How to create a document retention policy for client files
Build a practical retention schedule for temporary client document intake without confusing working copies with records your business must keep.
A useful document retention policy answers a specific question for each copy your business holds: why does this copy still need to exist today?
It should not assign one period to every client file. A temporary upload used to check an application may be needed for days, while the resulting contract, tax record or professional file may have to remain in an official system for much longer. Treating both copies as the same record either keeps sensitive intake files unnecessarily or deletes records the business is required to retain.
The policy needs to separate purpose, location and deletion trigger. It should also name the person who can approve an exception.
Start with the storage limitation rule
The EU General Data Protection Regulation does not provide a universal number of days or years for personal data. Article 5 says personal data must be adequate, relevant and limited to what is necessary, then kept in identifiable form for no longer than the processing purpose requires. The official GDPR text calls these principles data minimisation and storage limitation.
The UK Information Commissioner's Office says organisations should justify their periods, review data when a period ends and erase or anonymise it unless there is a clear reason to keep it. Its storage limitation guidance also says legal and regulatory requirements must be considered.
Other countries and sectors have their own rules. Tax, employment, professional and litigation duties may affect retention. A policy is not a substitute for advice about them.
Separate the intake copy from the official record
Most retention mistakes begin with an undefined word: "document."
Suppose a client uploads a bank statement so an accountant can confirm a figure. The upload, a download, the accounting workpaper and the submitted return are separate copies or records. They may need different periods.
The intake copy does not inherit the final record's period. Keep it only while it serves the intake purpose, unless a documented requirement says otherwise.
Ask these questions for every process:
- What decision or task needs the uploaded file?
- Which system holds the authoritative record after the task ends?
- Does that system need the original file, a derived fact, an approval record or only the outcome?
- What event proves the intake purpose is complete?
- Which law, contract or professional rule requires a longer period?
- Who may pause deletion, and on what grounds?
This boundary lets a temporary intake service remain temporary. It also prevents a team from treating an email inbox or upload portal as an accidental archive.
Use a retention worksheet
Build the schedule around business processes rather than file extensions. "PDF" says nothing about purpose. "Identity evidence for supplier onboarding" says much more.
| Field | What to record | Example format |
|---|---|---|
| Process | The task that receives the document | New supplier approval |
| Document category | The narrow category requested | Proof of account ownership |
| Purpose | Why the team needs this copy | Verify payment details before approval |
| Lawful basis or authority | The documented basis for processing | Contract, legal obligation, legitimate interests or another assessed basis |
| Official record | What must remain after review | Approval outcome in supplier system |
| Intake location | Where the temporary submission arrives | Controlled upload workspace |
| Start event | When the retention clock begins | Accepted upload time |
| End event | What normally completes the purpose | Supplier approved, rejected or request withdrawn |
| Normal period | Time allowed for review and closeout | Organisation's chosen operational window |
| Early deletion | When staff should remove it before expiry | Review complete and no hold applies |
| Exception owner | Role allowed to extend or pause deletion | Process owner or legal contact |
| Deletion scope | Copies and derivatives to remove | Original, previews, links and sensitive metadata |
| Evidence | Non-sensitive proof that deletion ran | Submission reference, event and time |
The example format is not a legal retention schedule. It shows the level of detail needed to write one.
Build the policy process by process
1. Inventory every intake route
List the places where client files arrive: personal mailboxes, shared inboxes, web forms, upload portals, messaging apps, shared drives and physical media. Include automatic copies such as mail archives and cloud sync folders.
Start with a real request and follow one file from the sender to final deletion. Staff interviews often reveal a route that the written procedure misses.
The US Federal Trade Commission recommends taking stock of where sensitive information enters and where it is stored. Its Protecting Personal Information guide also advises businesses to keep sensitive information only while they have a legitimate need and to create a written records retention policy when records must remain.
2. Identify external requirements
For each process, list applicable laws, regulatory rules, contracts, insurance conditions, professional guidance and active legal holds. Record the exact authority and the date it was checked. "Compliance requires it" is not enough.
Avoid copying a period from another country or industry. Even within one organisation, tax files, job applications and identity checks may follow different rules.
If the authority requires only a result or limited evidence, do not assume it requires every source document and working copy. Confirm the scope with the person responsible for the requirement.
3. Define a normal operational window
Choose how long the team normally needs to receive, review and close the submission. Base this on the process, not storage capacity.
A temporary intake product may offer standard choices such as 7, 30 or 90 days. Those are operational windows, not legal conclusions. Choose the shortest window that reliably covers the work. If a task routinely exceeds it, fix the schedule or process rather than asking staff to extend every submission.
Set the expiry when the document arrives. A date visible during review is easier to manage than a promise to clean up the workspace later.
4. Define the start and end events
"Keep for 30 days" is incomplete until the policy says when day one begins. It might begin at upload, acceptance, case closure, contract termination or the end of a reporting period.
Temporary intake usually benefits from an arrival-based clock because every submission receives a deadline immediately. Early deletion can then follow the completion event. A permanent record may use a different event under its own schedule.
5. Make early deletion normal
An expiry is the latest routine date, not a reason to keep a completed submission until the last minute.
Give the reviewer a clear closeout action. Before deleting the intake copy, they should record the required outcome or move the authoritative record into its approved system. Then they can remove the temporary material.
This workflow is easier when the original request is narrow. The data minimisation guide for document requests shows how to avoid collecting material that the team never needs.
6. Control extensions and holds
An extension should record a new date, reason and approver. Free-text reasons are useful for reviewers, but avoid putting document contents or personal details into logs.
Define acceptable reasons, such as a verified delay in the underlying process or a documented legal hold. A subscription cancellation, payment failure or staff holiday should not silently stop automatic deletion.
If most submissions in a category need extensions, the normal period is wrong or the workflow has a bottleneck.
7. Define what deletion covers
Deleting the visible list entry may leave the original object, preview images, temporary print output, active links, wrapped encryption keys or sensitive metadata. The policy should name these components and assign responsibility for their removal.
Backups may follow a separate rotation. State how long deleted data can remain there, how it is kept beyond normal use and what happens after a restore. The cloud document deletion guide explains this boundary in detail.
Downloads and screenshots outside the controlled workspace require their own device and records policies. No portal can erase an external copy it does not control.
Add an exception register
Exceptions need enough detail to be reviewed without becoming another sensitive record.
Record:
- The submission or process reference
- The original deletion date
- The new date or hold status
- A short coded reason
- The approving role
- The approval time
- The next review date for an open-ended hold
Do not copy filenames, client names or document contents into the register unless they are genuinely required and protected under a separate retention rule.
An open-ended hold should still have a review date. The review does not force deletion. It checks whether the reason remains valid.
Test whether the policy works
A policy that exists only in a document has not controlled retention.
Trace a few completed submissions through the schedule. Check intake, mailbox fallback, downloads, derivatives and the official record. Confirm that deletion ran and any tombstone contains no sensitive content.
Test failure handling as well. If storage is temporarily unavailable when a deletion job runs, the system should retry safely rather than marking the work complete. An expired or cancelled workspace should not stop the deletion schedule.
Review the schedule when a process, requirement or provider backup policy changes, or an incident reveals an unlisted copy.
A short policy statement
The operating rule can be concise:
Every sensitive document received for temporary review must have a recorded purpose, owner and deletion date at intake. The reviewer moves any record that must be retained into the approved system of record, then deletes the temporary copy when the task is complete or when its scheduled date arrives. Extensions require a reason, approver and new review date. Deletion continues for expired, cancelled and delinquent workspaces. External downloads follow the organisation's device and records policies.
Attach the detailed worksheet and authority references behind that statement. Staff need the rule first and the evidence when a difficult case appears.
Frequently asked questions
How long should a business keep client documents?
There is no single period for every client document. The answer depends on purpose, applicable law, contracts, professional rules and whether the copy is a temporary intake item or an official record. Document the reason for each period and review it when the purpose ends.
Does GDPR require deletion after 30 or 90 days?
No. GDPR requires personal data to be kept no longer than necessary for its purpose, subject to permitted longer retention and appropriate safeguards. It does not set a general 30-day or 90-day period for client files.
Can we keep documents in case they become useful later?
A vague possibility is a poor retention reason. Identify the specific future purpose, its legal basis and the period it justifies. If the organisation cannot explain why a copy is needed, it should normally erase or anonymise it, subject to applicable requirements.
Should deletion happen at expiry or after a manual review?
High-volume, standardised intake benefits from automatic deletion at the scheduled time. The team can delete earlier when work ends. Processes with genuine legal holds need a controlled pause and review mechanism, not a general manual queue that lets every item remain indefinitely.
What proof of deletion should we keep?
Keep the minimum non-sensitive evidence needed for accountability, such as an internal reference, deletion event, time and outcome. Do not retain filenames, document contents, sender identities or storage paths in the deletion record unless a separate documented requirement makes them necessary.
Does cancelling a service end the retention policy?
No. Automatic deletion should continue when a trial ends, payment fails or a workspace is cancelled. Billing status does not create a new purpose for keeping sensitive documents.