Redacting sensitive information from documents and emails is an essential part of protecting confidential and personal data. However, effective redaction is only one part of the information lifecycle. Organisations must also decide how long to retain the original, unredacted versions of those documents. Without a clearly defined data retention policy, businesses may unintentionally increase security risks, regulatory exposure, and storage costs by keeping sensitive originals indefinitely.
A data retention policy defines how long documents and emails are retained before they are securely deleted. In many document redaction platforms, this policy applies to the original source documents regardless of whether they have been redacted. The redacted copy can continue to serve its intended purpose, while the original is removed according to the organisation’s retention requirements. This ensures that sensitive information is not stored for longer than necessary.
When a document is redacted, the sensitive information is removed from the version intended for sharing. However, the original document often remains stored within the system. If that original contains personally identifiable information (PII), financial records, legal correspondence, or commercially sensitive material, it remains a valuable target for attackers and an ongoing compliance responsibility.
The UK’s National Archives advises that organisations should never redact the master version of an electronic record. Instead, they should create a separate redacted copy and ensure that any intermediate files are securely deleted once they are no longer required. This guidance highlights an important principle: organisations must actively manage both the redacted and original versions throughout their lifecycle, rather than assuming redaction alone is sufficient.
Modern privacy regulations place significant emphasis on retaining personal data only for as long as necessary. The UK GDPR’s storage limitation principle requires organisations to define retention periods based on legitimate business, legal, or regulatory requirements, and to securely dispose of information once those requirements have been met.
Government organisations follow this same principle. The UK Competition and Markets Authority states that data should only be retained while there is an administrative, legal, or audit need, after which it should be securely destroyed. Their policy also notes that, when projects conclude, organisations should consider securely deleting personal data where there is no continuing need to retain it.
For organisations processing large volumes of documents, automating these retention decisions helps demonstrate consistent compliance while reducing the risk of human error.
Every stored original document increases the amount of sensitive information that could be exposed if a system is compromised. While security controls such as encryption and access management reduce risk, deleting information that is no longer required is one of the most effective ways to minimise potential impact.
A retention policy reduces the volume of sensitive information held within the platform by automatically removing original documents once the configured retention period expires. In practical terms, fewer retained originals mean fewer records that could be exposed during a data breach, insider incident, or unauthorised access event.
This follows a widely accepted information security principle: reducing unnecessary data reduces organisational risk.
Retaining every original document indefinitely also creates operational challenges. Storage requirements continue to grow, backup volumes increase, and legal discovery or audit exercises become more complex because more historical information must be searched and reviewed.
Well-designed retention policies ensure that only information with ongoing business value is preserved. Many records management frameworks recommend assigning retention periods based on the type of record, its purpose, and any applicable legal obligations, preventing both premature deletion and unnecessary long-term storage. (The Royal College of Radiologists).
Customers, regulators, and business partners increasingly expect organisations to manage information responsibly throughout its entire lifecycle. A documented retention policy demonstrates that data governance extends beyond document redaction and includes secure disposal of original records when they are no longer needed.
Within a document redaction platform, configurable retention policies provide organisations with flexibility to meet their own legal and operational requirements. Some documents may need to be retained for only a few days after processing, while others may require months or years of storage before deletion. By allowing administrators to define these retention periods, organisations maintain control over their original documents while ensuring redacted versions remain available for their intended use.
At Obfys we allow users to set the length of time documents are kept for the overall account, with a range of between 1 day to 2 years. The retention policy is set per document based on the policy existing at the time the document was uploaded to the platform. Users should therefore begin redacting documents as soon as they are uploaded if a retention policy is set.
Redaction protects the information that is shared, but a data retention policy protects the information that remains behind the scenes. Together, they form a complete approach to information governance.
By automatically deleting original documents and emails after a defined retention period, organisations can reduce security risk, support compliance with data protection laws, lower storage costs, and demonstrate responsible data management. In short, effective redaction should always be complemented by an equally effective retention policy.