Leadership and readiness
Data retention schedule template by record type
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
A data retention schedule template lists each record type with its system of record, owner, retention period, the event that starts the clock, a disposal method and a licensing relevance rating. Counsel sets the periods. The most useful rule: no record type reaches deletion until its owner confirms whether it should be deleted, de-identified or archived.
Key takeaways
- Organize a retention schedule by record type, not by system, because one system often holds records with different obligations.
- Retention periods come from laws, contracts and notices, so counsel sets them and the template only reserves the column.
- Every row needs a trigger event, such as ticket closed or project closeout, or the period cannot be applied.
- A licensing relevance rating flags company-owned histories to review before disposal and never overrides a deletion duty.
- Client-owned deliverables, privileged files and personnel records get their own rows and default to Exclude.
What a data retention schedule template should include#
A data retention schedule template is a table with one row per record type and columns for who owns it, how long it is kept, when the clock starts and what happens at the end. Adding disposal method and licensing relevance columns turns it from a compliance list into a decision tool for the day a system is retired.
Build rows around record types, not systems. A help desk can hold ticket threads, call recordings and attachments with different obligations, and an ERP holds both tax records and order exceptions.
- Record type: a named family with one purpose, such as closed support tickets or nonconformance reports.
- System of record: where the authoritative copy lives, plus known copies in email, shared drives or backups.
- Owner: the role accountable for the record type, usually a department head rather than IT.
- Retention period: a placeholder that counsel fills from statutes, contracts, privacy notices and insurance needs.
- Clock starts: the event that starts the period, such as ticket closed or contract ended.
- Disposal method: one action from a short fixed list.
- Licensing relevance: whether the company-owned history deserves review before disposal.
- Notes and restrictions: clauses, holds, client ownership or personal data that change the default.
The template: record types and default treatment#
The template below covers record types most US operating companies hold. Each retention period is a placeholder naming the kind of rule counsel should check, because the right period depends on your industry, states, contracts and notices.
Treat the licensing ratings as starting defaults. A ticket archive full of password resets rates lower than one where agents wrote diagnoses and fixes, and a quality system with sparse entries rates lower than one with written root cause analysis.
| Record type | Typical systems | Retention period | Clock starts | Disposal method | Licensing relevance |
|---|---|---|---|---|---|
| Support tickets and resolution notes | Zendesk, Intercom, Freshdesk | Counsel to set: customer contracts, privacy notices | Ticket closed | De-identify and keep, or delete | High |
| CRM activity and deal notes | Salesforce, HubSpot | Counsel to set: privacy notices, contracts | Account closed | De-identify and keep, or delete | Medium |
| Business email and chat | Microsoft 365, Google Workspace, Slack | Counsel to set: litigation exposure, employee notices | Message date | Archive by policy | Medium |
| Issues, code reviews and releases | Jira, GitHub, GitLab, Linear | Counsel to set: customer code terms | Issue closed | Archive read-only | High |
| Jobs, estimates and dispatch records | ServiceTitan, Housecall Pro, Jobber | Counsel to set: warranty terms, state rules | Warranty ended | Archive read-only | High |
| Orders, shipments and exceptions | NetSuite, Epicor, WMS, TMS | Counsel to set: tax and contract rules | Order closed | Archive, de-identify contacts | High |
| Quality and maintenance records | QMS, CMMS, MES | Counsel to set: customer and regulatory requirements | Record closed | Archive read-only | High |
| Invoices, ledgers and tax records | ERP, accounting system | Counsel to set: tax and accounting rules | Fiscal year end | Secure delete | Low |
| Personnel, payroll and candidate files | HRIS, payroll provider, ATS | Counsel to set: employment and privacy law | Separation or decision date | Secure delete | Exclude |
| Client-owned deliverables | Shared drives, Procore, Bluebeam | Counsel to set: client agreements | Project closeout | Return or delete per contract | Exclude |
How to fill in each column without guesswork#
The owner, clock and disposal columns cause the most trouble because each needs a decision rather than a copied default. Fill the schedule with record owners in the room, not from an IT export alone.
Write the basis for every period in the notes, such as a contract clause or a counsel memo reference. When a period changes later, the next reviewer, an auditor or an acquirer can follow the reasoning.
| Column | What to enter | Mistake to avoid |
|---|---|---|
| Record type | A family of records with one purpose and one set of obligations | Listing a system name as if it were one record type |
| System of record | The authoritative system and every known copy, including exports | Forgetting legacy systems kept running for read-only access |
| Owner | A named role, such as head of support or controller | Making IT the owner of business records |
| Clock starts | One event the system records, such as a closed date | Using creation date when obligations run from closure |
| Disposal method | One code from the fixed list | Writing review with no one assigned to decide |
| Licensing relevance | A rating plus a one-line reason | Rating by volume instead of content and rights |
Which disposal methods should the schedule use?#
Disposal methods work best as a short fixed list that IT can carry out without interpretation. Each one maps to a written procedure and produces a log entry showing what was disposed of, when and on whose approval.
De-identify and keep is available only where no law, contract or notice requires deleting the record itself, and counsel decides that per record type. The schedule simply makes the option visible before an automated purge runs.
- Secure delete: remove records and their copies, including exports, through vendor deletion tools and backup rotation.
- De-identify and keep: strip names, contact details, account identifiers and personal free text, then keep the rest for a documented purpose.
- Archive read-only: move records to restricted storage with access logging where nobody can edit them.
- Return or delete per contract: follow the client agreement and file the confirmation.
- Suspend for hold: stop disposal while a legal hold applies, whatever the scheduled date.
How to rate licensing relevance#
Licensing relevance measures whether a record type documents company-owned work an AI developer might license, and whether the company could approve that license. A High rating means only that the owner reviews before disposal; it never outranks a legal duty to delete.
The ratings draw on drivers from the SourceX Enterprise Data Value Framework, chiefly human-generated signal, domain expertise, rights, preparation cost and privacy burden. A record type with strong signal but a heavy privacy burden often lands at Medium, because those costs reduce its net value.
| Rating | What it signals | Typical record types |
|---|---|---|
| High | Human-written work linking a request to a decision and outcome, owned by the company | Resolved tickets, code reviews, job histories, NCRs and CAPAs |
| Medium | Useful context with heavy personal content or weak links to outcomes | CRM notes, email, chat, call transcripts |
| Low | Mostly numeric or templated entries with little reasoning | Invoices, ledgers, system logs |
| Exclude | Personal, privileged or client-owned content | Personnel files, legal files, client deliverables |
Record types that need their own rows#
Record types with special obligations need separate rows so a general default never reaches them. At engineering, architecture and consulting firms, client deliverables often belong to the client under the engagement letter even though they sit on your servers, while staffing plans, internal review comments and proposal drafts are typically the firm's own.
Privileged legal files, records under a litigation hold and payment card data also get their own rows marked Exclude. Recruiting firms should split candidate personal data from job order and placement workflow records. Review the whole schedule on a fixed cadence and whenever a system is added, migrated or retired, since migrations are when old records disappear without a decision.
Illustrative: a consulting firm sorts its engagement archive#
Illustrative: a fictional management consulting firm keeps proposals and pipeline in Salesforce, engagement files in SharePoint, staffing and time in a professional services automation tool, and internal discussion in Teams. An old on-premises file server held many years of engagement folders, and nobody had decided what to keep.
The COO and outside counsel built a schedule by record type. Client deliverables became one row set to return or delete per engagement letter, rated Exclude. Proposals, staffing plans, internal project reviews and methodology playbooks became separate rows set to archive read-only, rated High or Medium. Consultant HR files and recruiting interviews were rated Exclude.
When IT retired the server, it archived internal working records under the schedule instead of wiping everything, and handled client folders engagement by engagement with confirmations logged. When the firm later explored licensing, its inventory already separated what it owned from what its clients owned.
How SourceX uses a retention schedule#
SourceX treats a retention schedule as an input to Supply, the first step of the SourceX five-step transaction, because it shows which record types still exist, where they live and what restricts them. The schedule can be described as metadata during the fit check, and no files are needed at that stage.
If a company proceeds, the basis notes and disposal logs support the Rights and Preparation steps and the provenance and privacy record in the SourceX Evidence Packet. SourceX never asks a company to keep records beyond what its legal duties and its own policy allow, and the company approves every release.
Frequently asked questions
How many record types should a retention schedule have?
Enough that each row has one purpose and one set of obligations. A single-line business may need a short list, while a company with several business lines needs more. If a row needs two periods or two owners, split it. If two rows always share an owner, period and disposal method, merge them.
Should the schedule show different periods for each state we operate in?
Counsel often sets one period per record type that satisfies the strictest rule that applies, then notes exceptions. Periods can differ by state, industry and contract, so a template copied from another company may be wrong for yours. Recording the basis for each period keeps later changes traceable.
Who should own the retention schedule?
One coordinator, often the general counsel, COO or a compliance lead, owns the document, and each record type has a business owner who answers for it. IT carries out disposal and keeps the logs but should not set business retention on its own.
Does a licensing relevance column create pressure to keep everything?
It should not. Legal and contractual deletion duties always come first, and the column only flags record types to review before disposal. Keeping records without a purpose can raise legal and security exposure, so a High rating needs a documented reason to keep, not a habit of keeping.
Can we change the disposal method for records already scheduled for deletion?
Often the method can change going forward, for example from delete to de-identify and keep, if no law, contract or notice requires deleting those records. Check each system's automated deletion settings first, since some tools purge on a timer regardless of what the schedule says.
Related resources
- QuestionShould companies sell or license their data?
- QuestionDo I need customer consent to license support tickets?
- InsightDo former employees have to consent before a closed company licenses their messages?
- InsightCan HVAC and plumbing companies license technician helmet-camera footage?
- InsightDo you need client consent to license de-identified RFIs and submittals?
- SolutionData partnerships between businesses and AI developers
See if your company qualifies
A short company assessment. No data uploads are needed.