Skip to content

AI data market

Should you delete old business records or keep them for AI value?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Decide whether to delete old business records or keep them by record family, in a fixed order: legal and contractual obligations first, then cost and risk, then value. AI value justifies keeping records only when they link work to outcomes and the company has the right to use them. It never justifies keeping personal data past its purpose.

Key takeaways

  • Obligations come first: legal holds, retention rules and customer contracts override any value argument.
  • Records that connect a request, a decision and an outcome carry most of the AI value in an old archive.
  • Personal data can often be removed while the operational record itself is kept.
  • Export and document records before retiring the system that holds them, because migrations lose history.
  • Raw logs, duplicate backups and orphaned attachments rarely justify their storage cost and breach risk.

Should you delete old records or keep them?#

Old business records should be kept or deleted by record family, not as one archive. A decade of support tickets, an old ERP order history and a departed sales leader's mailbox carry different obligations, costs, risks and value, and a blanket rule gets at least one of them wrong.

The order of questions matters. Start with what the company must keep or must delete, because those answers are not negotiable. Only records left open after that step go through the cost, risk and value comparison.

The four tests: obligation, cost, risk and value#

The four tests turn a vague storage debate into a decision a COO and a general counsel can both sign. Apply them in order and write down the answer for each record family, with the reason.

The four tests: obligation, cost, risk and value
TestQuestion to askPoints toward deletingPoints toward keeping
ObligationDoes law, a legal hold or a contract require keeping or deleting?A DPA or customer agreement requires deletion, or the retention period has endedA legal hold, tax rule, employment rule or contract requires retention
CostWhat does it take to keep the records readable?Only a paid legacy system can open themThey export cleanly to a standard format and store cheaply
RiskWhat harm follows if the records leak or are demanded in litigation?Heavy personal, health or payment data with no current useLow sensitivity, or sensitive fields can be removed
ValueWould anyone use the records for operations, analysis or licensing?Isolated files with no outcome or contextLinked histories of requests, decisions and outcomes the company controls

Which obligations override everything else#

Legal holds, statutory retention requirements and contract terms override every value argument. If litigation is pending or reasonably expected, relevant records must be preserved whatever the retention schedule says. Tax, employment and industry rules may require keeping some records for set periods, and those periods differ by record type and state.

The opposite obligation matters just as much. Customer agreements and data processing agreements often require deletion when a relationship ends, and privacy laws such as the GDPR and several US state laws expect personal information to be kept no longer than needed for the purposes disclosed. A record the company is obliged to delete is not available for AI value, however useful it looks.

Record each obligation against the record family it affects, and have counsel confirm the list. The same mailbox can contain records under a hold, records past their retention period and records a customer asked to have deleted. Then delete through a written retention schedule applied consistently, not through one-off purges before a deal or a dispute; routine deletion under a schedule is far easier to defend than an unexplained clean-up.

Which old records carry AI value#

Old records carry AI value when they show people doing skilled work and what happened as a result. Model developers look for request, decision and outcome chains: a support ticket with its resolution, a Jira issue with the code change and release, a dispatch record with the callback, a nonconformance report with its corrective action.

Age can help or hurt. Records written before AI writing tools were common carry a clearer human signal, but records about retired products, discontinued services or superseded rules may teach little. Rights matter too: records that belong to customers, or that contracts restrict, carry little licensing value however rich they are.

  • Usually worth keeping: resolved support tickets, issue histories with linked code, project files with approvals, job records with callbacks and warranty claims, quality records with corrective actions.
  • Usually worth minimizing: raw application logs, duplicate backups, personal mailboxes of departed staff, scanned HR files past their retention period, orphaned attachments.
  • Decide case by case: CRM histories, call recordings, shared drives and chat exports, which mix valuable discussion with personal data.

How to keep records without keeping all the risk#

Keeping records without keeping all the risk means changing their form, not only their location. Most of the risk in an old archive sits in a minority of fields, such as names, contact details, payment fragments, health notes and credentials. Most of the value sits in the work itself.

The steps below shrink the risk while preserving the parts a buyer, an analyst or a future acquirer would actually use.

  • Export records from the legacy system into a documented format before its license or hardware lapses.
  • Remove or pseudonymize personal data where its original purpose has ended, and record the method used.
  • Keep original creation dates, author roles and record identifiers so provenance survives the move.
  • Restrict access to a named owner and log who opens the archive.
  • Note the contract or notice that governs each record family, and set a review date.
  • Delete superseded copies, so one documented archive replaces several forgotten ones.

Keep or delete is really four choices#

Keep or delete is really four choices, and most record families land in one of the middle two. Naming the disposition for each family, rather than arguing keep versus delete, makes the decision easier to approve and to audit later.

Keep or delete is really four choices
DispositionWhat it meansTypical record families
Keep as isRetain in the live system with normal accessRecords under a legal hold or still used in daily operations
Keep minimizedRetain the work record with personal and payment details removed or maskedResolved tickets, job histories, quality records, issue histories
Keep coldExport to a documented archive, retire the system and restrict accessHistory from a legacy ERP, helpdesk or dispatch system being replaced
Delete on scheduleDestroy at the end of the retention period and log the deletionPersonal files past retention, duplicate backups, data customers asked to remove

Illustrative: a manufacturer retires its legacy quality system#

Illustrative: a fictional 200-person precision machining company is replacing an on-premises quality management system and a shared file server. The archive holds many years of nonconformance reports, corrective and preventive actions, supplier corrective action requests and inspection records, alongside customer drawings, scanned personnel files and old CNC programs written for customer parts.

The COO and outside counsel apply the four tests. Customer drawings and customer-specific programs are returned or destroyed as the customers' NDAs and purchase terms require. Quality records that customer contracts require the company to retain are kept as is until those periods end. Personnel files follow the retention periods counsel lists and are then destroyed.

Nonconformance reports, corrective actions and supplier requests are exported with inspector names replaced by role codes, keeping defect descriptions, root-cause analyses, actions taken and whether the problem recurred. The result is a smaller archive the company can use for training new quality engineers and evaluate for licensing later, plus a written record of why everything else was destroyed.

How SourceX fits into a retention decision#

SourceX can assess licensing fit before records are deleted, using metadata only: systems, record families, date ranges and known restrictions. Nothing is shared during the initial assessment, which matters when a system retirement date is close.

The assessment uses the SourceX Enterprise Data Value Framework. Human-generated signal, domain expertise, recency, data cleanliness and rights count in a record family's favor, while preparation cost and privacy burden reduce its net value. A family with weak rights and a heavy privacy burden may be better deleted than kept, and the assessment says so plainly.

Frequently asked questions

Is potential AI value a valid reason to keep personal data?

Rarely on its own. Privacy laws generally tie retention of personal information to the purposes the company disclosed, and licensing may not be one of them. The usual approach is to keep the operational record and remove personal details. Whether any personal data can be kept for a new purpose is a question for counsel.

Are backups a substitute for a proper archive?

No. Backups are built for restoring systems, not for finding or using records, and they often hold data the company meant to delete. Old backup sets can also preserve a retired system's format with no way to read it. Export what you mean to keep into a documented archive and let backups expire on schedule.

Who should own the keep-or-delete decision?

A COO or operations leader usually owns the inventory and the cost question, while general counsel owns obligations and risk. Department heads confirm what the records contain. Write the decision down by record family, with reasons, so a future acquirer, auditor or regulator can see why records were kept or destroyed.

What if we already deleted the records?

Then the decision is made, and the focus shifts to what remains. Check whether exports, reporting databases, shared drives or the old vendor still hold copies, and whether keeping those copies fits your obligations. Document the deletion so later diligence questions have a clear answer.

Do email archives count as records worth keeping?

Some do. Threads with customers, vendors and colleagues often hold the reasoning behind decisions that systems record only as outcomes. They also hold the most personal and confidential content. Treat email as its own record family, decide by team or mailbox, and expect heavier preparation if any of it is ever licensed.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify