Document Retention Schedule: How Long to Keep Records

Privacy & Compliance

Document Retention Schedule: How Long to Keep Records

Advertisement

A document retention schedule is a written policy that states how long each type of business record must be kept before it can be defensibly destroyed. Most contracts and financial records fall somewhere between three and seven years, but the real number comes from a statute, a contract clause, or your auditor, not a guess. Get it wrong in either direction and you either violate a retention requirement or leave a stale liability sitting in a folder years after it stopped being useful.

What is a document retention schedule?

A retention schedule is a table that maps record types to a required holding period and a trigger date, plus the destruction method once that period ends. It is not the same thing as a backup policy or a filing system. A backup keeps everything; a retention schedule tells you which records you are legally required to keep, which ones you are legally required to eventually destroy, and which ones are genuinely optional.

Most small businesses never write one down. Records pile up in email, shared drives, and paper boxes with no trigger date attached, so nobody can say with confidence when a given contract or invoice is safe to delete. That gap is what a written schedule closes.

How long should you keep contracts, invoices, and HR records?

The table below gives typical ranges used across US small-business practice. Treat every number as a starting point — check the statute of limitations in your state or country and any contract clause that sets its own term before finalizing your own schedule.

Record typeTypical retention windowWhy that longClock starts at
Signed contracts and vendor agreementsContract term plus 3-6 yearsCovers the statute of limitations for a breach-of-contract claimExpiration or termination
Invoices and accounts payable records3-7 yearsSupports tax filings and financial auditsEnd of the fiscal year
Employee personnel filesEmployment duration plus 3-7 yearsWage and discrimination claim windows outlast the employment itselfTermination date
Signed NDAsThe confidentiality term stated in the NDA, often 2-5 years or indefinite for trade secretsThe obligation in the document sets the clock, not a generic defaultDate of disclosure or contract end
Insurance claims files5-10 yearsClaims can be reopened or appealed long after resolutionDate of claim resolution

What does defensible deletion actually mean?

Defensible deletion is destroying a record on a documented schedule, for a documented reason, in a way you can prove after the fact if a court or regulator ever asks why the file no longer exists. It is the opposite of two common failure modes: keeping everything forever out of fear, and deleting things ad hoc when a drive fills up. Neither one holds up under scrutiny — the first because it turns every old record into discoverable evidence in a future dispute, the second because it looks like spoliation even when it was not.

NIST Special Publication 800-88 defines media sanitization in three tiers — clear, purge, and destroy — precisely because deleting a file's directory entry does not overwrite the underlying data. A record is not gone just because it left the file browser; the retention schedule has to specify which sanitization tier applies to which record type.

What happens when a vendor still holds your file after you delete it?

Deleting your local copy does not delete a vendor's copy. Cloud storage providers, document-review tools, and backup services routinely retain deleted files in backups or logs for a defined period after you remove them from view, and that period is set by the vendor's own retention policy, not yours. Before you rely on a delete button anywhere in your document workflow, check the vendor's data retention and deletion terms for how long backups persist and whether deletion requests propagate to those backups automatically or only on request.

This is also why a retention schedule needs to name every system that holds a copy of a record, not just the primary one. A file deleted from your contract folder but still sitting in an email attachment, a shared drive, and a vendor's backup has not actually left your custody for retention purposes.

How do you build an audit trail for document destruction?

An audit trail is what turns a claim that a file was deleted into a defensible fact. Build one with these steps:

  1. Assign every record type a named retention rule tied to a source — a statute, a contract clause, or a written internal policy — never kept “just in case.”
  2. Log the destruction event itself: which file, which rule triggered it, who approved it, and the exact timestamp.
  3. Store the destruction log separately from the destroyed record, so the audit trail survives the file's own deletion.
  4. Build a legal-hold process that overrides the schedule the moment litigation, a subpoena, or a regulator inquiry becomes reasonably foreseeable.
  5. Review the whole schedule at least once a year — retention laws and contract templates change without announcement.

A compliance program built for a growing startup should treat this log as a required artifact, not an optional nicety, because a regulator's first question after a breach is usually why a given record no longer exists.

When does a spreadsheet stop being enough to track retention?

A spreadsheet works fine for a few dozen contracts reviewed by one person who remembers the rules. It stops working once volume climbs, more than one person touches the schedule, or the contracts themselves contain the actual retention-relevant dates and clauses buried in paragraphs of text nobody has time to re-read. At that point the bottleneck is not the policy — it is finding the dates and clauses inside each document fast enough to apply the policy consistently.

This is where bulk document extraction earns its keep. HiDocument's bulk mode reads a batch of uploaded contracts or invoices at once and surfaces the dates and clause language that determine when each file's retention clock started, so a records reviewer is confirming a flagged date instead of re-reading every page from scratch. Compare plans to see the bulk upload limits and file-size caps before you commit a full folder to a test run.

Do retention rules change under GDPR, CCPA, or PIPEDA?

Yes, and the change is conceptual, not just a different number of years. The UK GDPR's storage limitation principle, Article 5(1)(e), requires that personal data be kept no longer than is necessary for the purpose it was originally collected — there is no single fixed retention period written into the law itself, which means your own documented purpose becomes the evidence for how long you were entitled to keep the data. The FTC's Disposal Rule, 16 CFR Part 682, takes a similar functional approach for US businesses that use consumer report information: it requires reasonable measures to dispose of that information, not a specific number of days.

Practically, this means a retention schedule covering personal data needs a stated purpose next to every retention period, not just a duration. If you already maintain a GDPR compliance checklist for legal documents, the retention schedule is the piece that turns a general storage-limitation policy into a specific, auditable number per record type. The same discipline pays off before you scan documents for PII ahead of a scheduled deletion pass — you need to know what personal data a file contains before you can prove you were entitled to delete it, and before that, that you were entitled to have kept it as long as you did.

What should you do next?

The most common reason teams never write a retention schedule is that it feels like it should already exist somewhere, or that building one properly requires a records-management consultant. Neither is true for a small business: a one-page table per major record type, reviewed once a year, covers most of the legal exposure. The effort is in finding the actual dates and clauses buried in your existing contracts and invoices, not in writing the policy itself.

Create a free HiDocument account and upload a batch of the contracts or invoices you are unsure whether to keep. Free tier gives you 10 analyses a month with a 5 MB file cap — enough to test bulk extraction on your oldest folder before you decide whether the Pro plan's higher caps are worth it for a full records cleanup.

Frequently Asked Questions

How long should a small business keep invoices?

Most small businesses keep invoices and accounts payable records for three to seven years, tied to the fiscal year they were issued in, because tax audits and financial statement reviews can reach back that far. Check your specific country's tax authority guidance for the exact window that applies to you.

What is defensible deletion?

Defensible deletion is destroying a record on a documented schedule, for a documented reason, in a way you can prove after the fact. It requires a named rule per record type, a logged destruction event, and a legal-hold process that can pause the schedule when litigation becomes foreseeable.

Does deleting a file also delete it from my cloud backup?

Not automatically. Cloud storage and document tools typically retain deleted files in backups for a period set by the vendor's own policy, separate from your local deletion. Check each vendor's data retention terms to confirm how long backups persist and whether your deletion request propagates to them.

What is a legal hold and when does it override a retention schedule?

A legal hold is an instruction to stop destroying specific records because litigation, a subpoena, or a regulator inquiry has become reasonably foreseeable. It overrides the normal retention schedule for the affected records until the hold is formally lifted, regardless of what the schedule would otherwise require.

Do GDPR and CCPA set a specific number of years for retention?

No. GDPR's storage limitation principle requires keeping personal data no longer than necessary for its stated purpose rather than a fixed period, and CCPA works similarly. This means your documented purpose for holding the data is what determines the defensible retention period, not a number written into the statute.

Can an intern or a paralegal just track retention in a spreadsheet?

Yes, at low volume with one person maintaining it. It becomes unreliable once more than one person edits the schedule or the volume of contracts and invoices grows past what one reviewer can re-read for dates and clauses, which is when bulk document extraction starts saving real review time.

Ready to analyze your own documents?

Upload any PDF, Word doc, or image — get 10 types of AI analysis instantly. Free to start, no credit card required.

Try HiDocument Free →

Related Articles