A hold stops the cycle in its tracks
The Phase 1 answers use conditional logic to add the hold tasks when litigation is live and the paper and media steps only when they apply. Enforced step order keeps deletion locked until legal sign-off.
A retention policy alone does not meet the storage limitation principle. Records leaving your systems on time, with proof, does. This free data retention review checklist is for records managers, DPOs, compliance leads and system owners who run the periodic disposal cycle: yearly for most organisations, quarterly for high-volume systems such as CRM, support tickets and logs. Seven phases run from the schedule and a system-by-system inventory to a legal hold check, approval and secure deletion. The output is a signed disposal log, deletion evidence, an exceptions register and an updated schedule.
A retention schedule lists each class of record, the event that starts its clock and how long it is kept. A disposal review is the recurring job that applies it: find what has expired, confirm nothing must be preserved, get approval, delete it and keep the proof. Many organisations have the first and skip the second.
The review covers every record class, not only personal data. Accounting records, contracts, HR files and logs have periods set by tax, company or sector law. For personal data, Article 5(1)(e) of the GDPR adds a ceiling: identifiable no longer than the purpose needs. The schedule must satisfy both the minimum and the maximum.
Holds: record class, trigger event, retention period, the legal or business reason and the disposal method.
Owner: the records manager or DPO, approved by legal.
Changes: when the law, the business or a system changes.
Does: applies the schedule to what each system actually holds.
Cadence: yearly as a baseline, quarterly for systems that create records by the thousand.
Produces: an approved disposal list, deletion evidence and an exceptions register.
Triggered by: litigation, an investigation or a regulator’s enquiry that is pending or reasonably anticipated.
Effect: named records are frozen, whatever the schedule says.
Ends: only when legal releases it in writing.
Seven phases take one review cycle from the schedule to signed-off disposal. The legal hold and physical disposal steps depend on the Phase 1 answers.
The first task’s scope answers drive the conditional steps in Phases 4 and 6.
Legal confirms the hold position every cycle. The last four tasks appear only when Phase 1 records an active hold or expected litigation.
The paper and media tasks appear only when Phase 1 includes physical records or retired storage media.
Owned by the records manager or DPO; the report goes to the senior manager who owns the retention policy.
The table maps the rules this review most often has to satisfy to their source and to the phase that produces the evidence. GDPR article numbers are the same in the EU and UK texts unless shown otherwise. Which rules apply depends on your jurisdictions, sector and contracts, so treat the table as a starting point, not legal advice.
| Requirement | Source | What it asks | Evidenced in |
|---|---|---|---|
| Storage limitation | GDPR Art. 5(1)(e); UK research safeguards in Art. 84B | Personal data kept identifiable no longer than the purpose needs | Phases 2–3 |
| Right to erasure | GDPR Art. 17(1)(a); exceptions in Art. 17(3) | Erase without undue delay once data is no longer necessary, unless a legal obligation or legal claims require it | Phases 3–4 |
| Disclosed periods | GDPR Arts. 13(2)(a), 14(2)(a), 30(1)(f) | Tell people the period or the criteria that set it, and record time limits for erasure | Phases 1, 7 |
| Disclosed periods (California) | Cal. Civ. Code §1798.100(a)(3) | Disclose the period per category and keep no longer than reasonably necessary | Phases 1, 7 |
| Processor deletion | GDPR Art. 28(3)(g) | Delete or return at the end of the service, and delete existing copies unless law requires storage | Phases 2, 6 |
| Protection of records | ISO/IEC 27001:2022 Annex A 5.33 | Records protected from loss and destruction for as long as they are kept | Phases 1, 4–5 |
| Information deletion | ISO/IEC 27001:2022 Annex A 8.10 | Information deleted when it is no longer required | Phases 3, 6 |
| Equipment disposal | ISO/IEC 27001:2022 Annex A 7.14 | Storage media checked for sensitive data before disposal or re-use | Phase 6 |
| Media sanitisation | NIST SP 800-88 Rev. 2 | Clear, purge or destroy, verify the result and complete a certificate | Phase 6 |
| Preservation for litigation (US) | Federal Rules of Civil Procedure, Rule 37(e) | Reasonable steps to preserve electronically stored information once litigation is anticipated | Phase 4 |
Minimum periods need a source and a trigger. UK government guidance tells a limited company to keep its company and accounting records for 6 years from the end of the last company financial year they relate to, and longer in some cases, including when HMRC has started a compliance check into its Company Tax Return. The IRS tells US employers to keep employment tax records for at least 4 years after the tax becomes due or is paid, whichever is later.
Two things had changed at the time of review. NIST published SP 800-88 Rev. 2 in September 2025, replacing the 2014 Rev. 1. It keeps the clear, purge and destroy methods but leaves device-specific techniques to the IEEE 2883 series, so update any procedure that quotes the Rev. 1 tables. In the UK, the Data (Use and Access) Act 2025 amended Article 5(1)(e) from 5 February 2026 to point to the new research safeguards in Article 84B, and the ICO marks its storage limitation and erasure guidance as under review as a result.
The Phase 1 answers use conditional logic to add the hold tasks when litigation is live and the paper and media steps only when they apply. Enforced step order keeps deletion locked until legal sign-off.
The disposal list is a table inside the task. Purge reports, processor confirmations and certificates attach to the step they evidence, approvals are recorded, and the activity trail shows who completed each step and when.
A recurring schedule per system group reviews CRM and logs quarterly and the rest yearly, with Phase 2 assigned to system owners. Keep the schedule itself as a data set so every review starts from the current periods.
CheckFlow is not a records management system, a data discovery scanner or a deletion tool, and it does not certify destruction. It runs the review, routes the approvals and holds the evidence. CheckFlow’s recurring checklist software shows how reviews like this one start on time.
This checklist enforces retention. The GDPR Compliance Audit Checklist tests the wider privacy programme once a year. For Californian consumers, the CCPA/CPRA Compliance Checklist covers notice at collection and consumer requests.
No law sets a frequency. The ICO’s guidance says there is no firm rule, but you must be able to justify both your retention and how often you review it. Yearly is the common baseline, quarterly for high-volume systems such as CRM, ticketing and logging, plus a review before any system is migrated or retired.
The policy sets the principles: who owns retention, how periods are approved, how legal holds work and how disposal is evidenced. The schedule applies them, one line per record class with the trigger, period, reason and disposal method. The policy changes rarely; the schedule changes whenever the law or a system does.
No. Article 5(1)(e) sets a principle, not a number: keep personal data identifiable for no longer than the purpose needs. Periods come from other law such as tax and employment rules, from limitation periods for likely claims, and from genuine business need. You set them, justify them, disclose them under Articles 13 and 14, and apply them.
Not necessarily at once. The ICO’s erasure guidance accepts that data may remain in a backup until it is overwritten, provided it is put beyond use: held only until the backup is replaced on an established schedule and not used for any other purpose. So document each backup cycle in Phase 2, and make sure a restore does not bring deleted records back into live use.
For storage media, the sample certificate of sanitisation in NIST SP 800-88 Rev. 2 records the manufacturer, model and serial number, media type, method (clear, purge or destroy), technique, tool, verification method, and who verified it, when, with a signature. For paper, ask the contractor for the date, volume, method and a signature.
The hold wins: held records come off the disposal list and automated deletion pauses until legal releases the hold in writing. Under the GDPR, Article 17(3)(e) disapplies the right to erasure where processing is necessary for legal claims. In US federal courts, Rule 37(e) lets a court act where electronically stored information that should have been preserved in anticipation of litigation is lost through a failure to take reasonable steps.
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.