Data Retention Starter Checklist
Questions to bring to your accountant or attorney before deciding how long to keep old customer and financial data — not a policy, just the prep work for that conversation.
Published · HI Tech Hui · ~6 min read · Tick the boxes as you go — your progress is saved in this browser.
Why old data is a liability, not an asset
Keeping everything forever feels cautious, but it works against you. Data with no active business or legal purpose cannot make you money — it can only be stolen, leaked, or subpoenaed. Every account, spreadsheet, and backup full of old customer and financial records is more surface area for an attacker, and more material a court can demand in a dispute that has nothing to do with why the data was collected. The security term for the fix is data minimization: keep what you need, for as long as you actually need it, on purpose — and get rid of the rest deliberately instead of by accident.
The part that actually requires a professional is deciding how long is long enough. That answer changes by record type, industry, state, insurer, and contract terms, which is exactly why this is a checklist of questions rather than a set of answers.
1. Financial & tax records
The IRS generally advises keeping records that support a tax return for three years from filing, extending to six years if income was underreported by more than 25%, seven years for a bad-debt or worthless-securities deduction, and indefinitely if a return was never filed or was fraudulent. Employment tax records carry a separate four-year minimum. These are general federal starting points, not your final answer — ask your CPA to confirm what applies to you.
2. Customer & sales records
A customer record with no active relationship, warranty period, or legal hold attached is usually the easiest category to reduce — and often the largest.
3. Employee & HR records
Employment records tend to have the longest and most fragmented retention rules of any category, because federal, state, and insurance requirements overlap.
4. Industry-specific & regulated data
If your business touches healthcare, payments, insurance, or another regulated space, general rules of thumb stop applying and specific frameworks take over.
5. Where the data actually lives
A retention decision only matters if it reaches every place the data was copied to. This is the part your IT provider can help execute once the retention periods are decided.
6. Writing it down
Once you have real answers from your CPA and attorney, the last step is putting them in writing — but that document should come from them, shaped around your specific business, not from a generic template.
The one habit that matters most
You do not need a perfect answer today. You need to stop the default of "keep everything because deleting things feels risky." Every piece of customer or financial data sitting around with no active purpose is doing nothing for your business except waiting to be part of a breach notification. The businesses that handle this well are not the ones with the longest retention policy — they are the ones who actually know what they are holding, why, and for how long, because they had the conversation above with someone qualified to answer it.
The pattern to watch for
If you cannot name, off the top of your head, roughly how old your oldest customer record is or where your last five years of financial exports actually live, that is the signal to have this conversation sooner rather than later — before a breach, an audit, or a subpoena forces the question.
Related reading
- Which compliance framework actually applies to your Hawaii business?
- HIPAA IT controls for Hawaii medical practices in 2026
- Vishing Scams: Team Training — scam-call scripts for your next team meeting
- Hawaii ransomware recovery: the first 72 hours
Want help figuring out where your customer and financial data actually lives, or executing a retention schedule once your CPA and attorney confirm it? HI Tech Hui provides managed IT, cybersecurity, and 24/7 monitoring through our in-house SOC for Hawaii businesses. Call (808) 206-8549, email info@hitechhui.com, or schedule a discovery call. We are at 401 Kamakee St Suite 206, Honolulu, HI 96814.
This page is educational and general in nature. It is not legal, tax, or accounting advice, and HI Tech Hui does not provide legal, tax, or compliance determinations. Retention requirements vary by industry, state, insurer, and contract — confirm the specifics that apply to your business with your own CPA and attorney. Federal retention figures referenced above come from the IRS and HIPAA Journal.
Let’s scope your IT & security plan.
Talk with a Honolulu-based engineer about managed IT, cybersecurity, or a 24/7 SOC handoff. We’ll review your current environment, identify the highest-impact gaps, and outline a clear next step — with no obligation.