Compyl
GRC Your Way

Data Retention Requirements by Law: How Long to Keep Records

By Compyl Research · Last reviewed September 2026

Data retention law is not one rule with one number. It is two opposing sets of rules applied to the same record at the same time: records laws that set a floor (keep this for at least N years) and privacy laws that set a ceiling (do not keep this longer than you need it). A defensible retention schedule is the document that resolves those two forces for every category of data your business holds — and a legal hold overrides both.

Key takeaways

  • Floors and ceilings, not one number. The IRS, OSHA, the SEC, ERISA and HIPAA tell you how long you must keep things. GDPR, CCPA/CPRA and the newer state privacy laws tell you how long you may. Both apply to the same record.
  • The longest applicable floor wins. Where two records laws cover one document, you keep it for the longer period. State medical-records rules routinely beat the federal HIPAA minimum.
  • Ceilings only bite once every floor has expired. A privacy law will not force you to delete a record you are legally required to retain — but it will penalize you for keeping it after that obligation ends. France’s data protection authority fined Carrefour France €2,250,000 in November 2020 partly for holding loyalty data on more than 28 million customers who had been inactive for five to ten years.
  • A legal hold suspends everything. Once litigation is reasonably anticipated, routine deletion has to stop for the relevant records, whatever the schedule says.
  • Auditors ask for the schedule, not the policy. SOC 2 and ISO 27001 assessors want evidence that records are actually disposed of on time, not a PDF that says they should be.

What do data retention laws actually require?

Almost every retention obligation in U.S. and EU law falls into one of three shapes, and telling them apart is most of the work.

Fixed-period floors. A regulator names a number of years and a trigger event. Payroll records: three years. OSHA injury and illness forms: five years following the year they cover. Audit workpapers: seven years. These are the easy ones — you can automate them.

Open-ended floors. The obligation runs until a condition is satisfied rather than until a clock expires. ERISA Section 209 requires plan sponsors to keep records until all benefits have been paid out and the audit window has closed. OSHA requires employee medical records for the duration of employment plus thirty years. Nevada requires physicians to keep a minor’s records until the patient turns 23. You cannot express these as a single retention period; you have to model the trigger.

Purpose-bound ceilings. Privacy laws almost never give you a number. GDPR Article 5(1)(e) — the storage limitation principle — requires that personal data be kept in identifiable form no longer than is necessary for the purpose it was collected for. California’s CPRA works the same way, with the added requirement that you disclose your retention period, or the criteria used to set it, at or before the point of collection. The number is yours to justify.

The practical consequence is that a retention schedule is a defensibility document. For fixed floors you cite the rule. For open-ended floors you model the trigger. For ceilings you write down the reasoning, because a regulator will ask why four years and not two.

How long do U.S. laws require you to keep records?

These are the federal floors most 200–1,000-employee businesses actually hit. Every one of them is a minimum — state law, contracts and your own litigation posture can extend it, and none of them can be shortened by policy.

Record type Minimum retention Source
Payroll records, collective bargaining agreements, sales and purchase records 3 years FLSA, 29 CFR 516.5
Timecards, wage-rate tables, work schedules, deduction records 2 years FLSA, 29 CFR 516.6
Federal income tax records 3 years from filing, longer in specific cases (7 years for bad-debt or worthless-securities claims; indefinitely if no return was filed) IRS period of limitations
Employment tax records 4 years after the tax is due or paid IRS
OSHA injury and illness logs (Forms 300, 300A, 301) 5 years following the calendar year they cover 29 CFR 1904.33
Employee medical records Duration of employment plus 30 years 29 CFR 1910.1020(d)(1)(i)
Employee exposure records 30 years 29 CFR 1910.1020(d)(1)(ii)
Employee benefit plan records supporting Form 5500 filings 6 years from the filing date ERISA §107
Records needed to determine benefits due Until all benefits are paid and the audit window closes ERISA §209
HIPAA policies, procedures, risk analyzes, BAAs and required documentation 6 years from creation or last effective date 45 CFR 164.316(b)(2)(i)
Audit workpapers and records supporting an audit report 7 years SOX §802 (18 U.S.C. §1520); SEC Rule 2-06 of Reg S-X; PCAOB AS 1215
Broker-dealer blotters, ledgers and customer account records 6 years, first two in an easily accessible place SEC Rule 17a-4(a)
Broker-dealer business communications, including email 3 years, first two in an easily accessible place SEC Rule 17a-4(b)(4)
FINRA member books and records with no other stated period 6 years FINRA Rule 4511(c)

Two things to notice. First, HIPAA’s six years applies to the compliance documentation — the policies, the risk analysis, the business associate agreements — not to patient medical records, which are governed by state law and vary enormously. Second, the SOX seven-year rule binds the auditor’s workpapers, not every corporate record, which is why “SOX means seven years for everything” is the single most common retention myth in a GRC program.

Which privacy laws limit how long you can keep data?

Privacy laws work in the opposite direction. Rather than a floor they impose a duty to justify and, once the justification lapses, to delete.

Regime What it requires on retention What that means in practice
GDPR (EU/EEA) Article 5(1)(e): personal data kept in identifiable form no longer than necessary for the stated purpose. Articles 13–14 require you to disclose the period or the criteria for setting it. Set a period per processing purpose, document the reasoning, and either delete or genuinely anonymize at the end of it. Pseudonymised data is still personal data.
UK GDPR and Data Protection Act 2018 Mirrors the EU storage limitation principle. Note the Limitation Act 1980 pulls the other way — six years for claims on simple contracts, so contract records usually justify a six-year floor.
CCPA/CPRA (California) Businesses must not retain personal information longer than reasonably necessary for the disclosed purpose, and must disclose the retention period or the criteria at or before collection. Your privacy notice becomes a binding commitment. If it says 24 months, 36 months is a violation.
Other U.S. state privacy laws (Virginia, Colorado, Connecticut, Texas, Oregon and the rest of the 2023–2026 wave) Data minimization and purpose limitation, generally without a fixed number. One retention schedule can satisfy all of them if it is purpose-based rather than jurisdiction-based.
PCI DSS Requirement 3 limits cardholder data storage to what is necessary for business, legal or regulatory purposes, with a defined retention period and quarterly deletion of data past it. Sensitive authentication data must not be retained after authorisation at all. This is the strictest ceiling most businesses meet. The compliant answer is usually to stop storing the data — tokenization removes the record and the obligation together.
Sectoral health privacy (state consumer health laws, FTC Health Breach Notification Rule) Deletion rights and purpose limits for health data held outside HIPAA. Health data in a wellness app or an HR system is often governed here rather than by HIPAA.

The enforcement pattern is instructive. The Carrefour France decision did not turn on a breach or a leak; the regulator simply found the company holding data it no longer had a reason to hold, and held that a four-year inactivity window “exceeds what appears necessary” in mass retailing. Over-retention is enforceable on its own.

What happens when a retention floor and a privacy ceiling collide?

Less often than people fear, and the resolution is almost always the same.

Privacy laws contain carve-outs for legal obligations. GDPR Article 6(1)(c) makes compliance with a legal obligation a lawful basis for processing, and Article 17(3)(b) removes the right to erasure where processing is necessary to comply with one. CCPA/CPRA similarly permits retention where required by law. So a genuine statutory floor beats the deletion request — you keep the record, you narrow its use to the legal purpose, and you tell the individual why.

The order of operations that survives an audit:

  1. Is there a legal hold? If yes, retain, full stop, and document the hold.
  2. What is the longest applicable retention floor across every federal, state, sectoral and contractual rule that touches this record? Keep until it expires.
  3. Once every floor has expired, does a business purpose still exist that you could defend in writing to a regulator? If not, the ceiling applies.
  4. Delete or anonymize — from primary systems, backups, archives and third-party processors — and log that you did.

The step that fails in practice is the fourth. Deletion from a production database while the record survives in a nightly backup, a data warehouse and a SaaS vendor’s copy is the most common form of paper compliance in retention programs.

How do state data retention laws differ?

Sharply, and mostly in healthcare and employment. A multi-state business cannot run one number.

  • Medical records are set by state, not by HIPAA. Florida hospitals must keep patient records seven years; North Carolina sets eleven; Nevada requires records for a minor to be kept until the patient reaches 23. If you operate in several states, your schedule has to hold the longest applicable period for each record — or, more practically, the longest across your footprint.
  • Employment records pick up state wage-and-hour rules that often exceed the FLSA’s three years.
  • Breach notification and privacy statutes increasingly require you to publish your retention criteria, which converts an internal choice into an external representation.

The practical rule for a multi-state footprint: set the schedule to the longest period that applies anywhere you operate, unless a specific jurisdiction’s privacy ceiling forbids it, in which case that data set needs its own row.

What should a data retention policy include?

A policy that an auditor will accept has seven components. Anything shorter is a statement of intent.

  • Data inventory and categories. Every record type you hold — contracts, communications, financials, CRM records, HR files, security and access logs, trade secrets and controlled data — in both digital and physical form. You can only manage what you have enumerated.
  • Retention period and trigger for each category. Not just “7 years” but “7 years from the report release date” or “duration of employment plus 30 years”. The trigger is the part systems get wrong.
  • Legal basis. The statute, regulation, contract or documented business justification behind each period. This is what converts a policy into a defense.
  • Ownership. A named role responsible for each category — not a department, a role.
  • Approved storage locations, including backups, archives and named third-party processors, because deletion obligations follow the data.
  • Disposal method, distinguishing deletion, secure destruction and anonymization, and specifying who verifies it.
  • Legal hold procedure — how a hold is issued, what it suspends, who tracks it, and how it is released.

Two versions are worth maintaining. The external, consumer-facing statement sets out categories, periods and lawful bases in plain language, and satisfies the GDPR and CPRA disclosure duties. The internal policy carries the procedures, the owners and the disposal steps. Writing one document to do both jobs produces something too legalistic for staff and too detailed for the public.

How do you build a retention schedule that holds up?

  1. Audit what you hold. Systems, shared drives, personal devices, physical files, and every SaaS tool a department bought without telling IT. Record where each category lives and who owns it.
  2. Map the regulatory scope per category. For each record type, list every framework that touches it — federal, state, sectoral, contractual and customer-imposed. Take the longest floor.
  3. Set the period and write down the reasoning. Where no law applies, the justification is a business one, and it needs to be in writing before a regulator asks.
  4. Bring in the people who know the exceptions. Legal for discovery and holds, HR for OSHA, FLSA and ERISA, finance for tax and audit, IT and security for logs and backups, and operations for traceability records. No single executive holds this map.
  5. Automate creation and deletion. Manual disposal does not happen. Set retention labels at the system level, automate archive and delete jobs, and keep an immutable log of what was destroyed and when.
  6. Reduce what you collect. The cheapest retention control is not holding the data. Tokenizing card data, truncating logs and shortening default collection windows removes both the storage cost and the compliance surface.
  7. Review on a schedule and on change. Annually at minimum, plus whenever you enter a new state or country, adopt a new framework, or sign a customer contract with its own retention terms.

What is a legal hold and why does it override the schedule?

A legal hold is an instruction to suspend routine deletion of records that may be relevant to litigation, an investigation or an audit. The duty attaches when litigation is reasonably anticipated — not when a complaint is filed — and it applies to electronically stored information including email, chat, backups and mobile data.

The consequences of getting this wrong are procedural rather than regulatory, which makes them easy to underrate. Under Federal Rule of Civil Procedure 37(e), a court that finds electronically stored information was lost because a party failed to take reasonable steps to preserve it can order measures to cure the prejudice, and where it finds intent to deprive, can instruct a jury to presume the evidence was unfavorable. A retention schedule that runs on autopilot through a hold is worse than no schedule at all, because the automation makes the destruction look systematic.

Practically, that means your retention automation needs a switch: a documented way to freeze deletion for a defined scope of custodians and data types, a record of who was notified, and a release procedure.

What are the most common data retention mistakes?

  • Keeping everything indefinitely “just in case.” Every record past its floor is a discoverable document, a breach exposure and a privacy liability with no offsetting benefit.
  • Deleting from production but not from backups, warehouses and vendors. The obligation follows the copy.
  • Confusing the audit-workpaper rule with a corporate one. SOX’s seven years does not make seven years the answer for everything.
  • Applying the federal minimum in a state that requires more. Particularly in healthcare, where state periods routinely exceed the federal baseline.
  • Publishing a retention period you do not actually meet. Under CPRA and GDPR the notice is a commitment, and the gap between it and reality is the finding.
  • No legal-hold mechanism. Automated deletion with no override is a spoliation risk.
  • Shadow copies on personal devices. If you permit work on personal hardware, the policy needs remote-wipe rights on termination or loss, in writing, agreed in advance.
  • Treating anonymization as deletion without testing it. If the data can be re-identified with reasonable effort, it is still personal data and the ceiling still applies.

How do SOC 2 and ISO 27001 treat data retention?

Neither framework sets retention periods; both require you to have set them and to be following them. In a SOC 2 examination, retention shows up under the confidentiality criteria and the disposal controls — the auditor asks for the schedule, then samples records to confirm disposal actually happened on time. A Type II report covers a period, typically up to twelve months, so the evidence has to be continuous rather than assembled the week before fieldwork.

ISO 27001 handles it through Annex A controls on the classification, handling and secure disposal of information, and through the documented-information requirements of the management system itself. Enterprise security questionnaires ask the same question in plainer language: how long do you keep our data after the contract ends, and how do we get confirmation it was destroyed?

In all three cases the failure mode is identical. The policy exists; the disposal evidence does not.

How Compyl helps you manage data retention

Compyl maps retention obligations across the frameworks a business is actually subject to, so a single schedule can satisfy overlapping requirements rather than being rebuilt per audit. Retention periods, owners and legal bases live alongside the controls they support, evidence of disposal is collected continuously instead of at audit time, and changes in scope — a new state, a new framework, a customer contract with its own terms — surface as tasks against the schedule rather than as a discovery during fieldwork.

Book a demo to see how Compyl handles retention alongside the rest of your compliance program.

Data retention FAQs

How long do businesses have to keep records in the United States?

There is no single period. Payroll records run three years under the FLSA, OSHA injury logs five years, ERISA plan filing records six years, and audit workpapers seven years. Employee medical and exposure records run thirty years. The governing period for any given record is the longest one that applies to it across federal, state, sectoral and contractual rules.

What does GDPR say about data retention?

GDPR does not set periods. Article 5(1)(e) requires that personal data not be kept in identifiable form longer than necessary for the purpose it was collected for, and Articles 13 and 14 require you to disclose either the period or the criteria used to determine it. You choose the number and you have to be able to defend it.

Should a company have one retention policy or several?

One policy, one schedule, two documents. A single internal policy with a schedule covering every data category avoids contradictory rules between departments. A separate plain-language external statement covers the disclosure duties under GDPR and CPRA. Multiple internal policies per jurisdiction almost always drift out of sync.

Does a data deletion request override a legal retention requirement?

No. GDPR Article 17(3)(b) and equivalent provisions in U.S. state privacy laws allow you to retain data where processing is necessary to comply with a legal obligation. You keep the record, restrict its use to that purpose, and explain the basis to the requester.

How long should we keep security and access logs?

No general U.S. statute sets a period, so it is driven by framework and contract. PCI DSS requires at least twelve months of audit log history with three months immediately available for analysis. Beyond that, choose the period your incident response actually needs — investigations routinely reach back further than teams expect — and document the reasoning.

Does HIPAA require keeping medical records for six years?

No. The six-year rule in 45 CFR 164.316(b)(2)(i) applies to HIPAA compliance documentation — policies, procedures, risk analyzes, business associate agreements. Patient medical record retention is set by state law and ranges from around five years to well over a decade, with longer periods for minors.

What is the difference between a retention policy and a retention schedule?

The policy states the rules, roles and procedures. The schedule is the operational table: each data category, its retention period, the event that starts the clock, the legal basis, the owner and the disposal method. Auditors read the policy but test the schedule.

Is anonymized data still subject to retention limits?

Genuinely anonymized data falls outside GDPR entirely, because it is no longer personal data. The test is strict: if the individual can be re-identified with reasonable effort, including by combining the data with other information you hold, it is pseudonymized rather than anonymous and the storage limitation principle still applies.

What happens if we keep data longer than our privacy notice says?

The notice is a representation. Under CPRA the disclosed period or criteria is binding, and under GDPR an inaccurate Article 13 disclosure is a transparency failure on top of the storage limitation breach. Regulators have taken enforcement action on over-retention alone, without any breach or complaint about security.

By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies