CRM Basics
Data retention & deletion policy
How long should you keep customer data, and when should you delete it? A plain, practical guide to setting retention periods and deleting data properly.
Most businesses are careful about collecting customer data and almost careless about getting rid of it. Records pile up for years: old leads who never replied, invoices from customers who moved on, call notes nobody will ever open again. A clear data retention policy is really just one decision, made once and written down: how long do you keep each kind of information, and when do you delete it?
This article is about that decision: how to think about retention periods, how to delete data properly, and what to do the moment a customer says "erase me." It is deliberately general and practical, not a summary of any one country's law, so it works whether you run a two-person agency or a growing sales team.
What a retention policy is, and why "keep everything" backfires
A retention policy answers one question for every category of data you hold: how long does this need to live, and what happens to it when the time is up? It is a short internal rule, not a legal essay.
The instinct to keep everything forever feels safe. It isn't. Old data is a quiet liability on four fronts:
- Risk. Every record you store is something that can leak in a breach. Data you deleted last year cannot be stolen this year.
- Cost. Storage is cheap, but messy storage is expensive in time: searches slow down, exports get bigger, and staff wade through dead records to find a live one.
- Accuracy. A contact list that is largely stale makes your reporting lie to you. Deleting or archiving dead data makes the rest more trustworthy.
- Obligation. In many places you are expected to keep data only as long as you have a genuine reason to. "We might need it someday" is not a reason that tends to hold up.
The principle behind every rule: purpose
You don't set retention periods by guessing a number. You set them by asking what the data is for. When the purpose ends, the clock starts.
A customer's phone number exists so you can serve and support them. While they are an active customer, that purpose is live and you keep it. Once they go cold, the original purpose is gone; and unless another reason applies (an unpaid invoice, a legal record you must keep, an ongoing marketing consent), the number should eventually go too.
This is why one phone number can have two clocks attached. The contact record might be due for deletion, while the invoice it appears on must stay for years, because tax and commercial rules in most countries require keeping accounting records. Retention is rarely one number for the whole customer; it is a set of clocks running in parallel.
How long is long enough? Think in categories, not customers
The practical move is to stop treating "the customer's data" as one lump and split it into categories, each with its own rule. Most small businesses have five or six that matter.
- Contact and lead records. Tie these to activity. A common approach is to review or delete leads with no engagement for a set window — say two or three years — rather than holding them forever.
- Invoices and accounting records. These usually have the longest clock, because tax law in most countries sets a minimum period. Check your local requirement and treat it as a floor.
- Marketing consent and communications. Keep these only while the consent is valid; when someone unsubscribes, keep just enough to remember not to contact them, and drop the rest.
- Support tickets and call notes. Useful for a while after a case closes, rarely useful for years. A shorter window fits most teams.
The data lifecycle, from first contact to deletion
It helps to picture any piece of data moving through four stages. Most records get stuck at stage two and never leave — exactly the problem a policy fixes.
The stages are simple. You collect data for a stated purpose and put it to active use while that purpose is live. When active use ends, the record enters a retention window — a defined period where you keep it for a secondary reason (records, warranty, legal minimums) but no longer touch it day to day. When that window closes, you delete or anonymize it.
Drawing it this way forces an exit. In a CRM, that is where the way contacts, companies and deals connect starts to matter: deleting a contact should not silently break the invoice or deal it was attached to, so you decide up front what happens to the links.
Three ways to "delete", and when each one fits
"Delete" is not a single action. There are three, and choosing the wrong one is a common mistake.
- Soft delete hides a record from everyday views but keeps it in the system, usually in a recycle bin or archive. It guards against fat-finger mistakes, but the data is still there, so it is not real erasure.
- Hard delete removes the record for good — what people usually mean by deletion, and what you need once the retention window has genuinely closed.
- Anonymization strips out everything that identifies a person while keeping the shape of the data. You lose the name and number but keep "one deal, this size, closed in March" for your reporting.
Anonymization is the underrated option. It honors a deletion in spirit — the person is no longer identifiable — while keeping the aggregate history your sales reports rely on. Often it is a cleaner answer than a hard delete that leaves a hole in your numbers.
Put your data on a schedule
Rocketly can archive, anonymize and delete customer records on rules you set once.
See how it worksDeletion requests and the awkward truth about backups
Sooner or later a customer will ask you to delete their data, and in many places they have a right to. You want this to be routine, not a scramble — which means knowing, before the request arrives, everywhere a person's data lives: the CRM, the invoicing tool, the email platform, the spreadsheet someone keeps on the side. The same map helps when you switch tools; a CRM data migration is the right moment to leave records behind instead of copying them into a new system.
The honest complication is backups. Even after you delete a record from your live system, it usually lingers in backup copies for a while. That is normal and generally acceptable, as long as backups run on their own rotation and get overwritten on schedule, so the deleted data ages out rather than living forever. What you must not do is quietly restore a deleted person from a backup and carry on using their data.
The goal is not "instantly gone from every disk on earth." It is "out of active use, and on a path to disappearing entirely."
Writing a retention schedule you will actually follow
A policy only works if it is small enough to keep. Aim for one page. For each data category, write four things: what it is, how long you keep it, the reason, and how it gets deleted. That is the whole document.
Then make it partly automatic, because a rule nobody enforces is just a wish. Good CRMs can flag or remove records on the rules you set: tagging leads with no activity for a set period, or anonymizing closed deals once their window is up. If you still track customers in spreadsheets, this is one of the quieter reasons to move from Excel to a proper CRM: a spreadsheet has no idea how old its rows are.
A few habits keep the policy alive:
- Write the reason next to every period. If you can't state why you keep something, that's a sign the period is too long.
- Review once a year. Purposes change; so should the schedule. Put it on the calendar.
- Cover the side channels. The exported spreadsheet and the old email folder count too, not just the CRM.
If you want the wider legal framing around all of this (lawful bases, consent, and the rest), our guide to a data-protection-compliant CRM covers the ground this article deliberately skips.
Frequently asked questions
Is there a standard number of years to keep customer data?
No single number covers everything. Accounting records usually have a legal minimum you must meet, while marketing and lead data should be kept only as long as they serve a purpose. Set a period per category, and check your local rules for anything tied to tax or law.
What's the difference between archiving and deleting?
Archiving moves a record out of daily view but keeps it recoverable; deleting removes it. Archiving is useful during a retention window, but it is not erasure — the data still exists and still counts as data you hold.
Do I have to delete data if a customer asks?
In many places customers have a right to erasure, though it is not absolute; you can usually keep what you are legally required to, such as invoices. The practical answer is to delete what you no longer need and be able to explain what you kept and why.
Does deleting in my CRM remove data from backups too?
Usually not right away. Backups run on their own cycle, and deleted data ages out as older backups are overwritten. As long as you don't restore and reuse someone you deleted, that is generally fine.
A retention policy is one of those unglamorous habits that quietly lowers your risk and tidies your reporting at once. You don't need a legal department to start; you need one page, a clock for each kind of data, and a way to act on it. A CRM like Rocketly can carry the mechanical part, archiving and deleting on the rules you set, so the policy runs in the background instead of relying on someone's memory. Decide the rules once, write them down, and let old data leave the way it arrived: on purpose.