A document retention policy defines which records your organisation keeps, why it keeps them, how long they remain necessary and who authorises disposal. The policy sets the rules; a retention schedule applies them to individual record categories.
The template below is a starting structure to adapt with your records, legal, privacy and business owners. It deliberately does not prescribe a universal duration. For software configuration after the policy is approved, see implementing retention in a DMS.
Document retention policy template
Purpose and scope
Define the business entities, locations, record categories and systems covered. Include paper records, email, shared drives, cloud applications, exported files and relevant copies on devices. Identify the authoritative copy when records exist in several places.
Ownership and responsibilities
Name the policy owner, the approver and the owners of each record category. Specify who maintains the schedule, applies technical settings, reviews exceptions and authorises disposal. Include a contact for questions and suspected mistakes.
Retention schedule
Complete a schedule entry for each category. The examples below show the questions to resolve; they are not legal retention periods.
| Record category | Trigger to define | Authority to verify | Owner and end action |
|---|---|---|---|
| Financial and tax records | The relevant filing, reporting or transaction event. | Applicable tax and accounting rules in the jurisdiction. | Finance; approved review or disposal action. |
| Contracts | Expiry, termination or another defined event. | Contractual, limitation and sector-specific requirements. | Legal or contract owner; review before disposal. |
| Employment records | The specific record’s event, such as the end of employment. | Employment, payroll and privacy requirements. | HR; restricted review and disposal. |
| Policies and approvals | Replacement, withdrawal or the end of the relevant process. | Business evidence needs and applicable sector rules. | Policy owner; controlled archive or disposal. |
For every completed entry, record the duration, the trigger definition, jurisdiction, source and date checked, business justification, system location, exception rules, approver and review date. Separate a minimum legal period from a justified decision to retain longer.
Preservation and exceptions
Define how a preservation instruction is issued, recorded, applied and released. It must identify affected records and custodians across systems. State how normal disposal is suspended, who can approve an exception and how unresolved cases are reviewed.
Disposal and evidence
Describe the approval and secure disposal process for each medium. Define the evidence retained after disposal and the handling of duplicates, exports and backups. Specify how an incorrect deletion is reported and how restoration is controlled.
Training and maintenance
Make the policy accessible to staff and contractors who handle records. Set a review interval and require a review after relevant legal, contractual, organisational or system changes. Record policy approval and version history.
Choose periods from the applicable rules
Names such as GDPR, HIPAA or a tax law are not interchangeable retention schedules. Determine whether a rule applies to the organisation and to the specific record. Ask the responsible legal or records owner to resolve conflicts before setting automatic disposal.
The European Commission’s GDPR guidance explains that personal-data retention must reflect purpose and legal obligations, with review or erasure limits. “Keep everything forever” is not a general-purpose solution.
For a concrete example of variation, IRS recordkeeping guidance distinguishes several US tax scenarios. A seven-year period mentioned there does not apply automatically to all business records or countries.
14-point policy review checklist
- Scope: all relevant entities, locations and record formats are named.
- Inventory: the team knows where authoritative records and copies reside.
- Owners: each record category has an accountable business owner.
- Jurisdiction: each schedule entry identifies the applicable legal context.
- Sources: obligations are documented with a source and review date.
- Triggers: each retention clock starts from an unambiguous event.
- Durations: the chosen period has an approved justification.
- Privacy: unnecessary personal-data retention is challenged.
- Preservation: the hold and exception process covers all relevant copies.
- Permissions: only authorised people can change rules or dispose of records.
- Disposal: approval, method and evidence are defined.
- Backups and devices: copy expiry and restoration are addressed.
- Training: users know how to classify records and report problems.
- Review: an owner, interval and change triggers keep the policy current.
Put the approved policy into operation
Folderit can help organise records with folders and metadata, control access, run policy approvals or acknowledgements, and apply configured retention actions. Keep the approved schedule distinct from the software settings so each rule can be traced to its authority.
For the practical steps—including start-date fields, folder inheritance and file exceptions—follow our document retention implementation guide. Verify the result with a small test set before enabling broad automated actions.