Skip to content

Leadership and readiness

Data retention schedule template by record type

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A data retention schedule template lists each record type with its system of record, owner, retention period, the event that starts the clock, a disposal method and a licensing relevance rating. Counsel sets the periods. The most useful rule: no record type reaches deletion until its owner confirms whether it should be deleted, de-identified or archived.

Key takeaways

  • Organize a retention schedule by record type, not by system, because one system often holds records with different obligations.
  • Retention periods come from laws, contracts and notices, so counsel sets them and the template only reserves the column.
  • Every row needs a trigger event, such as ticket closed or project closeout, or the period cannot be applied.
  • A licensing relevance rating flags company-owned histories to review before disposal and never overrides a deletion duty.
  • Client-owned deliverables, privileged files and personnel records get their own rows and default to Exclude.

What a data retention schedule template should include#

A data retention schedule template is a table with one row per record type and columns for who owns it, how long it is kept, when the clock starts and what happens at the end. Adding disposal method and licensing relevance columns turns it from a compliance list into a decision tool for the day a system is retired.

Build rows around record types, not systems. A help desk can hold ticket threads, call recordings and attachments with different obligations, and an ERP holds both tax records and order exceptions.

  • Record type: a named family with one purpose, such as closed support tickets or nonconformance reports.
  • System of record: where the authoritative copy lives, plus known copies in email, shared drives or backups.
  • Owner: the role accountable for the record type, usually a department head rather than IT.
  • Retention period: a placeholder that counsel fills from statutes, contracts, privacy notices and insurance needs.
  • Clock starts: the event that starts the period, such as ticket closed or contract ended.
  • Disposal method: one action from a short fixed list.
  • Licensing relevance: whether the company-owned history deserves review before disposal.
  • Notes and restrictions: clauses, holds, client ownership or personal data that change the default.

The template: record types and default treatment#

The template below covers record types most US operating companies hold. Each retention period is a placeholder naming the kind of rule counsel should check, because the right period depends on your industry, states, contracts and notices.

Treat the licensing ratings as starting defaults. A ticket archive full of password resets rates lower than one where agents wrote diagnoses and fixes, and a quality system with sparse entries rates lower than one with written root cause analysis.

The template: record types and default treatment
Record typeTypical systemsRetention periodClock startsDisposal methodLicensing relevance
Support tickets and resolution notesZendesk, Intercom, FreshdeskCounsel to set: customer contracts, privacy noticesTicket closedDe-identify and keep, or deleteHigh
CRM activity and deal notesSalesforce, HubSpotCounsel to set: privacy notices, contractsAccount closedDe-identify and keep, or deleteMedium
Business email and chatMicrosoft 365, Google Workspace, SlackCounsel to set: litigation exposure, employee noticesMessage dateArchive by policyMedium
Issues, code reviews and releasesJira, GitHub, GitLab, LinearCounsel to set: customer code termsIssue closedArchive read-onlyHigh
Jobs, estimates and dispatch recordsServiceTitan, Housecall Pro, JobberCounsel to set: warranty terms, state rulesWarranty endedArchive read-onlyHigh
Orders, shipments and exceptionsNetSuite, Epicor, WMS, TMSCounsel to set: tax and contract rulesOrder closedArchive, de-identify contactsHigh
Quality and maintenance recordsQMS, CMMS, MESCounsel to set: customer and regulatory requirementsRecord closedArchive read-onlyHigh
Invoices, ledgers and tax recordsERP, accounting systemCounsel to set: tax and accounting rulesFiscal year endSecure deleteLow
Personnel, payroll and candidate filesHRIS, payroll provider, ATSCounsel to set: employment and privacy lawSeparation or decision dateSecure deleteExclude
Client-owned deliverablesShared drives, Procore, BluebeamCounsel to set: client agreementsProject closeoutReturn or delete per contractExclude

How to fill in each column without guesswork#

The owner, clock and disposal columns cause the most trouble because each needs a decision rather than a copied default. Fill the schedule with record owners in the room, not from an IT export alone.

Write the basis for every period in the notes, such as a contract clause or a counsel memo reference. When a period changes later, the next reviewer, an auditor or an acquirer can follow the reasoning.

How to fill in each column without guesswork
ColumnWhat to enterMistake to avoid
Record typeA family of records with one purpose and one set of obligationsListing a system name as if it were one record type
System of recordThe authoritative system and every known copy, including exportsForgetting legacy systems kept running for read-only access
OwnerA named role, such as head of support or controllerMaking IT the owner of business records
Clock startsOne event the system records, such as a closed dateUsing creation date when obligations run from closure
Disposal methodOne code from the fixed listWriting review with no one assigned to decide
Licensing relevanceA rating plus a one-line reasonRating by volume instead of content and rights

Which disposal methods should the schedule use?#

Disposal methods work best as a short fixed list that IT can carry out without interpretation. Each one maps to a written procedure and produces a log entry showing what was disposed of, when and on whose approval.

De-identify and keep is available only where no law, contract or notice requires deleting the record itself, and counsel decides that per record type. The schedule simply makes the option visible before an automated purge runs.

  • Secure delete: remove records and their copies, including exports, through vendor deletion tools and backup rotation.
  • De-identify and keep: strip names, contact details, account identifiers and personal free text, then keep the rest for a documented purpose.
  • Archive read-only: move records to restricted storage with access logging where nobody can edit them.
  • Return or delete per contract: follow the client agreement and file the confirmation.
  • Suspend for hold: stop disposal while a legal hold applies, whatever the scheduled date.

How to rate licensing relevance#

Licensing relevance measures whether a record type documents company-owned work an AI developer might license, and whether the company could approve that license. A High rating means only that the owner reviews before disposal; it never outranks a legal duty to delete.

The ratings draw on drivers from the SourceX Enterprise Data Value Framework, chiefly human-generated signal, domain expertise, rights, preparation cost and privacy burden. A record type with strong signal but a heavy privacy burden often lands at Medium, because those costs reduce its net value.

How to rate licensing relevance
RatingWhat it signalsTypical record types
HighHuman-written work linking a request to a decision and outcome, owned by the companyResolved tickets, code reviews, job histories, NCRs and CAPAs
MediumUseful context with heavy personal content or weak links to outcomesCRM notes, email, chat, call transcripts
LowMostly numeric or templated entries with little reasoningInvoices, ledgers, system logs
ExcludePersonal, privileged or client-owned contentPersonnel files, legal files, client deliverables

Record types that need their own rows#

Record types with special obligations need separate rows so a general default never reaches them. At engineering, architecture and consulting firms, client deliverables often belong to the client under the engagement letter even though they sit on your servers, while staffing plans, internal review comments and proposal drafts are typically the firm's own.

Privileged legal files, records under a litigation hold and payment card data also get their own rows marked Exclude. Recruiting firms should split candidate personal data from job order and placement workflow records. Review the whole schedule on a fixed cadence and whenever a system is added, migrated or retired, since migrations are when old records disappear without a decision.

Illustrative: a consulting firm sorts its engagement archive#

Illustrative: a fictional management consulting firm keeps proposals and pipeline in Salesforce, engagement files in SharePoint, staffing and time in a professional services automation tool, and internal discussion in Teams. An old on-premises file server held many years of engagement folders, and nobody had decided what to keep.

The COO and outside counsel built a schedule by record type. Client deliverables became one row set to return or delete per engagement letter, rated Exclude. Proposals, staffing plans, internal project reviews and methodology playbooks became separate rows set to archive read-only, rated High or Medium. Consultant HR files and recruiting interviews were rated Exclude.

When IT retired the server, it archived internal working records under the schedule instead of wiping everything, and handled client folders engagement by engagement with confirmations logged. When the firm later explored licensing, its inventory already separated what it owned from what its clients owned.

How SourceX uses a retention schedule#

SourceX treats a retention schedule as an input to Supply, the first step of the SourceX five-step transaction, because it shows which record types still exist, where they live and what restricts them. The schedule can be described as metadata during the fit check, and no files are needed at that stage.

If a company proceeds, the basis notes and disposal logs support the Rights and Preparation steps and the provenance and privacy record in the SourceX Evidence Packet. SourceX never asks a company to keep records beyond what its legal duties and its own policy allow, and the company approves every release.

Frequently asked questions

How many record types should a retention schedule have?

Enough that each row has one purpose and one set of obligations. A single-line business may need a short list, while a company with several business lines needs more. If a row needs two periods or two owners, split it. If two rows always share an owner, period and disposal method, merge them.

Should the schedule show different periods for each state we operate in?

Counsel often sets one period per record type that satisfies the strictest rule that applies, then notes exceptions. Periods can differ by state, industry and contract, so a template copied from another company may be wrong for yours. Recording the basis for each period keeps later changes traceable.

Who should own the retention schedule?

One coordinator, often the general counsel, COO or a compliance lead, owns the document, and each record type has a business owner who answers for it. IT carries out disposal and keeps the logs but should not set business retention on its own.

Does a licensing relevance column create pressure to keep everything?

It should not. Legal and contractual deletion duties always come first, and the column only flags record types to review before disposal. Keeping records without a purpose can raise legal and security exposure, so a High rating needs a documented reason to keep, not a habit of keeping.

Can we change the disposal method for records already scheduled for deletion?

Often the method can change going forward, for example from delete to de-identify and keep, if no law, contract or notice requires deleting those records. Check each system's automated deletion settings first, since some tools purge on a timer regardless of what the schedule says.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify