Skip to content

Rights and contracts

Should you delete old data or keep it for AI?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Whether to delete old data or keep it for AI depends on three tests applied to each record family: a legal duty to keep or delete it, its privacy risk, and its licensing value. Keep what you must, delete what you promised to or cannot protect, and assess the rest before systems shut off.

Key takeaways

  • Decide by record family, such as job tickets or call recordings, not by system or by age alone.
  • A legal hold or a contractual deletion duty overrides any licensing value.
  • Records that link a request to a decision and an outcome are the ones AI developers tend to value.
  • A metadata-only assessment can run before a shutdown without moving or sharing any files.
  • Keeping records for possible licensing still requires security, access limits and a documented reason.

Why keeping or deleting old records is now a real decision#

Keeping or deleting old records is now a real decision because licensing operational records to AI developers adds a third factor to what used to be a housekeeping question about storage cost and legal risk. Years of support tickets, dispatch notes or quality records can carry value that did not exist when most retention schedules were written.

The decision usually arrives with a trigger. A help desk is being replaced, an ERP migration will not carry history forward, a subscription is up for renewal, or the company is winding down. Once the old system is switched off, the choice has been made by default, and the records are gone or trapped in exports nobody can read.

The three tests that decide each record family#

The three tests are legal duty, privacy risk and licensing value, applied in that order. A legal duty settles the question on its own. Privacy risk can rule out keeping records that have value. Value only decides the outcome for records that clear the first two tests.

Run the matrix one record family at a time. A single CRM can hold sales emails that pass all three tests and scanned identity documents that fail the second.

Two rules settle the most common conflicts. When a legal hold and a deletion duty cover the same records, the hold usually wins until it lifts, and counsel documents why. And a duty to keep records is not permission to reuse them: records kept for tax, warranty or litigation reasons still have to pass the privacy and rights review before anyone licenses them.

The three tests that decide each record family
Legal dutyPrivacy riskLicensing valueDefault action
Must keep: hold, tax, contract or regulationAnyAnyKeep under the duty's terms with access limits
Must delete: contract, promise or requestAnyAnyDelete and record the deletion
NoneHigh and hard to reduceAnyLean toward deletion; confirm with counsel
NoneLow, or reducible by de-identificationHighKeep, secure and assess for licensing
NoneLowLowDelete on schedule
UnknownUnknownUnknownPause deletion for a defined review and resolve the unknowns

A legal duty is any obligation that requires the company to retain or destroy specific records, and it comes from more sources than most owners expect. Retention duties and deletion duties can both apply to the same archive.

Write down which duties apply to each record family before anyone discusses value. Counsel should confirm the list, because the same email archive can sit under a litigation hold and a customer deletion clause at once.

  • Litigation holds: a pending or reasonably expected dispute freezes relevant records, whatever the retention schedule says.
  • Tax and accounting rules: invoices, payroll and financial records usually carry minimum retention periods set by law.
  • Industry and safety rules: some trades and manufacturers must keep inspection, maintenance or quality records.
  • Customer contracts and DPAs: many require return or deletion of customer data when the relationship ends.
  • Privacy notices and laws: your own published retention statements, and deletion requests under laws such as the CCPA.
  • Warranty obligations: open warranties may require keeping job and product records until they expire.

When deleting is the better answer#

Deleting is the better answer when records carry privacy or contractual risk that cannot be reduced, or when the company has promised to delete them. Data minimization is a core principle of modern privacy law, and keeping personal information longer than a disclosed purpose needs can create exposure in its own right.

Good candidates for deletion include call recordings collected without clear disclosures, free-text fields full of health or financial details, scanned identity documents, and customer content under contracts that require return. Defensible deletion means following a written schedule, recording what was deleted and when, and suspending the schedule whenever a hold applies.

Deletion has to reach the copies. Old exports on shared drives, backup tapes, a former vendor's archive and spreadsheets pulled by individual managers can all outlive the system itself. List where copies sit before declaring a record family deleted, and ask vendors to confirm deletion in writing where contracts allow.

What makes old records worth keeping for AI?#

Old records are worth keeping for AI when they show real work end to end: a request, the decision someone made and what happened next. Developers building agents for support, operations or engineering need examples of how experienced people actually handled cases, and that context rarely exists in public data.

Linkage matters more than raw volume. A field service company's estimates, dispatch notes, invoices and callbacks connected by job number are more useful than a larger pile of unconnected PDFs. Predominantly English records with consistent fields across years also rank higher.

Keeping records for this reason is a decision, not a default, and it needs an owner and a review date like any other retention choice.

What makes old records worth keeping for AI?
Record familyOften worth assessingOften a deletion candidate
Support ticketsThreads with resolution notes and linked engineering issuesTickets dominated by account numbers or health details
Job and dispatch recordsJobs linked to estimates, technician notes and callbacksPhotos of customers' homes with no work context
Email and chatInternal project discussions tied to outcomesMailboxes of departed staff with no business purpose
Quality recordsNCRs and CAPAs with root cause and closureCustomer-owned drawings and specifications
HR recordsRarely licensableKept only as law requires, then deleted

How to preserve records you decide to keep#

Preserving records you decide to keep means exporting them in a form that still makes sense once the old system is gone. A pile of PDFs or a database dump without its field definitions loses the links between request, decision and outcome that make the records worth assessing.

Start before the cancellation notice goes out. Software vendors often set an export window after a subscription ends and then delete customer data, so read the contract for that window and for any export fees, and run a test export early enough to fix problems.

  • Export full history, not just open items, with record IDs, timestamps, status changes and the keys that link jobs, tickets, invoices and callbacks.
  • Keep attachments joined to their parent records rather than in a separate folder with no index.
  • Save the field dictionary, status codes and custom field names, because exported codes are unreadable without them.
  • Open the export outside the old system and spot-check a sample of records end to end.
  • Store it in company-controlled, encrypted storage with access limited to named people and logged.
  • Write a one-page decision record: record families kept, legal basis or business reason, owner and review date.

Illustrative: a plumbing and HVAC company retires its dispatch system#

Illustrative: a fictional plumbing and HVAC company with a long operating history is moving from an older field service system to ServiceTitan. The migration will carry over customer records and open jobs but not the archive of closed jobs, technician notes and callback histories.

Before cutover, the owner sorts the archive with the three tests. Job records tied to open warranties stay under a legal duty. Early call recordings, made without clear disclosures, are scheduled for deletion. The remaining closed jobs, estimates and callback notes carry low privacy risk once customer names and addresses are removed, so the company exports them to its own storage and runs a metadata-only fit check before deciding whether to license them.

How SourceX approaches records before a shutdown#

SourceX can run a fit check on records before a system is retired, using metadata only: system names, years of history, record families and known restrictions. Nothing is shared during the initial assessment, so the check adds no privacy risk to the keep-or-delete decision.

If records proceed, the SourceX five-step transaction covers Supply, Rights, Preparation, Approval and Delivery, and the supplier approves every step. Large archives stay in the company's own storage or ship on encrypted drives, because SourceX does not host multi-terabyte datasets.

Frequently asked questions

Does keeping records for possible licensing conflict with data minimization?

It can, which is why the decision needs a documented reason. Keeping records with no legal duty and no assessed purpose is hard to justify. Keeping a defined record family, secured and access-limited, while a licensing assessment runs is easier to explain. Privacy counsel should review the reasoning against your notices and the laws that apply.

How long should deletion pause while we assess value?

Only as long as the assessment needs. Set a review date, name an owner and record the decision at the end, whether that is keep, license or delete. An open-ended pause turns into indefinite retention, which is the outcome privacy rules try to prevent.

Can we de-identify records instead of deleting them?

Often, and doing so can change both the privacy risk and the licensing value. De-identified records may fall outside some privacy obligations, but each law sets its own test, and the result has to hold up against realistic attempts to relink the records. Contractual deletion duties may still apply after de-identification.

Who should own the keep-or-delete decision?

The CEO or COO usually owns it, with counsel confirming legal duties and IT confirming what can be exported and how. In a wind-down, the officer or professional responsible for the company's assets may hold that authority instead.

What if the old archive is already gone?

Then the question moves to what remains. Current systems keep accumulating history, and exports or backups may exist under former vendors' terms. Going forward, a retention schedule that names record families and reviews value before deletion avoids repeating the loss.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify