Data retention and legal hold: what to keep and what to purge
Keeping every email forever feels safe and is actually liability. A plain-English guide to retention schedules and legal hold for small business.
· Jake Schaaf, Founder of Atticus Rowan
Somewhere in your Microsoft 365 tenant is an email from 2013. It is a half-joking complaint about a customer, written by an employee who left 8 years ago, sitting in a shared mailbox nobody has opened since. If your company is ever sued, that email is discoverable. Your attorneys will have to review it, at hourly rates, along with several hundred thousand of its neighbors. Keeping it bought you nothing. It is pure downside, aging quietly in storage you also pay for.
Most small businesses run a retention policy of “keep everything forever” without ever choosing it. Deleting things feels risky, storage feels cheap and nobody owns the question. But hoarded data is not safety. It is 3 kinds of liability:
- Discovery liability. In litigation, whatever exists must be searched, reviewed and produced. Review costs scale with volume. A decade of unmanaged mailboxes is a 6-figure review bill waiting for a lawsuit to activate it.
- Breach liability. When ransomware or a mailbox compromise hits, the blast radius is everything you kept. The 2013 mailbox full of customer details becomes part of the breach notification. You cannot lose what you no longer hold.
- Cost and clutter. SharePoint quotas, backup windows and migration projects all grow with the pile. Every future IT project is slower because of data nobody needs.
The fix is not aggressive deletion. It is a written schedule, applied automatically, with a working pause button for litigation. Here is the plain-English version.
Step 1: define categories, not files
Nobody can make retention decisions file by file. Workable schedules group information into a handful of categories with a keep-period each. For a typical 10-50 person business:
- Financial and tax records. Commonly kept 7 years, driven by tax audit windows
- Contracts and agreements. Term of the contract plus several years after it ends
- Employment and HR records. Statutory periods vary by record type and state
- Email. A chosen business period, commonly 3 to 7 years, unless a specific regulation says otherwise
- Project and client files. A period after project close that matches how often you genuinely revisit them
- Everything else. The default bucket, with a shorter period
The exact numbers are not an IT decision. Tax records, HR files and industry rules have real legal requirements behind them, and this is the part where your attorney and accountant earn their fees: they set the periods, we implement them. What Atticus Rowan brings is the map of where the data actually lives and the tooling to enforce whatever schedule counsel approves. Treat this article as implementation guidance, not legal advice.
If you serve regulated customers, expect their security questionnaires to ask directly: “Do you have a documented data retention policy?” A written schedule turns that from an awkward blank into a yes.
Step 2: write it down, 2 pages maximum
A retention policy nobody reads is a policy nobody follows. The written version needs only:
- The categories and their keep-periods
- Where each category lives (email, SharePoint, the accounting platform, paper)
- Who owns the policy and when it gets reviewed (annually is fine)
- The legal hold procedure, covered below
Resist the 30-page template. In a dispute, a court compares your policy to your practice. A short policy you actually follow is far stronger than an impressive one you ignore, because a policy you demonstrably ignore reads as evidence against you.
Step 3: automate it in Microsoft 365
Habits do not delete email on schedule. Policies do. Microsoft 365 Business Premium and most business tiers include retention policies that apply your schedule automatically:
- Retention policies apply keep-and-then-delete rules to mail, SharePoint, OneDrive and Teams by location or organization-wide
- Retention labels handle the exceptions, letting you tag contracts or financial records with longer periods than the default
- Deletion after the retention period is automatic, consistent and logged, which is exactly what “defensible” means: the 2013 email was deleted because a documented schedule said so, not because someone chose to delete it the week a dispute started
Two cautions from the field. First, retention policies are compliance tools, not backup. They control lifecycle, they do not protect you from tenant-level disasters or give you point-in-time restore. That distinction, and why it matters, is the subject of our Microsoft 365 backup guide. Align the 2: a backup that keeps everything for 10 years quietly defeats a 3-year retention schedule.
Second, your schedule only covers data you know about. The customer list living in a free SaaS tool someone signed up for in 2021 is subject to no policy at all. A shadow IT inventory is a prerequisite for honest retention, because you cannot manage the lifecycle of data you have not found.
Legal hold, in plain English
Legal hold is the pause button, and misunderstanding it is the most expensive mistake in this whole topic.
The rule: when litigation is filed or reasonably anticipated (a demand letter arrives, a dispute is clearly heading to lawyers, an employee threatens a claim), you must preserve potentially relevant information. Preservation overrides your deletion schedule immediately. Courts can and do sanction companies for information that was destroyed after the duty to preserve began, even when the deletion was just an automated policy running as designed.
The mechanics in Microsoft 365 are straightforward:
- Litigation hold on relevant mailboxes preserves everything in them, including items users delete, invisibly to the user
- eDiscovery holds can preserve targeted SharePoint sites, OneDrive accounts and Teams content
- Holds take precedence over retention policies automatically. The schedule keeps running everywhere else, deletion simply stops for held content
Your 2-page policy needs 4 sentences on this: who can declare a hold (typically an owner plus counsel), who implements it in the tenant, how fast (same day) and that the hold stays until counsel releases it in writing. Then rehearse it once. A hold that takes 3 weeks to implement because nobody knew the admin console is a hold that failed.
The payoff
A company with a written schedule, automated enforcement and a working hold procedure gets concrete returns: smaller discovery bills, smaller breach notifications, cleaner questionnaire answers, cheaper storage and migrations, and a defensible story when a court asks why a document no longer exists.
None of this requires new software for most Microsoft 365 businesses. It requires decisions from counsel, about 2 pages of writing and a few hours of configuration.
Atticus Rowan implements retention and hold for small businesses as part of security-first Microsoft 365 management: mapping where your data lives, configuring the policies counsel approves and making sure backup and retention are not working against each other. If your current retention policy is “keep everything and hope,” we can fix that.
Related insights
More on Operations & OT →September 11, 2026
Choosing practice management software: the security questions that matter
The platform that will hold every client record deserves more scrutiny than the sales demo gave it. Here are the questions to ask before you sign.
September 9, 2026
Stop emailing client files: secure exchange for professional practices
Tax documents and case files still travel as email attachments. Here is how a 5 to 50 person practice standardizes one secure channel without losing clients along the way.
September 4, 2026
The Windows 7 box running your CNC: legacy systems on the plant floor
When the controller PC cannot be upgraded and cannot be replaced, you still have 4 real options. Here is how to rank them honestly.