
Most businesses think carefully about what data they collect.
Very few think about when to delete it. Customer records accumulate across CRMs, email platforms and archived files — sitting there long after the customer relationship has ended and long after the data serves any purpose.
Under the Australian Privacy Act 1988, holding personal data longer than necessary is not a neutral decision. It is a compliance risk.
What Is a Data Retention Policy?
A Data Retention Policy defines how long a business keeps different types of personal information before deleting or de-identifying it. Most Australian businesses do not have one. Without it, data accumulates by default; not by design. Every piece of personal information stored in a system that is past its useful life is unnecessary exposure to a breach, an Individual Rights request or a regulatory investigation.
Under the Australian Privacy Act, businesses are required to take reasonable steps to manage personal information that is no longer needed for the purpose it was collected.
How Long Should You Keep Customer Data?
Retention periods depend on the type of data and the purpose for which it was collected. Some have legally defined minimums:
- Financial and tax records — generally seven years
- Employee records — seven years after employment ends
- Health records — varies by state, often seven years minimum
Outside of these, the test is straightforward: if the data is no longer needed for the purpose it was collected, it should be deleted or de-identified. Keeping it because it might be useful some time in the future does not meet that standard.
The Risks of Holding Data Too Long
Unnecessary data creates risk in three ways. It increases breach exposure — every additional record sitting in a system is one more that can be compromised in a security event.
It complicates Individual Rights requests, the more data a business holds, and the longer it has held it, the harder and more expensive it is to locate, assess and action a deletion request accurately. And it creates direct compliance exposure — holding data beyond its required retention period without a lawful basis is a privacy failure under Australian law, not just poor practice.
With the upcoming December 2026 Privacy Act amendments strengthening enforcement powers, regulators are paying closer attention to how businesses manage the full lifecycle of personal data — not just how they collect it. The businesses with clear retention policies already in place are the ones best positioned when a request arrives, or a regulator comes looking.
Good data governance starts with knowing what you hold, why you hold it, and when it should be deleted.





