Data Retention & Disposal Review Checklist Template

Most retention schedules are approved once and never enforced. The policy says six years, while the CRM still holds every customer it ever had.

A retention policy alone does not meet the storage limitation principle. Records leaving your systems on time, with proof, does. This free data retention review checklist is for records managers, DPOs, compliance leads and system owners who run the periodic disposal cycle: yearly for most organisations, quarterly for high-volume systems such as CRM, support tickets and logs. Seven phases run from the schedule and a system-by-system inventory to a legal hold check, approval and secure deletion. The output is a signed disposal log, deletion evidence, an exceptions register and an updated schedule.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: September 2026

The Schedule Sets the Rule. The Review Enforces It.

A retention schedule lists each class of record, the event that starts its clock and how long it is kept. A disposal review is the recurring job that applies it: find what has expired, confirm nothing must be preserved, get approval, delete it and keep the proof. Many organisations have the first and skip the second.

The review covers every record class, not only personal data. Accounting records, contracts, HR files and logs have periods set by tax, company or sector law. For personal data, Article 5(1)(e) of the GDPR adds a ceiling: identifiable no longer than the purpose needs. The schedule must satisfy both the minimum and the maximum.

Retention schedule

The rule

Holds: record class, trigger event, retention period, the legal or business reason and the disposal method.

Owner: the records manager or DPO, approved by legal.

Changes: when the law, the business or a system changes.

Disposal review

The check

Does: applies the schedule to what each system actually holds.

Cadence: yearly as a baseline, quarterly for systems that create records by the thousand.

Produces: an approved disposal list, deletion evidence and an exceptions register.

Legal hold

The override

Triggered by: litigation, an investigation or a regulator’s enquiry that is pending or reasonably anticipated.

Effect: named records are frozen, whatever the schedule says.

Ends: only when legal releases it in writing.

What the Retention Review Checklist Covers

Seven phases take one review cycle from the schedule to signed-off disposal. The legal hold and physical disposal steps depend on the Phase 1 answers.

Phase 1

Phase 1: Scope & Schedule Baseline

The first task’s scope answers drive the conditional steps in Phases 4 and 6.

  • Set the review scope and answer the scope questions — record the review period and systems in scope, whether any legal hold is active or litigation expected, and whether paper records or retired media are included
  • Close out last cycle’s exceptions — confirm each deferred deletion and failed disposal from the previous review is resolved, with evidence
  • Confirm the approved version of the retention schedule — one current version with a named owner and an approval date, and no local copies in circulation
  • Check each period against current legal requirements — tax, company, employment and sector rules that changed since the last review, with the source cited against each record class
  • Confirm every schedule entry names a trigger event — a period means nothing until it says from when: contract end, last activity or the end of the financial year
Phase 2

Phase 2: System-by-System Records Inventory

  • List every system that holds records — business applications, SaaS tools, email, file shares, data warehouses, logs and archives, each with a named owner
  • Map each record class in each system to a schedule entry — data with no matching entry is orphaned and goes straight onto the exceptions register
  • Record how each system enforces retention — an automated deletion rule, a manual purge or nothing at all, with the configuration captured as evidence
  • Record the backup cycle for each system — how long deleted data survives in backups before it is overwritten
  • List processors and SaaS vendors holding copies — their contractual deletion or return duty under Article 28(3)(g) and how they confirm it
Phase 3

Phase 3: Records Past Retention

  • Run the expiry query in each system — records whose trigger date plus retention period has passed, by record class, count and date range
  • Test that automated deletion actually ran — sample records the rule should have removed since the last review and confirm they are gone
  • Sweep unstructured stores — file shares, mailboxes and collaboration sites, where last-modified date and owner are often the only practical filters
  • Separate records kept for archiving, research or statistics — longer retention only with the safeguards of Article 89(1), or Article 84B under the UK GDPR
  • Cross-check erasure requests received in the period — data no longer needed for its purpose must be erased on request under Article 17(1)(a), so requests and schedule should agree
Phase 4

Phase 4: Legal Hold Check

Legal confirms the hold position every cycle. The last four tasks appear only when Phase 1 records an active hold or expected litigation.

  • Get written confirmation of holds from legal — matters, custodians, record classes and date ranges, plus any open tax enquiry or regulator request
  • Match each hold against the disposal candidates — by custodian, matter, system and date range, not by record class alone
  • Pull held records off the disposal list and pause deletion rules — including automated jobs that would otherwise run before the hold is lifted
  • Notify custodians and system owners of the hold — a recorded acknowledgement from each, filed with the matter
  • Return released records to the schedule — once legal lifts a hold in writing, the records re-enter the next disposal cycle
Phase 5

Phase 5: Approval to Dispose

  • Compile the disposal list for each record owner — system, record class, date range, volume and the planned disposal method
  • Get record owner approval for each list — the owner confirms nothing on it still serves a live business purpose
  • Record every retention extension with a reason and a review date — a record kept past its period without a written justification is hard to defend under storage limitation
  • Obtain legal and compliance sign-off on the consolidated list — a dated approval before anything irreversible happens
Phase 6

Phase 6: Secure Deletion & Destruction

The paper and media tasks appear only when Phase 1 includes physical records or retired storage media.

  • Run the approved deletion in each system — keep the system’s own report of what was removed, with record counts that match the list
  • Put backup copies beyond use — no restore of deleted data except for recovery, and backups age out on their documented cycle
  • Instruct processors to delete and get written confirmation — for every SaaS vendor and outsourced provider on the list
  • Anonymise instead of deleting only where the aggregate still has value — confirm nobody can be identified, or it is still personal data
  • Destroy paper records through a confidential waste contractor — a certificate of destruction with date, volume and method for each collection
  • Hand retired storage media to IT for sanitisation — record the NIST SP 800-88 method used (clear, purge or destroy) and the certificate reference
Phase 7

Phase 7: Exceptions, Schedule Update & Sign-off

Owned by the records manager or DPO; the report goes to the senior manager who owns the retention policy.

  • Log every exception with an owner and a due date — systems that cannot delete, failed jobs, orphaned data and extensions without a reason
  • Update the retention schedule and issue a new version — new record classes, changed legal periods, and systems added or retired
  • Update privacy notices where periods changed — so what people are told matches what you now do
  • Report the cycle to management — volumes disposed by system, holds applied, exceptions open and decisions needed
  • Schedule the next review — yearly as a baseline, quarterly for high-volume systems, and after any system migration or retirement

Retention and Disposal Requirements Mapped to the Review

The table maps the rules this review most often has to satisfy to their source and to the phase that produces the evidence. GDPR article numbers are the same in the EU and UK texts unless shown otherwise. Which rules apply depends on your jurisdictions, sector and contracts, so treat the table as a starting point, not legal advice.

Requirement Source What it asks Evidenced in
Storage limitationGDPR Art. 5(1)(e); UK research safeguards in Art. 84BPersonal data kept identifiable no longer than the purpose needsPhases 2–3
Right to erasureGDPR Art. 17(1)(a); exceptions in Art. 17(3)Erase without undue delay once data is no longer necessary, unless a legal obligation or legal claims require itPhases 3–4
Disclosed periodsGDPR Arts. 13(2)(a), 14(2)(a), 30(1)(f)Tell people the period or the criteria that set it, and record time limits for erasurePhases 1, 7
Disclosed periods (California)Cal. Civ. Code §1798.100(a)(3)Disclose the period per category and keep no longer than reasonably necessaryPhases 1, 7
Processor deletionGDPR Art. 28(3)(g)Delete or return at the end of the service, and delete existing copies unless law requires storagePhases 2, 6
Protection of recordsISO/IEC 27001:2022 Annex A 5.33Records protected from loss and destruction for as long as they are keptPhases 1, 4–5
Information deletionISO/IEC 27001:2022 Annex A 8.10Information deleted when it is no longer requiredPhases 3, 6
Equipment disposalISO/IEC 27001:2022 Annex A 7.14Storage media checked for sensitive data before disposal or re-usePhase 6
Media sanitisationNIST SP 800-88 Rev. 2Clear, purge or destroy, verify the result and complete a certificatePhase 6
Preservation for litigation (US)Federal Rules of Civil Procedure, Rule 37(e)Reasonable steps to preserve electronically stored information once litigation is anticipatedPhase 4

Minimum periods need a source and a trigger. UK government guidance tells a limited company to keep its company and accounting records for 6 years from the end of the last company financial year they relate to, and longer in some cases, including when HMRC has started a compliance check into its Company Tax Return. The IRS tells US employers to keep employment tax records for at least 4 years after the tax becomes due or is paid, whichever is later.

Two things had changed at the time of review. NIST published SP 800-88 Rev. 2 in September 2025, replacing the 2014 Rev. 1. It keeps the clear, purge and destroy methods but leaves device-specific techniques to the IEEE 2883 series, so update any procedure that quotes the Rev. 1 tables. In the UK, the Data (Use and Access) Act 2025 amended Article 5(1)(e) from 5 February 2026 to point to the new research safeguards in Article 84B, and the ICO marks its storage limitation and erasure guidance as under review as a result.

Why Run Your Retention Review in CheckFlow?

1

A hold stops the cycle in its tracks

The Phase 1 answers use conditional logic to add the hold tasks when litigation is live and the paper and media steps only when they apply. Enforced step order keeps deletion locked until legal sign-off.

2

Proof of disposal on the step it proves

The disposal list is a table inside the task. Purge reports, processor confirmations and certificates attach to the step they evidence, approvals are recorded, and the activity trail shows who completed each step and when.

3

Quarterly systems, yearly everything else

A recurring schedule per system group reviews CRM and logs quarterly and the rest yearly, with Phase 2 assigned to system owners. Keep the schedule itself as a data set so every review starts from the current periods.

CheckFlow is not a records management system, a data discovery scanner or a deletion tool, and it does not certify destruction. It runs the review, routes the approvals and holds the evidence. CheckFlow’s recurring checklist software shows how reviews like this one start on time.

This checklist enforces retention. The GDPR Compliance Audit Checklist tests the wider privacy programme once a year. For Californian consumers, the CCPA/CPRA Compliance Checklist covers notice at collection and consumer requests.

Frequently Asked Questions

How often should data retention be reviewed?

+

No law sets a frequency. The ICO’s guidance says there is no firm rule, but you must be able to justify both your retention and how often you review it. Yearly is the common baseline, quarterly for high-volume systems such as CRM, ticketing and logging, plus a review before any system is migrated or retired.

What is the difference between a retention policy and a retention schedule?

+

The policy sets the principles: who owns retention, how periods are approved, how legal holds work and how disposal is evidenced. The schedule applies them, one line per record class with the trigger, period, reason and disposal method. The policy changes rarely; the schedule changes whenever the law or a system does.

Does the GDPR say how long we can keep personal data?

+

No. Article 5(1)(e) sets a principle, not a number: keep personal data identifiable for no longer than the purpose needs. Periods come from other law such as tax and employment rules, from limitation periods for likely claims, and from genuine business need. You set them, justify them, disclose them under Articles 13 and 14, and apply them.

Do we have to delete personal data from backups?

+

Not necessarily at once. The ICO’s erasure guidance accepts that data may remain in a backup until it is overwritten, provided it is put beyond use: held only until the backup is replaced on an established schedule and not used for any other purpose. So document each backup cycle in Phase 2, and make sure a restore does not bring deleted records back into live use.

What should a certificate of destruction include?

+

For storage media, the sample certificate of sanitisation in NIST SP 800-88 Rev. 2 records the manufacturer, model and serial number, media type, method (clear, purge or destroy), technique, tool, verification method, and who verified it, when, with a signature. For paper, ask the contractor for the date, volume, method and a signature.

What happens to scheduled deletion when a legal hold is in place?

+

The hold wins: held records come off the disposal list and automated deletion pauses until legal releases the hold in writing. Under the GDPR, Article 17(3)(e) disapplies the right to erasure where processing is necessary for legal claims. In US federal courts, Rule 37(e) lets a court act where electronically stored information that should have been preserved in anticipation of litigation is lost through a failure to take reasonable steps.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Show What You Deleted, When, and Who Approved It

Free trial — no credit card required.