
Most small businesses keep everything forever, and that's a liability. Every old mailbox, every archived project folder, every ex-employee's OneDrive is data an attacker can steal and a plaintiff can subpoena.
A retention policy fixes both problems by deciding, in advance, what gets kept and what gets deleted. The rules are less complicated than people assume. The hard part isn't knowing them — it's enforcing them.
How long do you have to keep business records?
Keep tax records three years, employment tax records four years, and payroll records three years. Those are the federal floors for most small businesses. Your industry and your state add more on top, and a few rules run the other way by requiring you to delete data after a set period.
Here's the schedule most small businesses can start from, with the rule behind each line:
- Tax returns and supporting records — 3 years. The IRS says to keep records for 3 years by default. Stretch to 6 years "if you do not report income that you should report, and it is more than 25% of the gross income shown on your return," and 7 years for a worthless-securities or bad-debt claim. Keep them indefinitely if you never filed or filed a fraudulent return. The clock starts at the filing date, or two years from the date you paid the tax, whichever is later.
- Employment tax records — 4 years. The IRS says to keep all records of employment taxes for at least four years after filing the fourth quarter for the year.
- Payroll records — 3 years. The FLSA requires employers to preserve for at least three years payroll records, collective bargaining agreements, and sales and purchase records. Time cards, wage-rate tables and work schedules are 2 years.
- HIPAA Security Rule documentation — 6 years. Policies, procedures, risk analyses and assessments, held six years from creation or from the date last in effect, whichever is later. Not patient charts. More on that below.
- Customer information under the FTC Safeguards Rule — delete at 2 years. This one is a ceiling, not a floor. Covered financial institutions must "securely dispose of customer information no later than two years after your most recent use of it to serve the customer," absent a legitimate business or legal need to keep it. See the FTC's Safeguards Rule guidance.
- Client and patient files — state law. Set by your state and your professional body, not by federal rule. Get the number from your attorney and write it down.
- Contracts — term plus your state's statute of limitations on written contracts. That period differs by state, including across the states we serve, so get the number for yours from your attorney rather than assuming a default. The trigger is the end of the contract, not the signing date.
- General email — 3 to 7 years. No law sets this. Pick a number that covers the records living inside your mailboxes and apply it uniformly.
Treat that as a starting draft, not legal advice. What we can tell you is whether your systems will actually do what the policy says.
The HIPAA rule everyone gets backwards
HIPAA's six-year rule covers your Security Rule documentation, not patient charts. People get this backwards constantly.
HHS requires a covered entity to retain that documentation "until six years after the later of: 1) the date of the document's creation or 2) the date the document was last in effect," at 45 CFR 164.316(b)(2)(i). That means your written policies, your risk analysis, your training records.
The medical record itself is a different question with a different answer. HHS is explicit: "the HIPAA Privacy Rule does not include medical record retention requirements," and "State laws generally govern how long medical records are to be retained."
Other regulated industries have their own clocks. Registered investment advisers and broker-dealers answer to SEC and FINRA books-and-records rules.
Firms handling cardholder data have PCI DSS, which pushes toward storing less. Law firms answer to state bar rules on client files.
Why keeping everything is a security problem
Data you deleted can't be stolen.
Think about what's sitting in a ten-year-old mailbox at a typical firm. Bank details, signed contracts, scanned IDs, salary discussions, medical notes from an accommodation request. None of it is in use, and all of it is in scope when someone phishes that account.
Breach notification laws make this concrete. Under laws like the NY SHIELD Act, your notification obligation turns on the private information that was actually exposed. Records you'd already deleted aren't exposed and don't trigger anything.
Every year of data you hold past its useful life is another year of notification exposure you're carrying for no return.
Litigation works the same way. Anything you still have is discoverable.
Deleting on a published schedule, consistently, is defensible. The federal rule on lost electronically stored information, FRCP 37(e), turns on whether you took reasonable steps to preserve once litigation was anticipated.
Deleting after you get the preservation letter is a much worse day than handing over the documents would have been.
What goes in the policy
A workable retention policy is short. It needs five things:
- Categories. Tax and financial, employment and HR, client or patient records, email, contracts, marketing. Six to ten buckets, not forty.
- A period for each, with the rule or business reason it comes from.
- A trigger. Retention clocks start somewhere: date created, date the contract ended, date the employee left. Say which.
- A legal-hold process. One named person who can suspend deletion when litigation is anticipated, and a method that actually stops the automated deletion.
- An owner and a review date. A policy nobody owns is a document, not a control.
Write it once, have your attorney read it, then stop editing it. The value is in enforcement, not in the wording.
How to enforce it in Microsoft 365
Microsoft 365 can do this natively, and in the assessments we run it's usually switched off.
Purview retention policies cover Exchange mailboxes, SharePoint sites, OneDrive accounts and Teams messages. They run whether or not the user cooperates.
Microsoft's documentation is blunt about the mechanism. If someone edits or deletes covered content, "a copy of the content is automatically retained" — in the Preservation Hold library for SharePoint and OneDrive, and in the Recoverable Items folder for Exchange. Emptying Deleted Items doesn't defeat it.
Three things to get right when you set these up:
- Retain and delete are one setting. A retention policy that only retains is an archive. If you never set the delete action, you've made the problem permanent.
- Retention isn't backup. They solve different problems and you need both. We've written about why Microsoft 365 needs its own backup: retention holds data against a policy clock, backup restores it after something goes wrong.
- Test the legal hold before you need it. Put a hold on a test mailbox, try to delete something, confirm it survives. Find out now, not during a lawsuit.
Retention labels handle the rest: the contracts and records that need a different clock than the mailbox they live in. That's the part worth spending time on.
Where this usually breaks
Departed employees are the first failure. The retention policy covers the mailbox, then someone deletes the account to save a license and the data goes with it.
The opposite happens just as often: the account sits active and licensed for three years because nobody wants to be the one who deleted it. Neither is a plan. Convert to a shared mailbox or apply an inactive-mailbox hold, and write the step into your offboarding checklist.
The second failure is data outside Microsoft 365. The QuickBooks file, the practice management system, the shared drive on the old server, the personal Dropbox someone set up in 2019.
A retention policy that only covers email is covering a fraction of the problem. Inventory where the data actually lives first — data loss prevention and retention both depend on knowing that.
Then there's hardware. Retention ends at disposal, and a wiped drive with a certificate behind it is the last step of the policy, not a separate errand. Our hardware lifecycle management work exists mostly because that step gets skipped.
Frequently asked questions
Is a data retention policy legally required for a small business?
No federal law requires every business to have a written retention policy. Industry rules are a different matter. HIPAA, SEC and FINRA books-and-records rules, PCI DSS, the FTC Safeguards Rule and state data-security laws each impose retention or disposal duties on the businesses they cover. If any apply to you, a written policy is how you show you're meeting them.
How long should we keep employee emails after someone leaves?
Long enough to cover the records inside the mailbox, which for most small businesses means matching your general email period of three to seven years. Convert the mailbox to a shared mailbox or make it an inactive mailbox with a hold rather than deleting the account, so the retention policy keeps running on it.
Does deleting old data hurt us if we get sued?
Not if you deleted it on schedule before you had reason to expect litigation. Consistent enforcement of a published policy is the defense. Deleting after you anticipate a claim is a different thing entirely, which is why the legal-hold step matters more than the retention periods do.
Is Microsoft 365 retention the same as backup?
No. Retention governs how long data is kept and when it's deleted. Backup gives you a restorable copy after ransomware, a bad migration or a mistake. Retention won't restore a corrupted SharePoint site, and backup won't prove to a regulator that you enforce a deletion schedule.
Where do we start if we've never done this?
Inventory first. List every system holding business data and who owns it. In the assessments we run, three or four forgotten systems is typical. Set retention on email and files after that, then work through the rest.
Get the retention question settled
If you're not sure what your systems are currently keeping, or whether Microsoft 365 retention is switched on at all, that's a short conversation and worth having before it matters.
The NetSys Group has supported small businesses across New York, New Jersey, Connecticut, Pennsylvania and Southwest Florida since 1998. Contact us for a complimentary assessment and we'll show you what's actually being retained today and where the gaps are, or see the full range of what we cover on our services page.
Turn insight into action.
Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.



