The short answer

Set retention rules by record purpose and applicable business requirements. The software team should implement an agreed policy, not choose retention periods on its own.

Prepared with AI assistance. These are practical scoping recommendations; examples are illustrative, not client results.

Inventory the data

Identify customer records, attachments, activity history, exports, and backups. Different copies may serve different purposes and have different access paths. Ask the responsible business owners and advisers to establish any contractual or legal requirements before a deletion or archival schedule is designed.

Separate archive from deletion

Archiving can remove a record from active work while preserving controlled access. Deletion has different consequences. Define what each action means for linked records and reporting. Avoid a generic delete button that leaves users uncertain about whether information can be restored or remains available elsewhere.

Include generated copies

Exports, temporary files, notifications, and backups can retain information outside the main record. Ask the implementation team to document their lifecycle and limitations. A policy that only covers the primary table may not describe how the system actually handles the data.

Test the operating procedure

Use approved test records to exercise archive, retrieval, and deletion behavior. Verify authorization and the evidence retained about the action. Review the result with the policy owner. This guide is a scoping framework; specific retention periods and legal obligations require decisions grounded in the business's actual circumstances.