Skip to content

Consulting and recruiting

Return or destroy clauses after a consulting engagement ends

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A return or destroy clause requires a consulting firm to give back or delete client confidential information when an engagement ends or the client asks. Read four parts first: the trigger, the scope, the exceptions for legal and backup copies, and the certification duty. Copies kept under an exception stay confidential and serve only the purpose the exception allows.

Key takeaways

  • The trigger, scope, exceptions and certification duty define what a return or destroy clause actually requires.
  • Scope often reaches notes, analyses and extracts that contain client information, not only files the client sent.
  • Backup and legal-retention exceptions let some copies stay, but confidentiality continues and use is limited.
  • A legal hold overrides scheduled destruction until counsel releases it.
  • Copies kept under an exception are not available for reuse, licensing or AI training.

What does a return or destroy clause require?#

A return or destroy clause requires the consultant to return the client's confidential information, or destroy it and confirm in writing, at the end of the engagement or on the client's request. It usually sits in the confidentiality section of the master services agreement, the engagement letter or a separate NDA, and it survives termination along with the confidentiality duty itself.

Many firms treat the clause as an administrative afterthought. In practice it reaches every place client information landed during the project, including tools the engagement team adopted midstream, and the certificate the firm signs is a representation the client can rely on later.

Anatomy of the clause, part by part#

A return or destroy clause has a handful of standard parts, and small wording differences change the work required. Read each part against how your team actually stored and used client material, not against how the engagement was planned.

Anatomy of the clause, part by part
Clause partCommon wording patternWhat to check
TriggerOn termination, expiration or the disclosing party's written requestWhether a request can arrive mid-engagement, and who may make it
ScopeConfidential information and all copies, extracts, notes and analyses containing itWhether derived work product and summaries are included
ElectionReturn or destroy at the client's option, or at the consultant's optionWho chooses and how the choice is communicated
TimingWithin a stated period after the triggerWhether the period is realistic for backups and subcontractors
Retention exceptionsCopies required by law, regulation or professional standards; one archival copy; automatic backupsExactly which copies may stay, and for what purpose
Continuing confidentialityRetained copies remain confidential for as long as they are heldAccess limits and how long the duty lasts
CertificationAn officer certifies return or destruction in writing on requestWho signs and what the certificate must list
Flow-downApplies to affiliates, subcontractors and representativesWhether subcontractors signed matching terms

Which exceptions let a firm keep copies?#

Retention exceptions let a firm keep specific copies when law, professional standards or technical limits make destruction impractical. The most common are copies the firm must keep to meet legal or regulatory duties, a single archival copy kept to document the work and defend claims, and copies in automatic backup systems that are overwritten on a normal cycle.

Each exception is narrow. An archival copy is usually limited to compliance or defense purposes and stored with restricted access. A backup exception generally assumes the firm will not restore or use those copies and that they age out on schedule. A legal or regulatory exception covers what the rule requires, not the whole engagement folder.

If the clause has no exception and the firm cannot practically purge a backup, raise it with the client and document the agreed approach rather than signing a certificate that is not accurate.

Where client data hides after an engagement#

Client data hides in far more places than the engagement folder. A closeout that only deletes the SharePoint or Google Drive site usually leaves copies behind in tools nobody listed at kickoff.

  • Team chat channels and direct messages in Slack or Microsoft Teams, including shared files.
  • Email threads and attachments in each team member's mailbox.
  • Laptops, downloads folders and synced desktop copies.
  • Analytics workspaces: notebooks, Power BI or Tableau files and scratch databases.
  • AI tools: meeting note-taker transcripts, chat assistant histories and any document indexes built for the project.
  • Video meeting recordings: Zoom, for example, lets admins set cloud recordings to delete automatically after a set number of days, but only if someone turned the setting on.
  • PSA and CRM attachments, such as status reports uploaded to project records.
  • Subcontractor and expert network drives, and files downloaded from client data rooms.

Post-engagement compliance checklist and certificate#

A post-engagement checklist turns the clause into tasks with owners. Run it for every engagement, not only when a client asks, so the record exists before anyone needs it.

  • Confirm whether a legal hold, dispute or regulatory inquiry applies before deleting anything.
  • Record the client's election to return or destroy, in writing.
  • Inventory every location in the previous list, with the engagement manager signing off.
  • Return materials through a logged channel, or delete them with a method suited to the medium.
  • Document backup systems, their overwrite cycle and confirmation that copies will not be restored.
  • Store any permitted archival copy in a restricted location with an access log.
  • Collect written confirmation from subcontractors.
  • Issue the certificate of destruction and file it with the engagement records.

Illustrative: closing out a supply chain engagement#

Illustrative: a fictional operations consulting firm finishes a distribution network redesign for a mid-size manufacturer, and the client elects destruction. The engagement manager finds client shipment data in a Teams channel, an analyst's Python notebooks, a Power BI workspace and transcripts from an AI note-taker used in workshops.

The firm deletes each copy, asks the note-taker vendor to purge the transcripts, and confirms its backup system overwrites on a fixed cycle without restoration. Under the clause's archival exception it keeps one copy of the final report in a restricted folder. The certificate lists every system, the method used and the retained report, and the note-taker joins the firm's standard closeout list.

A certificate of destruction like this one should state what was destroyed, where, when and how, and what was kept under which exception. Vague certificates that simply say all information was destroyed create risk if a copy later surfaces in a mailbox or a backup restore.

How SourceX handles client-confidential material#

SourceX handles client-confidential material by keeping it out of scope. During the Rights step of the SourceX five-step transaction, a consulting firm identifies which engagements carry return or destroy duties, and anything covered by those duties, including retained archival copies, is excluded from what the firm might license.

What can remain are firm-owned records such as proposal processes, staffing plans and internal review templates, after confidential client details are removed. The SourceX Evidence Packet documents the licensing rights and release authorization for that material, so the firm can show it never drew on returned or destroyed client information.

Frequently asked questions

Does a return or destroy clause cover our deliverables?

It depends on the definitions. Final deliverables are often owned by the client under the IP section, while the clause covers the client's confidential information. Drafts and working papers that contain client data usually fall within scope even when the firm owns the underlying method. Read the definitions of confidential information, deliverables and work product together.

Can we keep anonymized lessons learned from an engagement?

Some agreements let the firm keep general knowledge, skills and experience, sometimes through a residuals clause, and others do not. Lessons learned that contain no client confidential information are easier to defend, but whether they are permitted depends on the wording. Check with counsel before building reusable assets from client work.

What if the client never asks for return or destruction?

Read the trigger. Some clauses apply automatically at termination, others only on request. Even when the duty depends on a request, many firms run the same closeout anyway, so client information does not sit indefinitely across tools, which also reduces exposure if the firm suffers a breach.

Does a legal hold override a return or destroy clause?

In general, a duty to preserve evidence for actual or reasonably anticipated litigation or an investigation takes priority over scheduled destruction, and many clauses say so expressly. Check how your tools behave: Slack, for example, states that under a legal hold, messages and files in the covered conversations are saved regardless of retention settings, even if members edit or delete them. Tell the client the hold exists, keep the affected material secured, and complete return or destruction once counsel lifts the hold. Record each step in the engagement file.

Do we have to destroy engagement emails?

If the emails contain client confidential information and fall within scope, generally yes, unless an exception applies. Many firms rely on the archival or legal retention exception for engagement correspondence and restrict access to it. Reconcile your email retention settings and any legal hold with the clause before deleting.

Who should sign the certificate of destruction?

Someone with authority over the systems and the engagement, often a partner or an officer named in the clause. The signer should rely on a documented checklist rather than memory, because the certificate is a statement the client may rely on later, including in a dispute.

Sources

  • Zoom admins and licensed users can enable deleting cloud recordings after a specified number of days. Source
  • Under a Slack legal hold, messages and files are saved regardless of retention settings, even if edited or deleted. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify