Data Retention
Data retention is the practice of keeping data for a defined period of time and then deleting it, based on legal, regulatory, and business requirements. Organizations typically formalize this in a data retention policy, which sets rules for what data to keep, how it is stored and protected, and when it should be removed. The goal is to hold onto information for as long as it is needed while not keeping it longer than necessary.
Data retention refers to the storage of data for a specified duration to satisfy legal, regulatory, and business obligations, followed by defined deletion or disposal. In many organizations it is operationalized through a data retention policy—a set of rules and procedures specifying which data types are retained, applicable retention periods, storage and protection controls, and deletion triggers. As commonly framed in the evidence, retention scheduling is driven by compliance and regulatory purposes as well as business needs such as data-driven insights; specific retention periods and mandatory schedules vary by jurisdiction, sector, and data type and are out of scope for this general definition.
Why it matters
Data retention sits at the intersection of legal compliance, operational efficiency, and risk exposure. Keeping data for as long as it is needed supports regulatory obligations, business continuity, and data-driven insights, while retaining it longer than necessary can increase legal liability, storage costs, and the potential impact of a breach. A well-defined retention policy helps organizations strike this balance by specifying what data to keep, how it is protected, and when it must be deleted.
For AI governance and model risk management, retention decisions carry additional weight. Training data, model inputs and outputs, validation datasets, and audit logs may all be subject to retention rules that reflect both compliance requirements and the practical need to reconstruct, reproduce, or challenge model behavior later. Insufficient retention can undermine the ability to validate or audit a model after the fact, while over-retention can conflict with data minimization expectations. These tensions should be resolved deliberately rather than by default.
Retention periods and mandatory schedules vary substantially by jurisdiction, sector, and data type, and this general definition does not attempt to specify them. Organizations should treat retention as a governed decision informed by legal counsel and applicable regulatory guidance, recognizing that a policy reduces but does not eliminate the risks associated with holding data.
Who it's relevant to
Inside Data Retention
Common questions
Answers to the questions practitioners most commonly ask about Data Retention.