data retention documentation

Data Retention Documentation

Data retention documentation is the written record proving what data your business keeps, how long it keeps it, who authorized the schedule, and when records were destroyed. Regulators, opposing counsel, and auditors do not ask what your practice is. They ask you to produce the documentation that shows it.

Last updated: August 2026

Key Takeaways

  • Data retention documentation has three parts: a retention schedule, a written policy that authorizes it, and destruction logs that prove the schedule was followed.
  • Utah Code 13-44-201 requires any business holding personal information to destroy records it does not intend to retain, by shredding, erasing, or otherwise making the information indecipherable.
  • Retention periods come from statute, not preference. Payroll runs three years, OSHA logs five years, HIPAA documentation six years, and employee exposure records thirty years.
  • A schedule stops protecting you the moment litigation is reasonably anticipated. At that point a legal hold overrides every deletion rule in the document.
  • The most common failure is not keeping too little. It is keeping everything forever, which turns old email into discoverable evidence in a lawsuit nobody has filed yet.

Data retention documentation and archived business records in a Utah law office

What Data Retention Documentation Actually Includes

Most businesses that say they have a retention policy have one document. That is not enough. Complete data retention documentation is a set of four artifacts, and an auditor or a judge will look for all four.

The data inventory. A list of what you hold and where it lives: the HR system, the accounting platform, the shared drive, the email archive, the backup tapes, the sales team’s phones. You cannot write a schedule for data you have not located. This is the step most companies skip, and it is why their policy describes a filing cabinet while their real exposure sits in a cloud mailbox.

The retention schedule. A table matching each record category to a retention period and the legal authority behind it. The authority column matters. “Seven years” with no citation is a guess; “seven years, 17 CFR 210.2-06” is a defensible position.

The written policy. The governing document that assigns ownership, defines who may approve an exception, and states how legal holds suspend destruction. It is signed and dated by someone with authority to bind the company.

The destruction log. A record of what was destroyed, when, by whom, and under which schedule line. Without it you cannot prove a missing file was disposed of in the ordinary course rather than deleted because it was inconvenient.

Any person who conducts business in the state and maintains personal information shall implement and maintain reasonable procedures to destroy, or arrange for the destruction of, records containing personal information that are not to be retained by the person.

Utah Code 13-44-201, Protection of Personal Information

Why Data Retention Documentation Matters More Than the Policy Itself

A policy describes intent. Documentation proves behavior. That distinction decides cases.

When a plaintiff asks why a key email no longer exists, the answer “our system deletes mail after 24 months” is worth very little standing alone. The same answer is close to bulletproof when it comes with a dated policy predating the dispute, a schedule line covering that mailbox, and a destruction log showing the same rule applied to thousands of unrelated messages on the same day.

Federal courts address lost electronic information under Rule 37(e) of the Federal Rules of Civil Procedure, which turns on whether the party took reasonable steps to preserve information it should have preserved. Reasonable steps are shown with documents. If the case is heading toward a courtroom, read our overview of how business litigation actually unfolds before you touch a deletion setting.

There is also a criminal edge to this. Under 18 U.S.C. 1519, knowingly destroying or altering a record with intent to obstruct a federal investigation or proceeding carries up to twenty years in prison. Routine, documented, consistently applied destruction is lawful housekeeping. Selective destruction after trouble appears is something else entirely.

Legal Requirements That Drive Your Retention Schedule

Retention periods are not a matter of taste. They come from specific rules, and the rules disagree with each other, which is exactly why the schedule has to be written down rather than remembered.

Record type Minimum retention Authority
Payroll records under the FLSA 3 years from last date of entry 29 CFR 516.5
Personnel and employment records 1 year from the record or personnel action, whichever is later; 1 year from termination if involuntary 29 CFR 1602.14
Form I-9 3 years after hire or 1 year after termination, whichever is later 8 CFR 274a.2
Employment tax records At least 4 years after the 4th quarter filing for the year IRS employment tax recordkeeping
OSHA 300 log, 300A summary, 301 reports 5 years following the covered calendar year 29 CFR 1904.33
Employee exposure records 30 years 29 CFR 1910.1020
Employee medical records Duration of employment plus 30 years 29 CFR 1910.1020
HIPAA policies, procedures, and required documentation 6 years from creation or last effective date 45 CFR 164.316
ERISA benefit plan records Not less than 6 years after the filing date 29 U.S.C. 1027
Audit and review workpapers for public company engagements 7 years 17 CFR 210.2-06
Customer information held by covered financial institutions Secure disposal no later than 2 years after last use, with limited exceptions 16 CFR 314.4(c)(6)

Notice the last row. The Safeguards Rule sets a maximum, not a minimum. That is the direction modern privacy regulation is moving, and it is why “keep everything” is no longer a safe default. Our related guide on records retention policies works through how to reconcile a floor and a ceiling in the same schedule.

Utah Rules Every Business Should Build Into the Schedule

Two Utah statutes do most of the work here, and a third sets the practical outer limit.

Utah Code 13-44-201 applies to any person conducting business in Utah who maintains personal information. It requires reasonable procedures to prevent unlawful use or disclosure, and it requires destruction of records containing personal information that are not to be retained. The statute names the acceptable methods: shredding, erasing, or otherwise modifying the information to make it indecipherable. Dragging a folder to the trash on a shared drive satisfies none of them.

Utah Code 13-44-202 adds the breach side. A business that becomes aware of a breach of system security must investigate in good faith, notify affected Utah residents where misuse has occurred or is reasonably likely, and, when 1,000 or more Utah residents are involved, expand notification further. Every extra year of data you retain is another year of records that a single breach can expose.

The Utah Consumer Privacy Act, Utah Code Title 13 Chapter 61, took effect December 31, 2023. Its applicability test is narrow and deliberately conjunctive: under 13-61-102, a controller or processor is covered only if it does business in Utah or targets Utah residents, has annual revenue of $25,000,000 or more, and either controls or processes the personal data of 100,000 or more consumers in a calendar year, or derives over 50% of gross revenue from selling personal data while processing data of 25,000 or more consumers. Most Utah small businesses fall outside it. They still fall squarely inside 13-44-201, which has no revenue threshold at all. The Utah Division of Consumer Protection maintains a public overview of the UCPA.

The statute of limitations sets your practical floor. Utah allows six years to sue on a written contract under 78B-2-309, and four years on a contract not founded on a writing under 78B-2-307. If you destroy the signed agreement, the change orders, and the payment history in year three, you have disarmed yourself for the remaining three years in which someone can still sue you. Keep contract files at least as long as they can be litigated. Our page on Utah contract law covers what those documents need to contain in the first place.

How to Build a Data Retention Policy That Holds Up

The document itself is short. The work is in the decisions behind it.

Inventory before you draft. Walk each department and ask what they create, where it goes, and who else has a copy. Include the shadow systems: personal cloud drives, texting threads with vendors, the spreadsheet on the office manager’s desktop. Anything you cannot see, you cannot govern.

Group records into categories, not files. Ten to twenty categories is workable. A hundred is a document nobody follows. Financial records, tax filings, employment files, safety records, customer data, contracts, corporate governance records, marketing lists, IT logs, and litigation files will cover most businesses.

Assign each category the longest applicable period, then stop. Where two rules overlap, the longer governs. Where nothing governs, pick a period tied to business need and write down the reasoning. An unexplained retention period is the one that gets attacked.

Name an owner for every category. Not a department. A role. Someone has to be answerable when the schedule is not followed.

Write the legal hold procedure into the same document. It should state who can issue a hold, how it is communicated, how automatic deletion is suspended, and who releases it. Holds fail when the policy assumes the IT administrator will remember which mailboxes to freeze.

Get it approved at the top. A retention schedule adopted by the board or the managing member is a governance act, which is why it belongs alongside your other corporate governance records. One adopted by the office without authority is a suggestion.

Turning the Policy Into Procedures People Follow

A schedule that requires manual effort will be ignored within a quarter. Build the periods into the systems.

Set retention labels in the email and document platform so deletion happens without anyone deciding. Configure the HR system to purge applicant records on the schedule. Put a calendar trigger on the annual destruction run so it happens on a fixed date rather than when someone remembers. Then write down what happened, because the destruction log is the artifact that turns configuration into proof.

Backups deserve their own line. Many companies delete a record from the live system and leave it sitting in a backup for years, which produces the worst outcome available: the data is still discoverable, and the destruction log now says something that is not true. Decide the backup retention window, state it in the policy, and make sure it matches reality.

Vendors deserve a line too. If a payroll processor, a marketing platform, or a cloud provider holds your records, your schedule is only as good as their contract. Check the retention and deletion terms during due diligence rather than after the relationship ends, and confirm what they return or destroy at termination.

Training, Review, and the Annual Audit

Retention rules fail at the desk level. New employees inherit habits, not policies. Cover the schedule during onboarding, refresh it annually, and be specific about the two behaviors that cause the most damage: saving business records to personal accounts, and deleting anything after receiving notice of a claim.

Review the documentation once a year and after any material change: a new state’s customers, a new regulated product line, a new system, an acquisition. Buying a company means inheriting its records and its retention failures, which is one of the quieter risks in regulatory compliance when buying a business.

Then audit against reality. Pull five record categories and check whether the actual retention matches the schedule. If it does not, either fix the systems or amend the document. A schedule contradicted by your own systems is worse than no schedule, because opposing counsel will introduce it as evidence that you knew the rule and ignored it.

Common Data Retention Documentation Mistakes

Mistake What it costs The fix
Keeping everything forever Every old file becomes discoverable, and every stale record becomes breach exposure Adopt defensible maximums, not just minimums
Policy exists but destruction is never logged No way to prove routine disposal, so gaps look like spoliation Log date, category, method, and approver on every run
Deletion continues after a claim arises Sanctions under FRCP 37(e), and potential exposure under 18 U.S.C. 1519 Written legal hold procedure that suspends automated deletion
Deleting from live systems only Data survives in backups, contradicting the destruction record Set and document a backup retention window that matches the schedule
Informal disposal of personal information Falls short of the shred, erase, or render indecipherable standard in Utah Code 13-44-201 Use certified shredding and documented secure wipes
Schedule ignores vendors and cloud platforms Third parties retain data you believe was destroyed Contractual retention and deletion terms, verified at termination

Who Owns This Inside the Business

Retention documentation sits at the intersection of legal, IT, HR, and finance, which is how it ends up owned by nobody. In a small company the practical answer is that one executive owns the policy, IT owns enforcement, and outside counsel reviews the schedule when the legal landscape moves. HR should own the employment categories directly, since they carry the most rules and the shortest tempers; our overview of Utah employment law and of OSHA recordkeeping obligations covers those categories in depth.

If you handle personal data from consumers, the schedule needs to line up with what your published privacy notice promises. A notice that says you delete data on request while your systems retain it indefinitely is a misrepresentation before it is a retention problem. See our discussion of privacy policy compliance and privacy policy regulations in Utah.

Frequently Asked Questions

What is data retention documentation?

It is the written proof of your retention program: a data inventory, a retention schedule tying each record category to a period and a legal authority, an approved policy that governs the schedule, and destruction logs showing the schedule was actually followed.

Is a data retention policy legally required in Utah?

Utah does not mandate a policy document by name, but Utah Code 13-44-201 requires any business holding personal information to maintain reasonable procedures to destroy records it does not intend to retain. In practice, proving reasonable procedures without written documentation is very difficult.

How long should a business keep customer data?

Long enough to satisfy any applicable retention rule and the limitations period on related claims, and no longer. Utah allows six years to sue on a written contract, so contract-related customer records are commonly kept seven years. Marketing data with no legal hook should be purged far sooner.

What is a legal hold and when does it start?

A legal hold suspends routine destruction of relevant records. It begins when litigation, an investigation, or an audit is reasonably anticipated, which is often well before a complaint is filed. A demand letter or a credible internal complaint is usually enough to trigger it.

Can I destroy records after a lawsuit is threatened?

No. Once a claim is reasonably anticipated, destroying relevant records exposes you to sanctions under FRCP 37(e) and, where a federal matter is involved, potential criminal liability under 18 U.S.C. 1519. Suspend the schedule, document the suspension, and confirm automated deletion is off.

Does data retention documentation cover paper as well as electronic files?

Yes. The same schedule should govern both formats, because the legal periods do not care where a record lives. Utah’s destruction standard of shredding, erasing, or rendering information indecipherable is written to cover both.

How often should a retention schedule be reviewed?

Annually at minimum, and immediately after any change that alters your obligations: a new regulated line of business, a new state’s customers, a system migration, or an acquisition. Record the review date on the document itself so the freshness is visible.

What happens if my documentation contradicts my actual practice?

It becomes evidence against you. Opposing counsel will argue you knew the standard and did not follow it. If an audit shows the systems and the schedule disagree, fix one of them promptly and document the correction.

Not sure whether your retention schedule would survive a discovery fight or a regulator’s request? A short review of what you keep, and why, usually resolves it faster than another year of guessing.

Talk with a Utah business lawyer or call (801) 613-1472.

Related Reading

Written by Jeremy Eveland, a business attorney practicing in Utah.

This article is general information, not legal advice. Reading it does not create an attorney-client relationship. Retention obligations vary by industry and by the facts of your business, so confirm your schedule with counsel before relying on it.

Jeremy Eveland
17 North State Street
Lindon UT 84042
(801) 613-1472

Jeremy Eveland
8833 S Redwood Road
West Jordan UT 84088
(801) 613-1472

Jeremy Eveland
17 North State Street
Lindon UT 84042
(801) 613-1472

Jeremy Eveland
8833 S Redwood Road
West Jordan UT 84088
(801) 613-1472

Home