How to Build a Strong and Effective Data Retention Policy

An enterprise data management strategy isn’t complete unless it includes an effective data retention policy.
A data retention policy (DRP) is simple, yet often disarmingly so. In essence, a DRP is a system of rules for holding, storing, and deleting the information an organization generates and handles. What is far from simple is building a data retention policy that’s comprehensive, manageable, and compatible with current and evolving legal, industry, and government demands.
DRP policies not only reduce an organization’s risk of running afoul of mandated requirements, but they can also add enormous value. Data governance reduces the costs associated with compliance and investigation, as well as potential downstream litigation, explains Andy Gandhi, a managing director at corporate investigation and risk consulting firm Kroll. “It also reduces internal costs associated with hardware for storing unnecessary data on servers … as well as staff to manage the data and servers,” added Gandhi, who’s also the global leader of Kroll’s data insights and forensics practice.
A DRP is also fundamental for knowledge development, says Pedro Ferreira, an associate professor of information systems at Carnegie Mellon University’s Heinz College of Information Systems and Public Policy. “A good DRP will store all data collected in ways that can be used in the future,” he notes.
When legal, regulatory, or security issues arise, it’s too late to begin thinking about getting the organization’s data in order, warns Scott Read, risk and financial advisory information governance leader at IT and business consulting firm Deloitte. “The digital landfill that most organizations are sitting on, be it in on-prem data centers or scattered across the cloud, is a ticking time bomb of cost and risk.”
Read recommends that to limit an enterprise’s exposure to adverse events, data should be actively managed and remediated in conjunction with a defensible, business-as-usual process that’s driven by a data retention policy. Additionally, to operate smoothly and orderly, organizations need to learn how to efficiently create, use, and dispose of obsolete records. “A data retention policy and retention schedule are key tools to establish efficient business-as-usual processes,” he says.
The first step toward creating a comprehensive DRP strategy is to identify the specific business needs the retention policy must address. The next step should be reviewing the compliance regulations that are applicable to the entire organization. “Designate a team of individuals across various business practices to begin data inventorying and devising a plan to implement and maintain a data retention policy that meets your business requirements while adhering to compliance regulations,” Gandhi advises.

