Document Retention Schedules: overview

Document Retention Tables: a guide for companies and how to automate them

R2 Docuo is the Document Management System used by everyone from SMEs to large companies to organise, automate and control the Document Retention Tables in their organisation.

SEE DOCUMENT MANAGEMENT SYSTEM

 

Document Retention Tables (DRTs), also known in English as records retention schedules, are an archival instrument defined by the ISAD-G standard (General International Standard Archival Description) used to control the lifecycle of documents in an organisation.

Without a DRT, your company either destroys documents too early or keeps them indefinitely, with the legal and cost risk that entails. R2 Docuo is a Document Management System that automates their application.

Understanding Document Retention Tables

Business activity generates different documents day after day: invoices, contracts, minutes and so on. These are created, used and later stored or destroyed, but how long should we keep each type of document?

Archival practice advises separating documents into current, intermediate and historical archives, according to their category and how much need there is to preserve them:

  • The Current Archive. Contains active and recent documents, used regularly in day-to-day operations and needing frequent access.
  • The Intermediate Archive. Contains documents that are still in force but do not relate to recent operations, and are therefore used less often.
  • The Historical Archive. Contains documents that are obsolete or relate to past operations, but which have to be preserved for legal, compliance or analytical reasons.

To implement a Document Retention Table successfully, you first have to draw up a Document Classification Chart (DCC) that uniquely identifies the category or type of each document.

You also have to assess how important each of those document types is to the organisation’s activity, through a Document Valuation Table (DVT).

The Document Retention Table establishes how long each type of document must remain in each archive, and when its lifecycle ends and it must be destroyed.

With the DCC and the DVT done, you then have to define the retention periods for each type of document in each archive, in both physical and electronic format, and what happens at the end of its lifecycle (the destruction procedure). This information is summarised in what is known as the organisation’s Document Retention Table (DRT).

Document Retention Table

Implementing DRTs with Document Management Software

Keeping a manual record of the archive periods for every document can be an extremely laborious task. That is why using a document management system is the best option for covering every need relating to document retention.

The best way to implement an organisation’s Document Retention Tables is to use Document Management Software.

Document Management Software has specific features that make this task easier and allow an organisation’s DRT to be implemented automatically.

For that reason, managing document retention manually, although possible, is falling out of use because of how laborious it is.

Why do I need to implement a Document Retention Table?

Many countries have written into their legal framework the obligation to comply with Document Retention Tables defined by the state, for all public organisations and for private ones carrying out public functions.

Beyond the legal necessity of that case, implementing a document retention table can bring many benefits to your organisation, specifically all those that come from not destroying documents while they are still needed, nor storing them for longer than necessary.

Document Retention Tables and data protection

For years, document retention was understood as an archiving matter: how much space documents take up and when they can be thrown away. The General Data Protection Regulation (GDPR) changed the framing and turned the retention period into a legal obligation.

Its Article 5.1(e) sets out the principle of storage limitation: personal data shall be kept “for no longer than is necessary for the purposes for which the personal data are processed”. Put another way, keeping a document containing personal data beyond what its purpose justifies is not caution, it is a breach.

Keeping things “just in case” is no longer an option: since the GDPR, every type of document needs a justified, written retention period. That written document is the Document Retention Table.

This makes the DRT more than good archival practice: it is the documentary evidence with which an organisation demonstrates that it has thought, type by type, about how long it keeps information and why. In an inspection, “we had not defined it” and “we have it defined here” are two very different positions.

You do not choose the period: the applicable rule sets it

The most common mistake when drawing up a DRT is setting a single period for the whole organisation. In reality, each document type answers to a different rule, and often to several at once. Some examples from the Spanish framework:

  • Commercial documentation: Article 30 of the Spanish Commercial Code requires books, correspondence and supporting documents to be kept for six years.
  • Tax documentation: the General Tax Act sets the general limitation period at four years (Article 66), counted from the end of the filing period.
  • Anti-money laundering: Act 10/2010 requires due diligence documentation to be kept for ten years.
  • Employment and social security documentation: four years, in line with the limitation periods for infringements in the social order.

When the same document falls under several rules, the longest period wins. And if a document type has no legal period assigned to it, it has to be justified by its business purpose, not left indefinite by default.

A useful DRT does not say “contracts are kept for ten years”. It says which rule imposes that period, from what date it is counted and what happens when it expires.

Blocking is not the same as destroying

There is a nuance that tends to get overlooked and that is worth reflecting in the DRT. Article 32 of the LOPDGDD (Spanish Organic Act 3/2018) introduces the concept of data blocking: when a piece of data is deleted but liabilities may still arise from it, it is not simply erased. Instead it is kept blocked, accessible only in order to respond to judges, courts or the competent authorities.

In practice, this means the lifecycle of many documents does not have two states (in force / destroyed) but three: in force, blocked and destroyed. A DRT that does not allow for the blocking period forces you to choose between deleting too early and keeping things too long, which are exactly the two risks you set out to avoid.

Assessing risk, not just the retention period

The Document Valuation Table usually limits itself to measuring how important each type of document is to the business. It is worth extending it with a second dimension: risk.

For each document type it is worth answering three questions:

  • What would be the consequences of this document being disclosed without authorisation, for the organisation and for the people whose data it contains?
  • What would be the consequences of losing it?
  • What would be the consequences of it being altered without anyone noticing?

The answers are not a theoretical exercise: they determine the security measures that have to be applied to that category (permissions, encryption, traceability, backups), and they feed directly into the impact assessment required by Article 35 of the GDPR when processing entails a high risk.

Two documents can have the same retention period and need completely different security measures. The period is set by the DRT; the level of protection, by the risk assessment.

It also has a valuable side effect: it forces teams to be aware of what information they are handling. A good share of security incidents do not come from a sophisticated attack, but from someone who did not know that particular spreadsheet was sensitive.

How to apply a DRT automatically

Defining the Document Retention Table is half the job. The other half is making sure it enforces itself, without anyone having to remember.

In a Document Management System, applying a DRT consists of defining a workflow for each document category and including archiving and destruction as further steps within it. Once the category is configured, the system acts on its own when the document reaches the established age:

  • If the document is digital only, it can be purged automatically when the period expires.
  • If there is a paper original, the system cannot destroy it: it alerts the person responsible for the archive so that they can do it and record the disposal.
  • If a blocking period applies, the document changes state and restricts its permissions instead of disappearing.

The step most often forgotten is the last one: keeping a record of the destruction. A log of what was deleted, when, under which rule and who authorised it. Without that trail, the organisation cannot demonstrate that it complied with its own policy, and a DRT you cannot demonstrate is not worth much.

The goal is not just to destroy on time, but to be able to prove that you destroyed on time and in accordance with a written rule.

Automated this way, document retention stops depending on somebody reviewing folders once a year and becomes a property of the system itself.