| A data retention policy is a written rule setting how long each type of business record is kept, where it lives once it leaves daily use, who is allowed to delete it, and how that disposal is carried out. |
A director asks for the file on a job the company finished in 2019. It was on a server that got replaced in 2022. Most of the data came across. Nobody is certain which parts did not.
The same business is still holding the CVs of everyone who applied for a role in 2017, the bank account details of staff who left a decade ago, and a shared drive folder named Old Stuff that runs to 400 gigabytes.
Both of those come from the same gap. Nobody ever decided what the business keeps, for how long, or who is allowed to get rid of it.
Most New Zealand businesses do not have a data retention policy. They have a habit, which is to keep everything, delete nothing, and hope the item someone asks for is still there. Storage is cheap, so nobody has had to challenge the habit. What it costs shows up later, in a breach that reaches further than it had to, or a request nobody can answer.
This guide covers what a data retention policy has to define, why a backup will not satisfy a seven year obligation, what the New Zealand retention periods actually are, and how to dispose of data without creating a different problem.
What Is a Data Retention Policy?
A data retention policy is a governance document, usually a few pages and a table, that gives every category of information the business holds a defined lifespan. It sets the period, the storage, the authority to delete, and the disposal method for each one.
The scope of a data retention policy is wider than people expect. It covers email, the customer database, job and project files, payroll, CCTV footage, application forms from candidates you did not hire, call recordings, the CRM, the shared drive, and the folders sitting on individual laptops that nobody has looked at since the person who made them left.
Why do so few businesses have one?
Few businesses have a data retention policy because the risk of deleting is visible and the risk of keeping is not. Deleting a record carries a visible risk, because someone might want it later and you will be the person who authorised its destruction. Keeping it carries a risk that is real but invisible until a breach or an information request makes it concrete. People act on the visible risk, so the default became keep everything, and most businesses have never revisited that default.
That works while the volumes are small. It stops working once the business is holding two decades of personal information spread across systems nobody has audited, on a shared drive whose permissions were last reviewed by someone who no longer works there.
What a data retention policy is not
A data retention policy is not a filing structure, a backup schedule, or a security control. A filing structure organises your records, a backup copies them, and a security control protects them. None of the three sets a limit on how long a record should exist, and setting that limit is the job a data retention policy does. Documents that should have been destroyed in 2018 carry the same risk whether the folder tree they sit in is tidy or not.
Why Is Keeping Everything Forever a Liability?
Keeping everything forever is a liability because data you no longer need can still be breached, requested by the person it concerns, produced against you in a dispute, examined by a buyer during due diligence, or charged to you every month as storage you do not use. A data retention policy removes that exposure on a fixed schedule. Once a record is destroyed on time, it no longer exists to be taken.
Most businesses treat a data retention policy as nothing more than a set of minimum periods they have to meet. What it costs to hold data past the point of needing it rarely gets counted at all.
A breach reaches everything you are still holding
When an attacker gets to a file server, the size of the incident is set by what happens to be on it. A business holding nine years of customer records has a nine year breach, with every one of those customers to notify and nine years of material in the hands of whoever took it. The controls that stop data leaving the business in the first place are a separate discipline, and our guide to data loss prevention covers those.
The same business running a data retention policy that clears personal information at the end of its required period has a much smaller incident to deal with and far fewer people to notify.
Old data surfaces in disputes and information requests
Any individual can ask a business what personal information it holds about them, and the answer has to reflect what you actually hold. In a legal dispute, documents you hold can be required as evidence through the process lawyers call discovery. Both routes reach the draft nobody remembered, the email thread from a manager who left in 2020, and the file that should have been destroyed three years ago.
A defined retention period, applied consistently, means that material is legitimately gone before anyone asks. Deleting it once a request or a dispute has arrived is a different matter altogether and can amount to an offence.
Old data shows up when you sell the business
Buyers run due diligence on your data. An investor or a bank will ask what personal information you hold, how it is protected, and whether you are meeting your Privacy Act obligations. If you are holding two decades of customer records with no policy behind them, expect the buyer to want warranties, adjust the price, or require you to clean it up before settlement.
Most owners find this out partway through a transaction, when there is no time to fix it properly and the other side is setting the deadlines.
What does keeping data too long actually cost?
Keeping data past its purpose costs money every month. Cloud backup and archiving are commonly priced per gigabyte per month, so every terabyte you carry unnecessarily is a line on a bill that renews forever, and Microsoft 365 charges for additional storage once you pass the included allowance.
Migrations are where it becomes obvious. Businesses pay to move data they should have destroyed, pay again to store it in the new system, and pay a third time in the project hours spent sorting it. Enforcing a data retention policy before a migration is one of the few IT decisions that takes cost out of a project instead of adding it.
Is a Backup the Same as an Archive?
No. A backup is a short cycle copy taken so the business can recover after a failure. An archive is a long term store of completed records, indexed so it can be searched, held for a defined period. Most backup systems overwrite themselves on a rotation measured in weeks or months.
Almost every business we talk to has this wrong, and it is an expensive thing to have wrong. A business running a ninety day backup rotation believes it is covered for seven years. It is covered for ninety days.

A backup gets called on at nine on a Monday morning after a server failure or a ransomware attack, and what you want is to be back where you were on Friday. An archive gets used years later, when an auditor or a lawyer asks you to produce a record as it stood at the time. A data retention policy has to specify both: the rotation length for recovery, and the retention period for the record.
Backup vs archive: how a data retention policy treats each
| Backup | Archive | |
|---|---|---|
| Purpose | Recover after failure, corruption or ransomware | Produce a completed record on request |
| Typical retention | 30 to 90 days on rotation | 6, 7 or 10 years, set by the obligation |
| Searchable | No, usually a whole system image | Yes, indexed by record |
| Restore unit | An entire server or system | A single document |
| Used when | A server fails on a Monday morning | An auditor or lawyer asks, years later |
| Priced for | Speed of recovery | Cheap long term storage |
Why the rotation catches people out
A backup fails as a long term archive in four ways:
- The rotation has already overwritten that point in time, so the version you want was cycled out years ago.
- The backup is an image of a whole system and not a searchable index, so finding one invoice means restoring an entire server first.
- The application that could read the file is no longer installed anywhere in the business.
- The file format itself may no longer open in any software you currently run.
An archive has to outlive the software that created it. Most backup arrangements cannot do that. A data retention policy needs both systems. They are built for different jobs. Our guide to backup as a service covers the recovery half of the pair.
How Long Do New Zealand Businesses Have to Keep Records?
New Zealand businesses must keep most core business and tax records for at least seven years, and employment records for at least six years. The periods come from separate Acts, so a data retention policy that applies a flat seven years to everything is close but not correct.
The main New Zealand retention periods
| Record type | Minimum period | Source |
|---|---|---|
| Income tax, GST and supporting business records | 7 years | Tax Administration Act 1994 |
| Company minutes, resolutions, shareholder communications, financial statements, accounting records | 7 years | Companies Act 1993, section 189 |
| PAYE and payroll records supporting tax returns | 7 years | Tax Administration Act 1994 |
| Wages and time records | 6 years | Employment Relations Act 2000, section 130 |
| Holiday and leave records | 6 years | Holidays Act 2003, section 81 |
| Personal information with no other retention obligation | No longer than the purpose requires | Privacy Act 2020, Principle 9 |
Tax and company records
Inland Revenue requires business records to be kept for at least seven years under the Tax Administration Act 1994. That covers income and expense records, GST, and the documentation behind your returns. Where a taxpayer is under audit or investigation, the Commissioner can require records to be retained for up to three further years beyond the seven. The obligation survives the business closing, so a company that ceases trading in 2026 is still accountable for records into the 2030s.
The Companies Act 1993 sets its own seven year requirement for company records, covering minutes of directors’ meetings and resolutions, written communications sent to shareholders, financial statements, and the accounting records for the last seven completed accounting periods.
Employment records
Wages and time records under the Employment Relations Act 2000 and holiday and leave records under the Holidays Act 2003 must be kept for six years, and that applies to former employees as well as current staff. Employment New Zealand sets out the detail of what those record keeping obligations cover.
One caution before you act on the six. Payroll data usually does double duty, because the same figures support your PAYE and income tax position, and that pulls them under the seven year tax obligation. In practice most businesses hold payroll at seven years for tax purposes while treating six as the employment law floor. Check which of your employment records are also tax records before you set a period in your data retention policy.
This is also the one area with published penalties, which is useful if you need to make the case internally. A Labour Inspector can issue an infringement notice of $1,000 per record keeping offence, up to $20,000 in fees within a three month period. The Employment Relations Authority can order penalties of up to $10,000 per breach against an individual and up to $20,000 against a company. Applied per employee, a record keeping failure across a small team becomes an expensive one quickly.
How long can you keep personal information under the Privacy Act?
Information Privacy Principle 9 of the Privacy Act 2020 provides that an agency must not keep personal information for longer than it is required for the purpose for which the information may lawfully be used. Principle 9 sets a maximum. Tax and company law set minimums. A record covered by both must be kept for at least the statutory minimum, then destroyed once the purpose that justified holding it has ended.
Holding a candidate’s application from 2017 breaches that principle. So does keeping former employees’ bank details after the payroll and tax obligations have run out, and retaining customer records for a relationship that ended a decade ago. Our NZ Privacy Act compliance guide covers the wider obligations the Act places on a business.
A workable data retention policy holds each record for as long as the law requires and disposes of it once that period ends.
Confirm your own periods
The periods above are the general New Zealand requirements and they are the starting point for your own data retention policy, not the finish line. Industry regulation, professional obligations, client contracts, insurance conditions, and claims that can arrive years after the work all add periods of their own, and some run considerably longer than seven years. Confirm your retention periods with your accountant or lawyer before you write them into a data retention policy and start deleting against them. This guide is practical direction for owners and managers and it is not legal advice.
What Should a Data Retention Policy Contain?
A data retention policy defines six things for every category of record: the record type, how long it is kept, where it lives, who can delete it, how it is destroyed, and who owns the decision. Anything less leaves a gap that gets filled by whatever an individual staff member decides on the day.
- Record type. Categories that mean something to your business, such as financial records, employment files, client project files, marketing contact lists, and CCTV. Ten to twenty categories is usually enough.
- Retention period. How long the category is held, and from when. The trigger date matters as much as the number. Seven years from the end of the financial year is a different date from seven years from when the document was created.
- Where it lives. Which system holds the record in active use, and which archive it moves to afterwards.
- Who can delete it. A named role. Deletion rights granted broadly across the business mean the data retention policy will not hold.
- How it is destroyed. The disposal method for each category and each medium, covering live systems, archives, backups, and physical media.
- Who owns the decision. One person accountable for the data retention policy being reviewed and followed. Without a named owner it gets written once and never applied.

In practice this fits on a page. Ten or fifteen rows in a table, with a named owner at the bottom, is a policy a business will actually keep up to date.
Where Should Archived Data Be Stored?
Archived data should sit in dedicated long term storage that is indexed, access controlled, separate from your live systems, and cheaper per gigabyte than the storage your business runs on daily. Cloud archive tiers are built for exactly this and are priced accordingly.
A data retention policy moves records through three stages:
- Active. In daily use, sitting on fast storage inside your working systems.
- Archived. Out of daily use but still inside its retention period, moved to slow, cheap, indexed storage.
- Expired. Past its retention period and due for documented destruction.
Will you be able to read it in ten years?
A record stays readable in ten years only if it is held in a format that does not depend on the application that created it. A proprietary format is readable only while you still run the software that made it, and a seven year archive will outlast at least one system change.
Where a record needs to survive independently, export it. PDF/A is a version of PDF designed specifically for long term archiving, and plain text or CSV will outlive most database formats. Your data retention policy should require a test retrieval once a year. Until you have restored something from the archive, you do not know that you can.
What about old email and former staff mailboxes?
Email is where retention problems concentrate. It holds a copy of nearly everything and almost never appears in the data retention policy. Former staff mailboxes get left active for years, personal archive files sit forgotten on individual laptops, and shared mailboxes accumulate without an owner. A workable rule is to export a departing staff member’s mailbox to the archive and remove the licence within 30 to 90 days of them leaving, then hold the exported mailbox for whatever period the underlying records require.
A system change is usually when all of it comes to light. Old mailboxes and orphaned archives are a standard discovery during an email migration, which makes it a good moment to apply a retention decision instead of moving the problem across intact.
How Do You Delete Data Securely?
You delete data securely by matching the method to the medium: a purge function in live systems, verified deletion in cloud services, a secure wipe or physical destruction for drives, and cross cut shredding for paper. Pressing delete in an operating system only removes the pointer to a file, and the contents stay on the disk until something else writes over them.
- Live systems. Use the deletion the application provides and confirm it purges the record rather than hiding it from the interface.
- Cloud services. Check what the provider does with deleted data and how long it lingers in their own recovery layers.
- Physical drives. Secure wipe to a recognised overwriting standard, or physical destruction with a certificate from the destruction provider.
- Paper. Cross cut shredding, or collection by a secure document destruction service that issues a certificate.
What happens to deleted data in backups?
Deleting a record from a live system does not remove it from the backups already taken. Those copies age out on their own rotation, so there is a window where the data is gone from production and still recoverable from backup.
Handle it by documenting the position honestly. Record the backup rotation length in the data retention policy, state that expired records persist in backups until the rotation completes, and confirm they are not selectively restored. Trying to surgically remove individual records from historical backups is impractical and usually damages the backup.
Who is allowed to delete company records?
Deletion authority belongs to named roles, and every disposal gets logged with what was destroyed, when, under which data retention policy rule, and by whom. That log is your evidence the disposal was deliberate. Without it, a planned destruction and an accidental data loss look the same afterwards.
The same access controls that decide who can reach a record also decide who can destroy it, so deletion rights should be reviewed whenever access rights are.
The legal hold exception
Where litigation, an investigation, or a regulatory request is underway or reasonably anticipated, scheduled destruction stops for anything relevant. This overrides every other rule in the data retention policy. Destroying material once the business knows a dispute is coming carries serious consequences, so the data retention policy needs a written legal hold clause naming who can invoke it and how the affected records are frozen.
How Do You Put a Data Retention Policy in Place?
Putting a data retention policy in place runs in six steps: inventory every system holding records, group what you find into categories, set a period for each with your advisers, decide where each category lives and moves to, name who can authorise deletion, and automate enforcement where the systems allow it.
- Inventory every system holding records. Servers, cloud services, email, the CRM, payroll, backups, and physical files.
- Group what you find into categories. Ten to twenty categories that mean something to your business.
- Set a retention period for each with your accountant or lawyer, and record the trigger date as well as the number of years.
- Decide where each category lives in active use and which archive it moves to.
- Name who can authorise deletion for each category, and how each disposal is logged.
- Automate enforcement with retention labels in Microsoft 365, lifecycle rules in cloud storage, and archive settings in your line of business applications.
The inventory is the step businesses skip, and it decides whether the rest of the work holds up. You cannot set a period for data you have not found. Most businesses turn up several systems they had forgotten and a volume of data well beyond what they estimated.
Step six matters more than it looks. A data retention policy that depends on someone manually clearing folders every quarter tends to lapse within the year, while one enforced by retention labels and lifecycle rules keeps running whether anyone remembers it or not.
Review it annually, and again whenever you change a major system. A data retention policy usually fails because it describes an environment the business no longer runs.
Where businesses get stuck
Businesses get stuck at the first deletion. Writing the data retention policy is straightforward enough. What stalls it is putting your name against the destruction of something real.
The way through is to start where the risk of keeping is clearly higher than the risk of deleting. Unsuccessful job applications, marketing lists nobody has used in years, former staff personal details past their obligation period, and CCTV footage beyond its retention window. Clear those, log the disposals, and the harder categories become easier to approve.
Get Your Data Retention Policy Sorted
The business in the opening cannot produce a file from 2019 and cannot account for 400 gigabytes it has no use for. Both of those trace back to the same missing decision. A data retention policy makes that decision once, in advance, for every category of record you hold.
Every year of data you are holding past its purpose is storage you are paying for, breach exposure you do not need, and material that can be requested or produced against you.
Exodesk builds and runs data retention policies for South Island businesses. That means an inventory of what you are actually holding, retention periods mapped against your obligations, archive storage that is genuinely separate from your backup, automated enforcement in Microsoft 365 and the systems you already run, and disposal that is documented properly. Your accountant or lawyer confirms the periods. Our job is making sure your systems can actually meet them and that the deletion happens.
We have supported Christchurch, Dunedin, and wider South Island businesses since 1989. This can run as part of our managed IT services or as a standalone piece of work if your IT is already handled.
Tell us how many years of data you think you are holding, and we will tell you what we find. The number is usually higher. You can also connect with us on LinkedIn.
Frequently Asked Questions
What is a data retention policy?
A data retention policy sets how long every category of information a business holds will be kept, where it moves to once it leaves active use, which role may delete it, and the method used to destroy it. Without one, staff default to keeping everything indefinitely.
Is a data retention policy a legal requirement in New Zealand?
New Zealand law does not require a business to hold a document titled data retention policy. The underlying obligations are compulsory, including the seven year record keeping requirements under the Tax Administration Act 1994 and Companies Act 1993, the six year employment record requirements, and the Privacy Act 2020 duty not to keep personal information longer than needed. Employment record keeping failures carry infringement fees of $1,000 per offence and Authority penalties of up to $20,000 against a company. A written data retention policy is how most businesses demonstrate they are meeting all of those consistently.
How long do New Zealand businesses have to keep records?
Core business records carry a seven year minimum in New Zealand. Inland Revenue requires business and tax records to be kept for at least seven years under the Tax Administration Act 1994, and the Companies Act 1993 sets seven years for minutes, resolutions, shareholder communications, financial statements, and accounting records. Employment records sit at six years. Confirm the periods that apply to your own business with your accountant or lawyer.
How long must employment records be kept in New Zealand?
Wages and time records under the Employment Relations Act 2000, and holiday and leave records under the Holidays Act 2003, must be kept for six years, covering former employees as well as current staff. Payroll figures that also support PAYE and income tax returns fall under the seven year tax obligation, so many businesses hold payroll records for seven years to cover both.
How long should unsuccessful job applications be kept?
Recruitment records for candidates who were not hired have no fixed statutory retention period in New Zealand, so Privacy Principle 9 governs them. Most employers keep unsuccessful applications for six to twelve months to cover any personal grievance or discrimination complaint arising from the recruitment process, then dispose of them. Holding CVs for years afterwards without a stated purpose is a common Privacy Act breach.
How long should CCTV footage be kept?
CCTV footage is personal information under the Privacy Act 2020 and carries no fixed statutory period, so retention is governed by the purpose it was collected for. Most businesses retain footage for somewhere between seven and thirty days on an automatic overwrite cycle, keeping individual clips longer only where an incident is under investigation. The retention window should be stated in the data retention policy and in the CCTV notice.
Is a backup the same as an archive?
No. Backups and archives do different jobs. A backup is a recent copy taken so the business can recover after a failure, and it typically overwrites itself on a rotation of weeks or months. An archive is a long term, indexed store of completed records held for a defined retention period. A business relying on backup rotation to meet a seven year obligation will find the copy it needs was overwritten years ago.
Can a backup satisfy a seven year retention requirement?
No. Backup rotations almost never satisfy a seven year requirement. The data is overwritten on cycle, the backup is an image of a system rather than a searchable index, and the application needed to read the file may no longer exist by the time the record is requested. Long term obligations need a purpose built archive running alongside the backup.
What does Privacy Principle 9 require?
Information Privacy Principle 9 of the Privacy Act 2020 provides that an agency must not keep personal information for longer than it is required for the purpose for which the information may lawfully be used. It operates as an upper limit, where tax and company obligations set minimums. Holding old job applications, former employee details, or lapsed customer records past their purpose breaches the principle.
Why is keeping data forever a risk?
Data held past its purpose remains exposed to every risk the business faces. A breach reaches whatever is stored, so nine years of customer records produces a nine year incident and nine years of people to notify. Old data is also discoverable in litigation and must be produced in response to a privacy request, including material the business had forgotten it held.
Do small businesses need a data retention policy?
Yes. Small businesses carry the same record keeping and Privacy Act obligations as large ones, with no exemption based on headcount or turnover. A small business data retention policy is correspondingly small, often a single table of categories and periods with one named owner. The practical argument is stronger for small teams, because there is no records department and the obligation sits with people who already have other jobs.
What if we delete something and later need it?
Retention periods are set to outlast the realistic window in which a record is needed, which is why they are confirmed with an accountant or lawyer before anything is deleted. Most businesses begin with categories where the risk of keeping clearly exceeds the risk of deleting, such as unsuccessful job applications and lapsed marketing lists. A legal hold clause also stops scheduled destruction whenever a dispute or investigation is underway or anticipated.
Can New Zealand business records be stored overseas?
Business records can generally be held in offshore cloud services, though Inland Revenue has specific requirements about records stored outside New Zealand and the Privacy Act 2020 places conditions on sending personal information overseas. Many Christchurch and Dunedin businesses prefer archive storage hosted in New Zealand or Australia for latency, sovereignty, and simpler compliance. Confirm your position with your accountant before committing records to an offshore archive.
What should a data retention policy include?
A complete data retention policy defines six elements for each record category: the record type, how long it is retained and from what trigger date, where it is stored in active use and in archive, which named role can authorise deletion, the destruction method for each medium, and the person accountable for the data retention policy overall. A legal hold clause suspending destruction during litigation or investigation is also required.
How do you delete business data securely?
Secure disposal means the information cannot be reconstructed. Live systems should use a purge function rather than a delete that only hides the record, cloud services need checking for how long deleted data persists in provider recovery layers, and physical drives require a secure wipe to a recognised standard or physical destruction with a certificate. Paper records need cross cut shredding or a secure document destruction service.
What happens to data in backups after it is deleted?
Deletion from a live system does not remove copies already captured in backups. Those copies age out naturally as the backup rotation completes, creating a window where a record is gone from production but still recoverable. Good practice is to document this in the data retention policy, state the rotation length, and confirm expired records are not selectively restored, because surgically editing historical backups is impractical.
What is a legal hold?
A legal hold suspends scheduled destruction of records relevant to litigation, an investigation, or a regulatory request that is underway or reasonably anticipated. It overrides every other rule in the data retention policy for the affected material. Destroying documents once the business knows a dispute is coming carries serious consequences, so the data retention policy should name who can invoke a hold and how the records are frozen.
Where should archived business data be stored?
Archived data belongs in dedicated long term storage that is indexed, access controlled, separate from live systems, and cheaper per gigabyte than daily use storage. Cloud archive tiers are designed for this and priced for it. Records that need to survive a change of system should be exported to durable formats such as PDF/A, and the archive should be test restored annually.
How often should a data retention policy be reviewed?
A data retention policy should be reviewed at least annually, and whenever the business changes a major system, adds a service that holds personal information, or sees a change in its regulatory obligations. A data retention policy usually fails by describing systems the business no longer runs. An annual review with the person named as policy owner keeps the document matched to the actual environment.
Where should a business start with data retention?
The first step is an inventory of every system holding business records, covering servers, cloud services, email, the CRM, payroll, backups, and physical files. Most businesses discover systems they had forgotten and far more data than expected. Categories and retention periods follow, then automated enforcement through tools such as Microsoft 365 retention labels and cloud storage lifecycle rules.

