Describe the information and its purpose
A retention inventory identifies what information is stored, where it lives, who owns it and why it is kept. It is not a blanket instruction to delete everything old. Customer records, financial documents and incident evidence can have different operational or legal requirements that the responsible organisation must determine.
Start with a defined folder or business process. A private worksheet is sufficient; you do not need a paid data-governance service to make the first useful inventory.
Map the copy locations
- List the data category and business purpose without copying the actual sensitive records into the worksheet. Identify the authorised owner who can make retention decisions.
- Record primary storage, shared links, email attachments, exports, downloads and backup copies. Include devices or cloud services where information is routinely duplicated.
- Note access groups, existing retention rules and any approved hold that prevents deletion. Ask the owner to resolve uncertain requirements using appropriate current guidance rather than guessing a universal retention period.
- Identify redundant or unneeded copies and propose a supported removal process. Obtain the required authority and preserve data that remains necessary for recovery, records or an investigation.
Verify a limited cleanup
Choose harmless disposable test data or a clearly approved redundant copy. Remove it using the relevant platform's supported controls and inspect expected recycle-bin or version-retention behaviour. Deleting a working file may leave backups, versions or downloaded copies elsewhere.
Avoid unsupported erasure claims
Ordinary file deletion is not a guarantee of forensic destruction, particularly on modern storage or managed cloud systems. Use the vendor's supported lifecycle and device-retirement process when stronger handling is required. Document what the action actually removed and what remains governed by another retention schedule.
Keep access and retention related
A necessary long-lived record does not need to be readable by every user. Review access separately from whether the record should exist. Conversely, restricting a folder is not a reason to keep an unnecessary export forever.
Maintain an accountable inventory
Assign a review owner and revisit after application changes or staff departures. A useful register helps the business make deliberate retention and access decisions. It should avoid storing a second uncontrolled collection of sensitive data while trying to document the first one.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.