual processes.
- Involve stakeholders: Collaborate with IT, legal, security, and compliance teams during policy creation and review.
- Align backup retention with your schedule: Regular, automated backups protect against data loss, but backups also keep deleted data around. Set backup retention windows that support recovery without keeping data longer than your policy allows.
Data retention policy examples
When creating or optimizing a data retention policy, it helps to look at how established companies have built theirs. Below are some examples.
Because these policies are publicly available, they include limited information.
1. Marketo data retention policy
Marketo's data retention policy sets different retention periods for different activities across its platform. These are:
- A retention period of 14 days for Delete Lead
- A retention period of 90 days for twelve high-volume activities, including Add to List and Change Score
- A retention period of 25 months for other lead activities related to Web, Smart Campaign, Social, Email, CRM, and Segmentation, such as Fill Out Form
Previously, its policy was to retain data for all activities for 90 days. The goal of the updated policy is to improve performance for users across the Marketo platform.

2. X (formerly Twitter) data retention policy
X has a comprehensive privacy policy that includes information about its data retention practices, including retention periods for different types of information. For example, it keeps cookies and information collected using cookies for up to 13 months, and it keeps information about how users view or interact with ads on or off X, and with its content on third-party sites, for up to 90 days.

3. Google data retention policy
Google's data retention policy explains why it holds onto different types of data for different periods of time, including personal information and content like photos and documents. It does not specify exact retention periods for each type of data, but it provides a high-level overview of its processes for safe and complete deletion.

These examples show a useful pattern: the most transparent policies tie each retention period to a specific type of data and explain why that period was chosen.
How Secureframe can help you create and manage a data retention policy more efficiently
Secureframe helps you write a data retention policy, get employees to accept it, and continuously collect the evidence that proves your systems follow it. Instead of rebuilding that proof before every audit or self-assessment, you can monitor it in one place year-round.
- Policy templates: Start with a data retention and disposal policy template reviewed by former auditors, including framework-specific addenda for requirements like HIPAA and PCI DSS, or bring your existing policy into the platform.
- Policy management: Tailor the policy with Secureframe's policy editor and AI-powered text revisions. Assign a policy owner, set review dates, and use version control, so you always have a current, approved policy.
- Policy acceptance tracking: Personnel management automatically imports employees and contractors through your HR, SSO, and MDM integrations. You can then track who has accepted the policy and send reminders before annual acknowledgments lapse.
- Automated evidence collection: 300+ native integrations with your cloud providers, databases, and business tools automatically pull evidence such as database backup configurations and log retention settings. Records that live outside your integrations, such as deletion request logs and certificates of destruction, can be uploaded and stored in one evidence library.
- Continuous control monitoring: Automated tests continuously check that your policy is published and accepted; backups for SQL, MySQL, and PostgreSQL databases stay configured with defined retention; and database logs capture data additions, modifications, and deletions. If a control drifts, Secureframe flags it and gives step-by-step guidance on the evidence needed to pass the test.
- Asset inventory management: Track the devices and systems that store sensitive data so you can see what needs to be sanitized or destroyed when it's retired.
- Cross-framework control mapping: Secureframe maps your data retention and disposal controls to requirements across frameworks, so one policy and one set of evidence count toward many requirements. We support over 50 frameworks including, SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, CCPA, NIST 800-53, FedRAMP, and CMMC.
- Expert guidance: Secureframe's compliance experts, including former auditors, can help you set retention periods and interpret requirements across frameworks like GDPR, HIPAA, ISO 27001, and CMMC as they change.
See how Secureframe Comply automates policy management and evidence collection for your data retention policy. Request a demo to talk with an expert.
If you’re a defense contractor looking for these capabilities and more, learn how Secureframe Defense is purpose- built for CMMC and NIST SP 800-171 Rev 2.
This post was originally published in February 2025 and has been updated for accuracy and comprehensiveness.
FAQs
What is the purpose of a data retention policy?
A data retention policy ensures an organization keeps data only as long as it is legally, contractually, or operationally needed, and then disposes of it securely. This supports regulatory compliance, reduces breach exposure, and lowers storage costs.
What should a data retention policy include?
A data retention policy should include its purpose and scope, the categories of data it covers, retention periods for each category, secure disposal methods, roles and responsibilities, legal hold procedures, exceptions, enforcement, and a review schedule.
How long should data be retained?
It depends on the type of data and the requirements that apply to it. Some rules set specific periods, such as six years for HIPAA security documentation or 90 days for DFARS 7012 incident media, while frameworks like GDPR, CCPA, and PCI DSS require keeping data only as long as necessary.
Is a data retention policy a legal requirement?
Not every organization is legally required to have a formal data retention policy, but many regulations and frameworks, including PCI DSS, HIPAA, GDPR, NYDFS, and the FTC Safeguards Rule, effectively require one by mandating documented retention and disposal practices. SOC 2 and ISO 27001 auditors also commonly expect one.
What is the difference between a data retention policy and a data retention schedule?
A data retention policy sets the overall rules, responsibilities, and disposal methods for an organization's data. A data retention schedule is the detailed list that applies those rules, showing each record type and exactly how long it is kept.
What is a data retention and destruction policy?
A data retention and destruction policy is another name for a data retention policy that explicitly covers both how long data is kept and how it is destroyed. Some organizations call it a data retention and disposal policy.
What is a legal hold, and how does it affect data retention?
A legal hold is an instruction to preserve data that may be relevant to litigation, an investigation, or an audit. It overrides normal deletion schedules, so data under a hold must be kept until the hold is formally released, even if its retention period has ended.
Does CMMC require a data retention policy?
CMMC does not include a practice titled "data retention policy," but it does require related practices, such as sanitizing media before disposal and, at Level 2, retaining audit logs. Combined with the 90-day evidence preservation requirement in DFARS 252.204-7012, most defense contractors document these procedures in a data retention and disposal policy referenced in their SSP.
What is zero data retention?
Zero data retention is an approach where data is deleted as soon as its immediate purpose is fulfilled, rather than stored for future use. The term is also commonly used for AI and SaaS vendors that commit not to store customer prompts or inputs after processing.
Who is responsible for a data retention policy?
A designated policy owner, often in security, compliance, or legal, is typically responsible for maintaining the policy. Data owners apply it to their systems, IT teams carry out disposal, and all employees are responsible for following it.
How often should a data retention policy be reviewed?
A data retention policy should be reviewed at least annually, or whenever there are significant changes in regulations or your organization's operations.
How can a data retention policy help reduce liabilities?
A data retention policy minimizes liabilities by ensuring unnecessary data is not retained, reducing the risk of data breaches and non-compliance fines.
What is the role of automation in data retention policies?
Automation tools help streamline data classification, backup, retention, and deletion processes, reducing human error and improving efficiency.
What are the risks of not having a data retention policy?
Without a policy, organizations face increased risks of non-compliance, data breaches, and inefficiencies in managing large volumes of data.

Anna Fitzgerald
Senior Content Marketing Manager
Anna Fitzgerald is a digital and product marketing professional with nearly a decade of experience delivering high-quality content across highly regulated and technical industries, including healthcare, web development, and cybersecurity compliance. At Secureframe, she specializes in translating complex regulatory frameworks—such as CMMC, FedRAMP, NIST, and SOC 2—into practical resources that help organizations of all sizes and maturity levels meet evolving compliance requirements and improve their overall risk management strategy.

Rob Gutierrez
Senior Cybersecurity and Compliance Manager, CISA, CCSK, CMMC RP
Rob Gutierrez is an information security leader with nearly a decade of experience in GRC, IT audit, cybersecurity, FedRAMP, cloud, and supply chain assessments. As a former auditor and security consultant, Rob performed and managed CMMC, FedRAMP, FISMA, and other security and regulatory audits. At Secureframe, he’s helped hundreds of customers achieve compliance with federal and commercial frameworks, including NIST 800-171, NIST 800-53, FedRAMP, CMMC, SOC 2, and ISO 27001.