top of page
background.jpg

​

GEODI Discovery Series | Issue 13 | Data Retention: Should We Keep Every Piece of Data Forever?

Sep 29
4 min read

A file was last opened in 2017. The project team has long since changed. The customer relationship ended years ago. Three newer versions of the document exist in another system. But the file is still there.


And it is not alone. One copy is on the old file server. Another is in the archive. Another is in a user's personal folder. Another is an email attachment. And all of them are still being backed up.


Nobody uses this data. Nobody really knows why it is being kept. Yet the organization continues to store it, back it up, protect it and carry its risk.


This is exactly where the data retention challenge begins.


Storage Has Become Cheaper. Keeping Data Has Not.


As enterprise data volumes grow, storage is usually the first cost that comes to mind. But the true cost of retaining data for years is not just the disk space it occupies.


For as long as data is retained, it requires:


  • Access rights management

  • Security controls

  • Backups

  • Retrieval when needed

  • Management in line with regulatory requirements

  • Assessment during a potential security incident


Just because it is technically possible to keep data does not mean it should be kept. The real question is:


Why are we still keeping this data?


A Retention Policy Is Not the Same as the Actual Data Environment


Many organizations have retention policies. For example, one document category may need to be retained for five years, while another record type must be kept for ten.


On paper, the system is clear. The actual data environment often is not. To apply a retention policy, you first need to know what a file is. Take SCAN_004823.pdf:


  • Is it a contract?

  • An invoice?

  • A copy of an identity document?

  • A personnel record?

  • A technical document?


You cannot make a retention decision based solely on a file's creation date. You first need to understand its contents.


Discovery → Understanding → Classification → Retention Decision


Effective data retention is therefore more than a mechanism for deleting files based on age. It requires evaluating data alongside its content, context and business value.


Data Retention: Should We Keep Every Piece of Data Forever? – GEODI Discovery Series Issue 13, Zero Second

"Old Data" and "Expired Data" Are Not the Same


A ten-year-old contract may still have legal or operational value. A six-month-old temporary export file may have no remaining business value. Therefore:


Old ≠ Obsolete


Age is an important signal, but it is not a retention decision on its own. A better assessment considers several signals together:


Age + Content + Data Type + Usage + Business Context + Regulatory Requirement


This approach makes it possible to ask not only how old data is, but why it is still being kept.


ROT Data: The Hidden Data Burden


One important concept in data retention is ROT data:


  • Redundant: unnecessary copies that also exist elsewhere.

  • Obsolete: content that is no longer current or has lost its business value.

  • Trivial: temporary or insignificant data with no lasting organizational value.


Examples of content kept for years include old report exports, temporary working files, outdated presentation versions, unused project folders, duplicate documents and old email attachments. These can account for a substantial share of an organization's total data volume.


But the main problem with ROT data is not how much space it occupies. It is that organizations keep retaining it without knowing what it contains.


Unnecessary Data Means Unnecessary Risk


Imagine a folder named "Former Employee Records / 2014". The folder is no longer actively used. Yet it contains national identity numbers, addresses, phone numbers, bank details, signed documents and other personal information.


Even when this data is no longer needed for business purposes, keeping it in the system expands the amount of data the organization must protect.


During a security incident, an attacker does not ask, "Is this data actively being used?" They focus on the data they can access.


Retention is therefore also a data security issue. Data you no longer hold cannot be leaked from your systems.


But "Delete Everything Old" Is Not the Answer Either


Data minimization should not be confused with uncontrolled deletion. The fact that a document has not been opened for a long time does not mean it has no value.


Legal obligations, contractual requirements, audit needs or organizational knowledge may require certain data to be retained for a long time.


The right retention approach is not a choice between "Keep Everything" and "Delete Everything Old". The goal is:


Keep What You Need. Know Why You Keep It. Dispose of What You No Longer Need.


Retention Decisions Require Visibility First


If an organization does not understand its data environment, the answers to these questions remain unclear:


  • What data do we have?

  • Where is it located?

  • How old is it?

  • When was it last used?

  • Which data category does it belong to?

  • Does it contain personal or sensitive information?

  • Are there other copies?

  • Does it support an active business process?

  • Does the retention requirement still apply?

  • Is it now a candidate for deletion or archiving?


Without these answers, a retention policy remains largely theoretical. You cannot manage the lifecycle of data you do not understand.


The GEODI Perspective


The GEODI Discovery approach helps improve visibility by discovering content across different data sources.


Organizations can evaluate not only a file's name and location, but also its content, metadata, dates and discovered data types. This visibility allows them to examine active content, old data, duplicate content, sensitive information and datasets that need retention review.


Retention initiatives can then be based on the organization's actual data environment, rather than policy documents alone.


Discovery is not about automatically deleting every old file. Its real value is helping the organization make informed decisions:


Keep → Archive → Review → Dispose


There Must Be a Decision at the End of the Data Lifecycle


Enterprise data management often focuses on creating data. How will we collect it? Where will we store it? How will we classify it? How will we protect it? But the data lifecycle also has an end.


Good data governance manages not only how data is created, but also when it should no longer be retained. The objective should not be to keep as much data as possible.


It should be to retain the data you need, for the necessary period, for the right reason.


Key Takeaway


Data retention is not about how long you can keep data. It is about knowing how long you should keep it.


Sometimes, the safest data is the data you no longer hold.


Zero Second | GEODI – Data Discovery by DECE Software.

GEODI Discovery Series Issue 13, prepared by Zero Second.

 
 
 

Comments


bottom of page