How to use this page. HI Tech Hui is an IT and cybersecurity firm — not a law firm or an accounting firm — so this page does not tell you how long to keep any specific record, and it is not a data retention policy. It is a starter checklist of questions to bring to your CPA or attorney, who can confirm the retention periods that actually apply to your industry, your state, your insurance requirements, and your contracts. Check the boxes as you gather answers, then use the answers to build the actual policy with your advisor.

Published · HI Tech Hui · ~6 min read · Tick the boxes as you go — your progress is saved in this browser.

Why old data is a liability, not an asset

Keeping everything forever feels cautious, but it works against you. Data with no active business or legal purpose cannot make you money — it can only be stolen, leaked, or subpoenaed. Every account, spreadsheet, and backup full of old customer and financial records is more surface area for an attacker, and more material a court can demand in a dispute that has nothing to do with why the data was collected. The security term for the fix is data minimization: keep what you need, for as long as you actually need it, on purpose — and get rid of the rest deliberately instead of by accident.

The part that actually requires a professional is deciding how long is long enough. That answer changes by record type, industry, state, insurer, and contract terms, which is exactly why this is a checklist of questions rather than a set of answers.

1. Financial & tax records

The IRS generally advises keeping records that support a tax return for three years from filing, extending to six years if income was underreported by more than 25%, seven years for a bad-debt or worthless-securities deduction, and indefinitely if a return was never filed or was fraudulent. Employment tax records carry a separate four-year minimum. These are general federal starting points, not your final answer — ask your CPA to confirm what applies to you.

2. Customer & sales records

A customer record with no active relationship, warranty period, or legal hold attached is usually the easiest category to reduce — and often the largest.

3. Employee & HR records

Employment records tend to have the longest and most fragmented retention rules of any category, because federal, state, and insurance requirements overlap.

4. Industry-specific & regulated data

If your business touches healthcare, payments, insurance, or another regulated space, general rules of thumb stop applying and specific frameworks take over.

5. Where the data actually lives

A retention decision only matters if it reaches every place the data was copied to. This is the part your IT provider can help execute once the retention periods are decided.

6. Writing it down

Once you have real answers from your CPA and attorney, the last step is putting them in writing — but that document should come from them, shaped around your specific business, not from a generic template.


The one habit that matters most

You do not need a perfect answer today. You need to stop the default of "keep everything because deleting things feels risky." Every piece of customer or financial data sitting around with no active purpose is doing nothing for your business except waiting to be part of a breach notification. The businesses that handle this well are not the ones with the longest retention policy — they are the ones who actually know what they are holding, why, and for how long, because they had the conversation above with someone qualified to answer it.

The pattern to watch for

If you cannot name, off the top of your head, roughly how old your oldest customer record is or where your last five years of financial exports actually live, that is the signal to have this conversation sooner rather than later — before a breach, an audit, or a subpoena forces the question.

Related reading


Want help figuring out where your customer and financial data actually lives, or executing a retention schedule once your CPA and attorney confirm it? HI Tech Hui provides managed IT, cybersecurity, and 24/7 monitoring through our in-house SOC for Hawaii businesses. Call (808) 206-8549, email info@hitechhui.com, or schedule a discovery call. We are at 401 Kamakee St Suite 206, Honolulu, HI 96814.

This page is educational and general in nature. It is not legal, tax, or accounting advice, and HI Tech Hui does not provide legal, tax, or compliance determinations. Retention requirements vary by industry, state, insurer, and contract — confirm the specifics that apply to your business with your own CPA and attorney. Federal retention figures referenced above come from the IRS and HIPAA Journal.

Ready when you are

Let’s scope your IT & security plan.

Talk with a Honolulu-based engineer about managed IT, cybersecurity, or a 24/7 SOC handoff. We’ll review your current environment, identify the highest-impact gaps, and outline a clear next step — with no obligation.

HI Tech Hui team