
Most Australian businesses are quietly hoarding data. Old customer lists, spreadsheets full of contact details, resumes from people you never hired, scanned invoices going back a decade. It feels safer to keep everything, just in case. In reality, the opposite is true. Every record you hold is something you have to protect, and something an attacker can steal. Holding data you no longer need adds risk without adding value.
The good news is that data retention is not a guessing game. Australian law tells you what you must keep and for how long, and privacy rules tell you what you should get rid of. This guide walks through both sides so you can decide what to keep, what to delete, and when.
The two forces pulling on your data
Data retention sits between two rules that pull in opposite directions. On one side, tax, employment and corporate laws require you to keep certain records for a set number of years. Throwing them out too early can leave you unable to answer an audit or defend a claim. On the other side, the Privacy Act expects you to get rid of personal information once you no longer need it. Keeping it forever is not compliance, it is a liability.
The trick is to stop treating all data the same. A payroll record and a marketing enquiry from three years ago have very different obligations attached to them. Once you separate your data by type, the answer to “keep or delete” usually becomes obvious.
What you are required to keep
Several Australian regulators set minimum retention periods. These are floors, not targets, so the rule is to keep the record until the longest applicable period has passed. The most common ones for a small or medium business are:
- Tax and business records: five years. The ATO requires you to keep most business records for five years, generally from when you prepared or obtained the record, or completed the transaction it relates to, whichever is later. Some records need to be kept longer if they still relate to an open assessment.
- Employee records: seven years. Under the Fair Work Act, employers must keep employee records, including pay, hours and leave, for seven years.
- Company financial records: seven years. The Corporations Act requires companies to keep financial records for seven years, and ASIC enforces this.
- Superannuation records: five years. Records such as super contributions and employee fund choices generally need to be kept for five years.
Your industry may add its own rules. Health providers, financial advisers, builders and childcare operators often face longer or stricter retention requirements, so check your professional or regulatory body if you are unsure. When two periods apply to the same record, keep it for the longer one.
What you should delete
The Privacy Act pushes in the other direction through Australian Privacy Principle 11. In plain terms, if you hold personal information that you no longer need for any purpose you are permitted to use it for, and you are not required by law to keep it, you must take reasonable steps to destroy it or de-identify it. Personal information means anything that identifies a living person: names, phone numbers, email addresses, dates of birth, and similar details.
This is the part most businesses ignore, and it is where a lot of avoidable risk lives. Think about the data that piles up without anyone deciding to keep it: enquiry forms from prospects who never became customers, resumes from candidates you did not hire, exported customer lists sitting in someone’s downloads folder, old databases from a system you stopped using two years ago. None of it earns its keep, and all of it is exposed if you have a breach. Deleting it is not just tidy, it is the law.
Reducing what you hold also shrinks the impact of any incident. If personal information you hold is exposed, you may have obligations under the Notifiable Data Breaches scheme. The less sensitive data you are sitting on, the smaller and less painful that event becomes. You can read more in our guide to notifiable data breaches.
The data you have forgotten about
A retention policy only works if it covers all the places your data actually lives. In most businesses, data has quietly spread far beyond the main system. Copies end up in email attachments, shared drives, personal laptops, USB sticks, cloud storage accounts and the apps individual staff signed up for on their own.
That last one deserves attention. When staff use tools the business never approved, customer data can end up in accounts nobody is tracking and nobody remembers to clean out. This is a common blind spot, and we cover it in our article on shadow IT. Before you can retain or delete data with any confidence, you need a rough map of where it is kept. A short data stocktake, listing your main systems and the kinds of personal information each one holds, is worth an afternoon of someone’s time.
Building a simple retention schedule
You do not need a legal team or a fancy system to get this right. A one-page retention schedule, reviewed once a year, puts most small businesses well ahead. Here is a practical way to build one:
- List your data types. Group what you hold into a handful of categories: tax and financial records, employee records, customer records, marketing and enquiry data, and supplier records.
- Assign a keep period to each. Use the legal minimums above as your starting point, and note where an industry rule extends them.
- Set a delete trigger. For data with no legal keep period, such as unsuccessful job applications or cold marketing leads, decide a sensible cut-off, for example twelve months after last contact.
- Name an owner. Give one person responsibility for running the schedule, so deletion actually happens rather than being everyone’s job and therefore no one’s.
- Put a reminder in the calendar. A quarterly or annual clean-out, booked in advance, is what turns a policy on paper into a habit.
Keep the document short and readable. A schedule nobody understands is a schedule nobody follows. If your obligations are complex, get a one-off review from an accountant or lawyer, then run it yourself from there.
Deleting data properly
Deleting data means more than dragging a file to the recycle bin. When you decide something should go, make sure it is genuinely gone, including the copies. That means emptying the trash, clearing backups on their normal cycle, and wiping or destroying old devices and drives before they leave the business. Paper records with personal information should be shredded, not just binned.
There is a middle path worth knowing about. If you want to keep data for analysis or reporting but no longer need to identify individuals, you can de-identify it by stripping out the details that point to a person. Done properly, de-identified data falls outside the Privacy Act, which lets you keep the insight without carrying the risk. Just be careful: weak de-identification that can be reversed does not count, so remove enough that a person cannot reasonably be re-identified.
Retention rules are also shifting. Australia’s privacy laws are being reformed, and tighter expectations around holding and disposing of personal information are part of that direction. Our overview of the Privacy Act changes explains what is coming and how to prepare. Building good retention habits now means you are ready rather than scrambling later.
Find out where you stand
Data retention is one piece of a bigger picture, and most businesses are stronger in some areas than others. The quickest way to see how yours is tracking is to take our free self-assessment. You answer 27 short questions and get a personalised PDF report mapped to the ACSC Essential Eight, ISO 27001 and SOC 2, with practical next steps for the gaps it finds. It takes about five to ten minutes and the report is instant.
Take the free SecurityScore assessment and find out where your business stands today.