Retention Rule
A retention rule is a specific instruction that tells an organization how long to keep a particular type of information before it is archived or deleted. It typically defines the category of data covered, the time period it must be kept, and what happens at the end of that period. Retention rules are usually grouped together within a broader data retention policy.
A retention rule is an individual, enforceable directive within a data retention policy that specifies the applicable data or record category, the retention period (which may be expressed as a minimum, a maximum, or both), the triggering event that starts the retention clock (such as creation date), and the disposition action taken on expiry (for example, archival or deletion). In practice, retention rules are operationalized through governance tooling; for instance, platform retention policies and labels can be configured to retain items for a defined period after creation and then delete them. Minimum and maximum retention windows are commonly derived from legal, regulatory, or business requirements and govern the timeframe over which records must remain available. This entry defines the concept of a retention rule only; it does not enumerate jurisdiction-specific statutory retention periods, and the applicable duration for any given data type depends on the governing legal, regulatory, and contractual context. Note that retention rules interact with, but are distinct from, legal hold obligations, cross-border transfer requirements, and lawful-basis analysis, none of which are covered here.
Why it matters
Retention rules translate abstract policy intent into concrete, enforceable behavior over the lifecycle of information. Without defined rules that specify how long each category of data is kept and what happens when that period ends, organizations tend to accumulate data indefinitely or delete it inconsistently. Both extremes carry risk: keeping records beyond their useful or lawful life expands the volume of data exposed in a breach and can conflict with data minimization expectations under regimes such as the EU GDPR and UK GDPR, while premature or ad hoc deletion can undermine the availability of records that legal, regulatory, or contractual obligations require to be retained. Access Corp frames this dual pressure directly: minimum and maximum retention requirements establish the timeframe that governs how records are maintained, with the purpose of ensuring records remain available for as long as they are needed.
Retention rules are also central to demonstrable accountability under governance frameworks. Stating that an organization deletes data "when it is no longer needed" is not sufficient; accountability generally requires evidence that specific rules exist, are applied to defined data categories, and are actually executed. Governance tooling makes this operational, for example, a platform retention policy can be configured to retain items for a defined period after creation and then delete them, producing a repeatable and auditable disposition process rather than relying on manual judgment.
This entry describes the concept of a retention rule and does not enumerate jurisdiction-specific statutory retention periods. The correct duration for any given data type depends on the governing legal, regulatory, and contractual context, which is out of scope here. Retention rules also interact with, but are distinct from, legal hold obligations, cross-border transfer requirements, and lawful-basis analysis, none of which are addressed in this definition.
Who it's relevant to
Inside Retention Rule
Common questions
Answers to the questions practitioners most commonly ask about Retention Rule.