Data retention should reflect business purpose, operational needs, contracts, backups, and applicable requirements. Keeping everything forever increases storage, access, cleanup, and incident risk.
This is an implementation checklist, not legal advice. Have qualified professionals review requirements for the business and records.
Inventory record types
List customer, lead, employee, financial, payment, document, support, analytics, integration, audit, and backup records. Record system, owner, source, purpose, sensitivity, and users.
Define lifecycle states
Document active, archived, expired, deleted, anonymized, quarantined, and legal-hold states. Explain what staff can see and what happens when a record is no longer needed for the original purpose.
Control access and exports
Use role-based access, limit exports, protect files, record sensitive actions, and remove users who change roles. Retention rules should apply to shared folders and spreadsheets, not only the main database.
Plan deletion and recovery
Define automated or manual deletion, dependency handling, audit evidence, backup expiration, restore behavior, and who approves exceptions. A deleted record should not quietly remain in an unmanaged export.
The privacy checklist and permissions checklist cover related controls.
Review vendors and integrations
Record what third parties receive, how long they retain it, how deletion is requested, and how access ends when a service is removed. Add retention review to system-change planning.
Data living indefinitely across tools and exports? Ask Vertinus to map the record lifecycle and ownership.