Ten years of passports in a shared drive
The firm has been running for years. Every closed file is still on the server or in the cloud: passport scans, bank statements, payslips, medical letters, children's birth certificates. Some belong to clients who were refused and never came back. Some belong to people who have long since left the country. Nobody has deleted anything, because nobody is sure what is safe to delete.
Then a laptop is lost, or an old account is compromised, and the question becomes how much sensitive data was exposed. The honest answer is: far more than the firm needed to keep.
Deletion feels riskier than keeping
Most firms have a retention policy on paper. What they lack is a way to apply it. Files are closed but not dated consistently, documents sit in several places (the case system, email, shared drives, WhatsApp), and there is no list of files due for review.
There is also real caution. Clients come back years later, complaints can arise, and a partner worries that the one file deleted will be the one needed. So the default becomes keeping everything, which quietly grows the firm's exposure every year.
Nobody has the job, either. Retention sits between the principal, whoever handles data protection and the caseworkers, and without a named owner and a monthly list, it is always something to deal with next quarter.
What keeping everything costs
| Issue | Effect |
|---|---|
| Sensitive data accumulates | More harm if systems are breached |
| No schedule applied | Retention policy exists only on paper |
| Documents spread across systems | Deletion in one place leaves copies elsewhere |
| Subject access requests | Slow searches through years of files |
| Storage and backup | Growing costs for data nobody uses |
Staff time is affected too. When a former client asks what the firm holds about them, or asks for something to be deleted, the search covers every system and every year, and it is done by hand.
How we put your retention schedule into practice
- Your firm decides the retention periods per type of matter and document, with whoever leads data protection. We do not set them.
- We map where client documents are stored, including the case management system, email, shared drives and messaging, and record each closed matter's closing date.
- Each closed matter gets a review date calculated from your schedule, and a monthly list shows the matters due.
- A named person reviews each due matter and chooses: delete, keep for a stated reason, or keep specific documents only. Nothing is deleted without that decision.
- Approved deletions are carried out across the stores we can reach through their APIs, and a record is kept of what was deleted, when and on whose authority, without keeping the content.
- Matters flagged to keep get a new review date, so an extension is a decision, not a default.
Where a store cannot be reached automatically, the review list tells your team exactly what to remove by hand.
Less data, less exposure
The firm holds what it has decided to hold and can say why. Old sensitive documents stop piling up. Subject access requests are faster because there is less to search. And if something does go wrong, the impact is smaller.
Staff also gain clarity. Instead of wondering whether they are allowed to delete an old file, they follow a process with a named decision-maker, and the reasons for keeping or removing anything are written down.
Is this your file store?
- No closed files have ever been deleted
- Your retention policy has never been applied in practice
- Client documents are held in several systems
- Nobody is sure which files are safe to remove
- Searching old files for a request takes days