Documentation / Platform glossary / Data retention

Data retention

In Short

Data retention is the deliberate decision about how long each category of information is kept and what happens when that period ends. Retention is a policy question before it is a technical one, because both keeping too little and keeping too much create real exposure.

Data retention concept diagram

Definition

A retention policy states, per category of data, how long it is held, what triggers the clock, and what disposal means. The trigger matters as much as the duration: retention measured from creation behaves very differently from retention measured from the end of a relationship.

Three phases describe the lifecycle. Data is retained while it serves its identified purpose. It becomes expired when the period elapses. It is then disposed of — deleted or irreversibly anonymized — as a distinct step, because expiry is a status change and disposal is an action.

Retention is genuinely a two-sided risk. Too short, and an investigation has no evidence, a dispute cannot be resolved, and statutory record-keeping obligations are breached. Too long, and the same data becomes discoverable in litigation, exposed in a breach, and subject to rights requests that would otherwise not apply. Neither direction is the safe default.

Two complications recur in practice. Legal hold must be able to suspend deletion for specific records without disabling the policy generally. And backups have their own retention: data deleted from a live system may persist in backups for some period, which needs to be stated honestly rather than glossed over when answering a deletion request.

Why It Matters

Retention is where privacy law becomes operational. GDPR's storage limitation principle, PIPEDA's retention principle, and CCPA/CPRA deletion rights all require an organization to know what it holds and for how long — which is not answerable without a policy.

The most common weakness is a documented policy nothing enforces. Retention that depends on someone remembering to delete is not retention.

How QueryTek Uses It

QueryTek documents how long categories of information remain available for legitimate business and support needs, and treats disposal as an explicit step. Retention is described as functional availability — what a customer can still retrieve, and when. Specific periods are established contractually.

Related Terms