There’s no single number, but there is a workable default: keep tax and employment records for the federal periods, keep customer and client data only as long as you have a business reason for it, and delete everything else on a schedule you write down once. Most small businesses land on three years for general records, longer for payroll and property, and much shorter for routine working files and email.

Getting this wrong costs money in both directions. Delete too early and you can’t defend a tax position or a dismissal. Keep everything forever and you’re paying to store and back up records you had no duty to hold, while every one of them stays available to a breach, a subpoena or a discovery request. The second mistake is far more common, and it’s the one that quietly grows.

What Is a Data Retention Policy, in Practical Terms?

It’s a short written document that lists the categories of information your business holds, states how long each category is kept, and names who’s responsible for deleting it. That’s the whole thing. It isn’t a legal treatise, and for most small businesses it fits comfortably on two pages.

The point of writing it down is consistency. If your business deletes records whenever someone happens to think of it, the pattern looks arbitrary, and arbitrary deletion is exactly what raises eyebrows if a dispute arrives. A schedule applied evenly is defensible. Federal small-business guidance says as much, advising firms to develop a written records retention policy to identify what information must be kept rather than leaving it to habit.

How Long Do the Federal Rules Actually Require?

Tax rules give the clearest numbers, and they’re tied to how long a return can still be examined or amended. The general period is three years, stretching to six if income was substantially understated, and with no limit at all where a return was never filed or was fraudulent. Employment tax records run on their own clock.

  • Three years for records supporting income, deductions or credits on a filed return, in the ordinary case.
  • Six years where income that should have been reported was understated by more than a quarter of gross income.
  • Seven years for a claim relating to a bad debt deduction or worthless securities.
  • Indefinitely where no return was filed or a fraudulent one was filed.
  • Property records until the limitation period expires for the year you dispose of the property, because the basis calculation depends on them.

Payroll deserves its own line because it’s the one people guess wrong. The federal guidance is to keep employment tax records for at least 4 years after the date that the tax becomes due or is paid, whichever is later. Note the “at least” and note that other employment rules impose their own longer periods, so four years is a floor rather than a target.

What the tax rules don’t cover

Most of your data. Tax periods say nothing about customer emails, project files, CCTV, call recordings, job applications from people you didn’t hire, or the shared drive folder called Old Stuff. For those, the governing principle is different and simpler: keep sensitive data only while you have a business reason to hold it, then dispose of it properly. If you handle health, financial or client records under an industry rule, that rule sets your floor, and it’s worth confirming whether the Safeguards Rule applies to your business before you assume it doesn’t.

Why Is Keeping Everything a Risk Rather Than a Precaution?

Because every record you hold is a record that can be stolen, demanded or misfiled. Storage is cheap enough that cost alone rarely forces the issue, so the real argument is exposure. Data you deleted on schedule three years ago can’t appear in a breach notification, a discovery request or a regulator’s file today.

The cost side is still real, and it compounds quietly. Every extra terabyte gets stored, replicated, backed up, and often archived to a second location, so one copy of a file you don’t need becomes four or five copies you’re paying to protect. Restores get slower. Searches get slower. Migrations get more expensive, because moving to any new platform means moving years of material nobody has opened.

The exposure side is sharper. If a mailbox holds eight years of correspondence, a single compromised account exposes eight years. If it holds eighteen months because everything older was archived or deleted on schedule, the same compromise is a much smaller incident with a much shorter notification list. Retention is one of the few controls that shrinks the damage of an attack you didn’t prevent.

What Should a Small Business Retention Schedule Contain?

One row per category of information, with a period, a reason and an owner. Build it from the obligations that bind you first, then decide the discretionary categories yourself. Resist the urge to copy a template wholesale, because a template can’t know which rules apply to your business or which records you’d want in a dispute.

Start with what’s already mandated

Tax and payroll first, since the periods are published and non-negotiable. Then anything an industry regulator, licensing body, insurer or major client contract requires. Write the source next to each period. Six months from now, somebody will ask why the number is what it is, and a schedule that cites its reasons survives that conversation.

Then set the discretionary categories

Email, general working files, marketing lists, CCTV, visitor logs and call recordings usually have no fixed legal period, which means you choose. Choose deliberately and shorter than instinct suggests. A useful test is to ask what you’d actually do with a five-year-old file, and whether the answer justifies keeping it available to anyone who compromises an account.

Write down the exception that stops deletion

Every schedule needs a hold rule. The moment litigation, an audit, an insurance claim or an investigation becomes reasonably likely, routine deletion has to stop for anything relevant, and it has to stop deliberately rather than by accident. Deleting on schedule is defensible. Deleting on schedule after you knew a claim was coming is not, and automation makes that mistake easy unless someone can pause it.

How Do You Make Deletion Actually Happen?

By automating it, because manual deletion never survives a busy quarter. Most business email and file platforms can apply retention periods at the folder, mailbox or label level and delete or archive on their own. The work is deciding the periods and mapping them onto the places data actually lives, not the switch-flipping itself.

Two traps catch people here. The first is backups: deleting a file from the live system doesn’t remove it from backup sets, so your effective retention is whatever your backup rotation keeps, not what your policy says. Reconcile the two or the policy is fiction. The second is scattered copies, the exported spreadsheet on a laptop and the shared folder nobody remembers. Automation only reaches the systems you point it at, and this is also where retention meets how far back your security logs reach, since logs are the one category most businesses should keep longer, not shorter.

When we help a business set retention periods, we start from the rules that already bind it rather than from a blank template: tax and payroll periods first, then anything an industry regulator or client contract requires, then customer data, and only then the everyday working files where the business genuinely gets to choose. Doing it in that order usually shortens the list, because it becomes obvious how much is being kept for no reason at all.

Frequently Asked Questions

Can we just keep everything and avoid the whole question?

You can, and that’s the default most businesses drift into, but it’s a choice with a cost. You pay to store and protect it, you widen what a breach exposes, and you keep material available to anyone entitled to demand it. Keeping everything isn’t a neutral option; it’s the highest-exposure option.

Does a retention policy have to be a formal document?

It has to be written, dated and actually followed. It doesn’t have to be long or drafted by a lawyer. A two-page table listing categories, periods, the reason for each period and who’s responsible does the job for most small businesses far better than a twenty-page document nobody reads or applies.

What happens to the data sitting in our backups?

It stays there until the backup rotation ages it out, regardless of what you deleted from the live system. That’s normal and usually acceptable, but your policy should say so explicitly and state the backup retention period alongside the live one, so the two aren’t quietly contradicting each other.

Do we need to delete data when a customer asks us to?

It depends on which state and sector rules cover you, and several now grant deletion rights with defined response windows. Even where a right applies, it’s usually limited by records you’re separately required to keep, such as tax documents. Confirm your position before promising anything in writing.

How long should we keep records for staff who’ve left?

Longer than most people expect, and longer than the tax minimum. Employment tax records carry their own multi-year floor, and separate employment rules add their own periods for hiring records, agreements and claims. Treat departure as the start of a retention clock, not as permission to delete the file.

Where do we start if nothing has ever been deleted?

With the categories, not the files. Trying to sort a decade of accumulated storage document by document is what stalls these projects permanently. List the categories you hold, set a period for each, apply it going forward, then work backwards through the oldest material once the schedule is running.

Turn the Schedule Into Something That Runs by Itself

A retention policy only works when it stops depending on anyone’s memory. The decisions take an afternoon once someone lays out which rules bind your business and which categories you’re free to choose. The lasting part is wiring those periods into the systems that hold the data, so deletion happens on schedule and the hold rule can pause it when it needs to.

If your storage keeps growing and nobody can say what’s safe to delete, that’s the problem worth solving this quarter. Start by matching your controls to the rules you actually fall under, then ask the O&O Systems team where to start on turning those obligations into a schedule your systems enforce without being reminded.