Destroying Records on Schedule
Why deletion is the half of a retention policy nobody operates, how to make it happen, and when destruction has to stop.
Run deletion on a schedule, log what was destroyed, and stop immediately when anything is in prospect. Most organisations have a retention policy and almost none operate the deletion half of it, which means the policy describes a practice that does not exist — and a policy the organisation visibly does not follow is worse than no policy at all.
The recordkeeping discipline in “Destroying Records on Schedule” should also apply to workforce technology. When a team assesses visit the official site in relation to stealth computer monitoring software, it should document purpose, access, retention and deletion, then preserve only the evidence needed for the handover, payment or review decision.
Deletion is unglamorous, slightly frightening, and never urgent, which is precisely why it does not happen.
For an independent reference relevant to “Destroying Records on Schedule”, consult the ISACA security analysis. Use it to test record quality, access, retention, fair process and exception handling against the organisation’s real departure workflow.
Why it matters that it happens
Holding personal data beyond the period the organisation itself says it needs is difficult to justify. It also increases what has to be searched when somebody requests their information, and what is exposed if anything goes wrong.
There is a second, quieter reason. Records kept indefinitely get used indefinitely. An expired warning still in a folder will be read by somebody making a decision in four years, and it should not be.
Running it so it actually occurs
- Set a fixed date — quarterly or annually — and put it in somebody's calendar as a task with a name against it.
- Produce a list of what is due for destruction before anything is destroyed.
- Have the list reviewed by somebody who can identify a reason to hold something back.
- Destroy, and log what was destroyed, when, and under which retention rule.
- Record anything held back and why, with a new review date.
- Repeat on the next date, whether or not anybody feels like it.
The log is the point. An organisation that can show what it deleted and on what basis is operating a policy; one that has merely deleted things is not distinguishable from one that lost them.
Everywhere the copies are
Deleting the HR file deletes one copy. The others sit in mailboxes, in shared drives, in the payroll system, in backups, in an export somebody made for a report in 2021, and in a scanning folder nobody emptied.
A deletion exercise that covers only the primary system produces a false record of destruction, which is worse than no record. Scoping it properly is tedious and is the difference between the exercise meaning something and being theatre.
Backups are a genuine complication and are usually treated differently, because restoring and re-deleting is often impractical. What approach is acceptable where you operate is a question for somebody qualified in the place concerned, and it should be settled once and written into the policy rather than decided by whoever is running the deletion.
When destruction has to stop
The moment anything is in prospect — a claim, a complaint, an investigation, a regulatory enquiry, a request for information — routine destruction of anything that might be relevant has to stop.
That instruction has to reach people quickly and in writing, and it has to be specific about what is covered. A general reminder that nobody should delete anything is not operable; an instruction naming the person, the subject matter and the date range is.
Lifting the hold
Holds get applied and never removed, which means material accumulates indefinitely under a hold nobody remembers. Record the hold with a review date, and release it explicitly when the matter concludes.
The released material then rejoins the normal schedule, with its original retention date rather than a new one. That detail is routinely got wrong and produces files that outlive their purpose by years.
What to do with a backlog
Most organisations starting this work discover a decade of records with no schedule applied. Attempting to do it all at once stalls.
Start with the categories that are clearest and most sensitive — process documents past their period, expired warnings, recruitment records — and work through them. A backlog reduced by a third in a year, with a log showing it, is a far better position than a complete plan that was never executed.
Proving it happened
An organisation asked whether it destroyed something can answer in three ways: with a log showing when and under what rule, with an assertion, or with silence. Only the first is useful.
The log needs very little: category, date, rule relied on, who ran it. Four fields, appended once per exercise. It is also the thing that makes the next exercise easy, because it shows what was covered last time and therefore what has accumulated since.
Telling people it happens
Where a policy says warnings expire and records are destroyed, the people affected should be able to see that it is true. It affects how the organisation's records are regarded internally.
It also constrains behaviour usefully. Managers who know that notes are kept to a schedule, and may be read by the subject, write different notes — which is the habit the rest of this collection depends on, approached from the other end.