Short answer: a property-management retention register should identify each record class, business and legal owner, source system, property scope, sensitivity, authoritative retention rule, trigger date, minimum and maximum period, access, legal-hold status, disposal method, approval, and proof. The schedule must be built from applicable requirements, not copied from a generic internet table.
The FTC advises businesses to keep only information they legitimately need and to use a written policy describing what is retained, how it is protected, how long it is kept, and how it is securely disposed. NIST SP 800-88 Rev. 2 addresses media sanitization based on information sensitivity. U.S. federal civil procedure also addresses preservation failures involving electronically stored information, but duties and remedies depend on the facts and jurisdiction. This independent register is educational and is not legal, tax, accounting, privacy, discovery, or records-management advice.
Inventory record classes, not random files
Group leases, applications, screening records, notices, payments, ledgers, statements, invoices, work orders, inspections, photos, communications, access logs, keys, insurance, tax records, vendor files, employment records, and system logs. Name the system of record and responsible owner for each class.
Record the authority behind every period
Identify the statute, regulation, contract, accounting policy, insurer requirement, litigation instruction, or approved business need that supports the period. Record jurisdiction and reviewer. Avoid presenting one duration as valid for every state, country, property type, entity, or record.
Define the trigger and full lifecycle
A period is ambiguous without a trigger such as application decision, lease termination, transaction close, work completion, contract end, tax-year close, or account closure. Map active use, archive, restricted access, hold, eligible-disposal review, and verified destruction.
Know where copies and exports live
Record primary storage, backups, email, shared drives, mobile devices, vendor systems, integrations, exports, and paper files. The software data export and exit checklist helps identify portable records that may outlive the platform that created them.
Download the retention and hold register
Download the editable document retention and legal-hold register (CSV). It includes record classes, authority, jurisdiction, trigger, period, locations, sensitivity, access, holds, disposal approval, sanitization, proof, and periodic review.
Apply holds without destroying the schedule
When qualified authority issues a preservation instruction, record the matter, scope, custodians, systems, start time, notice, acknowledgment, collection method, access, and release authority. Suspend ordinary disposal only for the affected material. Keep the underlying schedule so normal disposition can resume after an authorized release.
Protect retained records proportionately
Limit collection and access, separate sensitive categories, use appropriate encryption and authentication, preserve audit events, and review vendor handling. Use the security and access-control checklist to connect record sensitivity to roles, devices, integrations, backups, and incident response.
Dispose through an approved method
Deleting a visible file may not sanitize the underlying media or every managed copy. Match the method to the medium, sensitivity, reuse decision, provider capability, and approved policy. Record who approved disposal, what was included, when it occurred, and what evidence was retained.
Prevent automation from overriding a hold
Retention jobs, mailbox rules, storage lifecycle policies, account deletion, and vendor cleanup can remove records automatically. Test hold precedence and exception alerts. Route unexplained deletions or missing evidence through the incident communication and recovery checklist.
Review the schedule as operations change
Review at a defined cadence and after a new jurisdiction, property type, service, vendor, regulation, lawsuit, merger, or software migration. Keep version history and approval evidence. A schedule no one updates becomes a false promise rather than a control.
Frequently asked questions
Can software decide the legal retention period automatically?
Software can apply an approved rule, calculate dates, preserve holds, and report exceptions. Qualified people must determine which authority and rule apply.
Should every record be kept forever to be safe?
No. Indefinite retention can increase privacy, security, discovery, and operating risk. Use documented requirements, holds, approved disposal, and qualified review.
Official references
- FTC: Protecting Personal Information, retention policy guidance
- NIST SP 800-88 Rev. 2: Guidelines for Media Sanitization
- U.S. Courts: Federal Rules of Civil Procedure