{"id":787,"date":"2024-01-01T13:47:26","date_gmt":"2024-01-01T13:47:26","guid":{"rendered":"https:\/\/solutionsreview.com\/expert\/?p=787"},"modified":"2024-02-02T14:26:47","modified_gmt":"2024-02-02T14:26:47","slug":"attributes-of-an-effective-and-compliant-data-retention-policy-and-schedule","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/thought-leaders\/attributes-of-an-effective-and-compliant-data-retention-policy-and-schedule\/","title":{"rendered":"Attributes of an Effective and Compliant Data Retention Policy and Schedule"},"content":{"rendered":"<p style=\"text-align: justify;\">When creating a data retention policy there is a temptation to simply create a list of legal requirements and call this the policy. Avoid this, as a poorly designed data retention policy creates significantly more work. Time invested creating a compliant and effective policy not only drives better compliances, but also saves energy and effort in program execution.<\/p>\n<p style=\"text-align: justify;\">Creating an effective data retention policy requires more than determining the maximum retention period for personal information in each geography. Rather, an effective data retention policy synchronizes privacy and record retention requirements, justifies the retention of personal information and perhaps most important, socializes and builds a consensus across the business.<\/p>\n<p style=\"text-align: justify;\">A data retention \u201cpolicy\u201d consists of two components: a shorter, overarching policy and a detailed schedule. A policy has three primary purposes: 1) it defines records and non-records covered by the data retention policy, including short-term working documents, and states that records must be kept for the duration of the retention period listed in the records retention schedule; 2) it states that once a record\u2019s and working document\u2019s retention period has expired, that they must be destroyed; and 3) in the event of a legal hold, the policy and retention schedule are suspended for the records under the hold.<\/p>\n<p style=\"text-align: justify;\">The retention schedule is a listing of records created and maintained by the organization. A schedule lists the records that must be kept for legal, regulatory or business purposes, details which documents and data contain personal information, and provides a retention period specifying how long that record must be retained. The schedule may or may not contain citations detailing the specific legal or regulatory requirements for retaining any given record. Note the term \u201crecord\u201d is used to describe specific content that may either have minimum or maximum retention requirements.<\/p>\n<p>Attributes of an effective data retention policy include:<\/p>\n<p style=\"text-align: justify;\">Address Information Across All Media \u2013 A data retention policy and schedule should reflect a media-agnostic approach) that does not focus exclusively on application information stored in databases, but address all media including files, emails and paper documents. Furthermore, the policy and schedule should not, for example, classify email as a record type, but rather recognizes email as a medium that contains both records and non-records.<\/p>\n<p style=\"text-align: justify;\"><em>Compliant with Legal and Regulatory Record Retention Requirements<\/em> \u2013 The policy and schedule should reflect federal, state and industry-specific, as well as country-specific, international record retention mandates. The schedule should include minimum retention periods, retention trigger events and descriptions of the records (paper\/physical and electronic) that the organization maintains in the regular course of business.<\/p>\n<p style=\"text-align: justify;\"><em>Global Policy with Local Exceptions as Necessary<\/em> \u2013 Despite the wide array of privacy and recordkeeping requirements across countries and individual states, it is better to have a single, global schedule with local exceptions where necessary than having multiple geography-specific schedules. It is exceedingly difficult to implement multiple policies, especially as companies often have the same content management system for multiple countries. Note that there are some outliers. For example, China requires retention of some accounting records for 15 years, which substantially exceeds the typical 7-year retention in the US, and the 8-year retention required in several European countries. It may make sense to set the global policy for eight years with a specific local exception for China.<\/p>\n<p style=\"text-align: justify;\"><em>Reflects Business Value of Information<\/em> \u2013 Some information has value to the business. This can include intellectual property, business processes, operational information, etc. Retention should be based on business value. In other words, a company can declare to save information for a period of time because it has business value even if there is no underlying regulatory requirement.<\/p>\n<p style=\"text-align: justify;\"><em>Identify Personal Information and Retention Justification<\/em> \u2013 Data retention polices should detail which records contain personal information and includes a business retention justification for retaining this personal information. This is discussed in greater detail below.<\/p>\n<p style=\"text-align: justify;\"><em>Focus on \u201cBig Bucket\u201d Categories<\/em> \u2013 Within the last decade many organizations have shifted to a \u201cbig bucket\u201d strategy where records are grouped together and there are fewer overall retention periods. A simplified system based on broad retention categories \u2013 sometimes called \u201cbig buckets\u201d \u2013 and a limited number of retention periods (e.g., 1 year, 5 years, 7 years, 10 years and permanent) make it easier for employees to comprehend, as well as making disposition easier to automate.<\/p>\n<p style=\"text-align: justify;\"><em>Clear and Usable<\/em> \u2013 A data retention schedule must be easy to understand. The schedule must identify and be organized to make it easy for any given employee to find records in a language that is familiar to them. It is helpful to provide specific definitions of record and non-record, as well as examples that employees actually use. To improve the results, do not burden employees with descriptions of record types that they are not likely to encounter. The traditional approach is to organize the schedule from the perspective of the records manager. . Keep it simple and straightforward.<\/p>\n<p style=\"text-align: justify;\"><em>Consider the Need for Legal Holds<\/em> \u2013 Companies facing or anticipating litigation or regulatory investigations have a duty to preserve that information. This duty to preserve usurps all privacy or records expiration or disposition. Polices should acknowledge this responsibility.<\/p>\n<p style=\"text-align: justify;\"><em>Socialize and Obtain Consensus with the Business<\/em> \u2013 Finally, continue to socialize the policy, business value and retention requirements with business units and other key stakeholders, seeking to achieve reasonable retention periods.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>When creating a data retention policy there is a temptation to simply create a list of legal requirements and call this the policy. Avoid this, as a poorly designed data retention policy creates significantly more work. Time invested creating a compliant and effective policy not only drives better compliances, but also saves energy and effort [&hellip;]<\/p>\n","protected":false},"author":539,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[11],"tags":[],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Attributes of an Effective and Compliant Data Retention Policy and Schedule<\/title>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Attributes of an Effective and Compliant Data Retention Policy and Schedule\" \/>\n<meta property=\"og:description\" content=\"When creating a data retention policy there is a temptation to simply create a list of legal requirements and call this the policy. Avoid this, as a poorly designed data retention policy creates significantly more work. Time invested creating a compliant and effective policy not only drives better compliances, but also saves energy and effort [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/solutionsreview.com\/thought-leaders\/attributes-of-an-effective-and-compliant-data-retention-policy-and-schedule\/\" \/>\n<meta property=\"og:site_name\" content=\"Solutions Review Thought Leaders\" \/>\n<meta property=\"article:published_time\" content=\"2024-01-01T13:47:26+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-02-02T14:26:47+00:00\" \/>\n<meta name=\"author\" content=\"Mark Diamond\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Mark Diamond\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/attributes-of-an-effective-and-compliant-data-retention-policy-and-schedule\/\",\"url\":\"https:\/\/solutionsreview.com\/thought-leaders\/attributes-of-an-effective-and-compliant-data-retention-policy-and-schedule\/\",\"name\":\"Attributes of an Effective and Compliant Data Retention Policy and Schedule\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/#website\"},\"datePublished\":\"2024-01-01T13:47:26+00:00\",\"dateModified\":\"2024-02-02T14:26:47+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/#\/schema\/person\/edb68d22af13eb192d2f3fc54976f0b4\"},\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/attributes-of-an-effective-and-compliant-data-retention-policy-and-schedule\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/thought-leaders\/attributes-of-an-effective-and-compliant-data-retention-policy-and-schedule\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/attributes-of-an-effective-and-compliant-data-retention-policy-and-schedule\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/thought-leaders\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Attributes of an Effective and Compliant Data Retention Policy and Schedule\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/#website\",\"url\":\"https:\/\/solutionsreview.com\/thought-leaders\/\",\"name\":\"Solutions Review Thought Leaders\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/thought-leaders\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/#\/schema\/person\/edb68d22af13eb192d2f3fc54976f0b4\",\"name\":\"Mark Diamond\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/thought-leaders\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/0263a0ab50709e00f9482d37f0706b3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/0263a0ab50709e00f9482d37f0706b3a?s=96&d=mm&r=g\",\"caption\":\"Mark Diamond\"},\"description\":\"Mark Diamond is CEO of Contoural, the largest independent provider of Records &amp; Information Management and Litigation Readiness Consulting Services. He is also Founder and program administrator of the Association of Corporate Counsel Data Steward program, the industry-leading law firm and legal service provider information security assessment, benchmark and accreditation program.\",\"url\":\"https:\/\/solutionsreview.com\/thought-leaders\/author\/mark-diamond\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Attributes of an Effective and Compliant Data Retention Policy and Schedule","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"Attributes of an Effective and Compliant Data Retention Policy and Schedule","og_description":"When creating a data retention policy there is a temptation to simply create a list of legal requirements and call this the policy. Avoid this, as a poorly designed data retention policy creates significantly more work. Time invested creating a compliant and effective policy not only drives better compliances, but also saves energy and effort [&hellip;]","og_url":"https:\/\/solutionsreview.com\/thought-leaders\/attributes-of-an-effective-and-compliant-data-retention-policy-and-schedule\/","og_site_name":"Solutions Review Thought Leaders","article_published_time":"2024-01-01T13:47:26+00:00","article_modified_time":"2024-02-02T14:26:47+00:00","author":"Mark Diamond","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Mark Diamond","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/thought-leaders\/attributes-of-an-effective-and-compliant-data-retention-policy-and-schedule\/","url":"https:\/\/solutionsreview.com\/thought-leaders\/attributes-of-an-effective-and-compliant-data-retention-policy-and-schedule\/","name":"Attributes of an Effective and Compliant Data Retention Policy and Schedule","isPartOf":{"@id":"https:\/\/solutionsreview.com\/thought-leaders\/#website"},"datePublished":"2024-01-01T13:47:26+00:00","dateModified":"2024-02-02T14:26:47+00:00","author":{"@id":"https:\/\/solutionsreview.com\/thought-leaders\/#\/schema\/person\/edb68d22af13eb192d2f3fc54976f0b4"},"breadcrumb":{"@id":"https:\/\/solutionsreview.com\/thought-leaders\/attributes-of-an-effective-and-compliant-data-retention-policy-and-schedule\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/thought-leaders\/attributes-of-an-effective-and-compliant-data-retention-policy-and-schedule\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/thought-leaders\/attributes-of-an-effective-and-compliant-data-retention-policy-and-schedule\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/thought-leaders\/"},{"@type":"ListItem","position":2,"name":"Attributes of an Effective and Compliant Data Retention Policy and Schedule"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/thought-leaders\/#website","url":"https:\/\/solutionsreview.com\/thought-leaders\/","name":"Solutions Review Thought Leaders","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/thought-leaders\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/thought-leaders\/#\/schema\/person\/edb68d22af13eb192d2f3fc54976f0b4","name":"Mark Diamond","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/thought-leaders\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/0263a0ab50709e00f9482d37f0706b3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/0263a0ab50709e00f9482d37f0706b3a?s=96&d=mm&r=g","caption":"Mark Diamond"},"description":"Mark Diamond is CEO of Contoural, the largest independent provider of Records &amp; Information Management and Litigation Readiness Consulting Services. He is also Founder and program administrator of the Association of Corporate Counsel Data Steward program, the industry-leading law firm and legal service provider information security assessment, benchmark and accreditation program.","url":"https:\/\/solutionsreview.com\/thought-leaders\/author\/mark-diamond\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/posts\/787"}],"collection":[{"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/users\/539"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/comments?post=787"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/posts\/787\/revisions"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/media?parent=787"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/categories?post=787"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/thought-leaders\/wp-json\/wp\/v2\/tags?post=787"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}