A retention policy sets how long records are kept and when they are destroyed. It reduces storage cost, limits the discovery burden, and is entirely defensible — provided two things are true.

It is applied consistently. Selective destruction, or a policy honoured only when convenient, is worse than none. It invites the argument that deletion was purposeful.

It stops on a hold. The moment litigation is reasonably anticipated, automated deletion must be suspended for the affected material. This is a technical step, not an instruction to staff: email expiry, messaging platform retention, backup rotation and device-retirement processes each have to be paused by someone with administrative access. Nearly every serious spoliation finding involves a policy that continued running after the duty attached.

What a good policy covers: categories of record with retention periods tied to legal and regulatory requirements rather than to habit; the systems each category lives in, including messaging platforms and personal devices used for work; who owns the process; and the hold procedure with named responsibility for executing it.

What to avoid: periods so short they conflict with statutory retention obligations; a policy that exists on paper while systems retain everything forever, which produces the discovery burden without the benefit; and a hold process that depends on one person remembering.