Business privacy
Customer Data Should Have an Expiration Plan
A practical approach to deciding what customer information to keep, when to review it, and how to make deletion part of everyday business.

A customer fills out a form, completes a purchase, or asks a question. The immediate task gets handled, but the information can remain in an inbox, spreadsheet, or export long after anyone remembers why it was collected. For a small business, privacy work can begin with a simple question: what is our plan for this information once its original job is finished?
A retention plan gives that question an owner and a repeatable answer. It does not require deleting everything on an arbitrary deadline. It means making deliberate decisions about the purpose, useful life, and eventual disposal of different records.
Start with the purpose, not the storage space
The Federal Trade Commission’s business guide recommends understanding what personal information a business holds, reducing unnecessary collection, and keeping sensitive information only while there is a legitimate need. It also recommends a written retention policy covering security, retention periods, and disposal.
One practical way to begin is to choose a single workflow: appointment requests, for example. Write down which fields arrive, who uses them, and where copies go. Ask whether each field helps complete the appointment process. If an optional free-text box regularly collects sensitive details the business does not need, consider replacing it with a narrower question.
Build a small, usable retention register
A simple register could have six columns: record category, business purpose, storage location, responsible person, review trigger, and disposal method. Use categories that your team recognizes, such as unsuccessful inquiries or completed support requests. Avoid a single rule that treats every file as interchangeable.
For each category, separate the operational reason for keeping it from any applicable legal or contractual requirement. Accounting records, unresolved disputes, and records subject to a preservation obligation may need different handling. Confirm those requirements with a qualified adviser before setting deletion dates. This article does not prescribe a universal retention period.
Include the copies people forget
Imagine an appointment request moving from a website into an inbox and then into a scheduling tool. Someone also downloads a spreadsheet to organize a busy week. Removing the request from the website does not answer what should happen to the email or downloaded file.
As a practical exercise, follow one ordinary record through its actual route. Include shared folders, attachments, exports, and service providers. Ask your providers how deletion works, what happens to backups, and whether restoring a backup could bring previously deleted information back into use. Document the answers and any limits; do not promise immediate erasure everywhere unless the process supports it.
Give review and deletion a real owner
A policy is easier to use when it names a role, rather than assuming someone will remember. That person can review records reaching their retention trigger, check for exceptions, and record that the agreed disposal process ran. A recurring calendar item can be a reasonable starting point before investing in automation.
Keep the review record proportionate. A log can identify the category, date, decision, and responsible role without reproducing the personal details being removed. If an exception is necessary, record why and when it will be reviewed again, so temporary extensions do not quietly become permanent storage.
Protect information while it remains
Retention decisions sit alongside security. The FTC’s Start with Security guide emphasizes limiting access to people who need it and securely disposing of information when it is no longer needed. Keeping fewer records does not eliminate the need to protect those that remain.
In practice, review who can open the relevant folder, who can export records, and what happens when a team member changes roles. Before disposal, use a method suitable for the medium and sensitivity of the information. Moving a file out of sight should not be treated as proof that every copy is gone.
Make one improvement this week
Choose one record category and complete its register entry. Verify the applicable requirements, assign an owner, and test the process on a small, appropriate set of records. Notice where the workflow is unclear and improve it before expanding. A modest process that people actually follow is a useful foundation for more consistent privacy practices.