Back to Blog
Compliance GuidesMarch 29, 202612 min readReviewed by the PrivacyLawMap editorial teamLast reviewed March 29, 2026

Data Retention Policy: What US State Privacy Laws Require and How to Build One

Share:
Turn This Guide Into a Working Privacy SetupSponsored

Termly can generate and maintain your privacy policy, consent banner, and data-request workflow as requirements change.

Start Free with Termly

A data retention policy is a formal document that defines how long your organization keeps different categories of personal data and what happens when that period expires. In 2026, with over 20 US state privacy laws now in effect, having a well-defined data retention policy is no longer optional — it is a core compliance requirement.

As of August 4, 2026, exactly three US laws force a business to put its retention practices in front of the public: California requires a per-category retention period in the privacy notice, Minnesota requires a description of the retention policy plus a last-updated date, and Illinois BIPA requires a publicly available retention schedule for biometric data. Every other state comprehensive privacy law imposes a duty to limit retention but never asks you to publish it — which is why a policy that satisfies Virginia can still fail California.

This guide explains what a data retention policy is, why US state privacy laws require one, and walks you through building a compliant policy from scratch. Whether you are a small business owner or a compliance officer managing multi-state obligations, you will find practical examples, best practices, and a step-by-step template below.

What Is a Data Retention Policy?

A data retention policy is an internal governance document that specifies:

  • What data you collect — categories of personal information (names, emails, purchase history, browsing data, biometrics, etc.)
  • How long you keep it — defined retention periods for each category, tied to a business purpose or legal obligation
  • When and how you delete it — procedures for secure disposal once the retention period expires
  • Who is responsible — roles and accountability for enforcing retention schedules

Without a data retention policy, organizations tend to accumulate data indefinitely — creating unnecessary liability, increasing breach exposure, and violating the data minimization principles that multiple state laws now mandate.

Why US State Privacy Laws Require Data Retention Policies

Most US state comprehensive privacy laws do not use the exact phrase "data retention policy," but they impose requirements that make one essential. Here is how the major state laws address data retention:

Data Minimization and Purpose Limitation

Several state laws require that data collection be limited to what is "reasonably necessary" for a disclosed purpose. Once that purpose is fulfilled, keeping the data becomes a violation. The states with the strongest language include:

State LawData Retention RequirementStrictness
Maryland MODPAMust not collect, process, or share data that is not "reasonably necessary and proportionate" to the specific purpose disclosed. No consent override for non-essential data.Strictest
California CCPA/CPRAMust disclose retention periods in privacy policy. Cannot retain data longer than reasonably necessary for the disclosed purpose. Risk assessments required for high-risk processing.Strong
Colorado CPAPurpose limitation: cannot process data for purposes not reasonably necessary or compatible with the disclosed purpose.Moderate
Connecticut CTDPAData minimization: collection must be adequate, relevant, and reasonably necessary for the disclosed purpose.Moderate
Virginia VCDPAPurpose limitation: processing must be adequate, relevant, and reasonably necessary for the disclosed purpose.Moderate
Texas TDPSAData minimization: adequate, relevant, and reasonably necessary for the disclosed purpose.Moderate

Consumer Right to Deletion

Every major state privacy law grants consumers the right to delete their personal data. To honor deletion requests properly, you need a retention policy that specifies what data exists, where it is stored, and how to remove it. States with active deletion rights include California, Virginia, Colorado, Connecticut, Utah, Indiana, Kentucky, Rhode Island, Texas, Oregon, Montana, Delaware, New Hampshire, Iowa, Nebraska, Tennessee, Maryland, Maine, and Oklahoma.

Use our Privacy Law Calculator to determine which state deletion requirements apply to your business.

Which US Laws Require You to Publish or Disclose a Retention Policy

This is the distinction most retention-policy guides miss. Nearly every state comprehensive privacy law tells you to limit retention; only a handful tell you to say so in public. Getting this wrong is expensive in one direction only — an unpublished policy is invisible to a regulator reading your website, which is exactly how a state AG opens a file.

Obligation tierLaw and citationWhat the statute actually makes you publish
Publish a retention schedule Illinois BIPA, 740 ILCS 14/15(a) A private entity holding biometric identifiers "must develop a written policy, made available to the public, establishing a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information when the initial purpose for collecting or obtaining such identifiers or information has been satisfied or within 3 years of the individual’s last interaction with the private entity, whichever occurs first." The entity must then actually comply with its own schedule.
Disclose retention in the privacy notice California CCPA/CPRA, Cal. Civ. Code § 1798.100(a)(3) "The length of time the business intends to retain each category of personal information" — or, if that is not possible, "the criteria used to determine that period." The same subsection bars retaining personal or sensitive personal information "for longer than is reasonably necessary for that disclosed purpose."
Disclose retention in the privacy notice Minnesota MCDPA, Minn. Stat. § 325M.16, subd. 1(a)(7)–(8) The privacy notice must include "a description of the controller’s retention policies for personal data" and "the date the privacy notice was last updated." Minnesota is the disclosure requirement most businesses miss, because it arrived with a Virginia-model statute that otherwise looks nothing like California.
Duty to limit — no publication mandate Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Texas TDPSA, Maryland MODPA and the other Virginia-model comprehensive laws Collection and processing must be "adequate, relevant, and reasonably necessary" for a disclosed purpose (Maryland is stricter still: "reasonably necessary and proportionate," with no consent override). These duties make a retention schedule necessary to defend, but none of them requires you to publish the schedule itself.

The practical consequence: if you operate in Illinois with biometrics, your retention schedule is a public document, not an internal one. If you are subject to California or Minnesota, the retention section belongs in the privacy notice itself. Everywhere else, the schedule can live internally — but you still have to be able to produce it when an attorney general asks.

Source check: Last verified August 4, 2026 against the verbatim text of 740 ILCS 14/15(a), Cal. Civ. Code § 1798.100(a) and (c), and Minn. Stat. § 325M.16 subd. 1 (date_retrieved: 2026-08-04). The Illinois text was read from an archived capture of the Illinois General Assembly’s own ILCS page.

Data Retention Policy Best Practices

Based on the requirements across 20+ state privacy laws, here are the best practices for building a compliant data retention policy:

1. Map Your Data Inventory First

You cannot define retention periods without knowing what data you have. Conduct a data inventory that catalogs every category of personal information your organization collects, where it is stored, who has access, and what business purpose it serves. This inventory also supports data protection impact assessments required by many state laws.

2. Tie Every Retention Period to a Purpose

Each category of data should have a specific retention period tied to a legitimate business purpose or legal requirement. Examples:

Data CategoryExample Retention PeriodJustification
Customer purchase records7 yearsTax and accounting compliance (IRS requirements)
Website analytics / cookies13 monthsMarketing analysis; aligns with GDPR guidance
Employee HR recordsDuration of employment + 3 yearsEmployment law statute of limitations
Customer support tickets2 years after resolutionQuality assurance; warranty period coverage
Marketing email listsUntil consent withdrawal or 2 years of inactivityConsent-based; CAN-SPAM compliance
Biometric dataUntil purpose fulfilled or 3 yearsState biometric privacy laws (IL BIPA, TX, WA)
Browsing / behavioral data90 daysShort-term personalization; minimize breach exposure
Precise geolocation data30 days or do not collectHigh sensitivity; Maryland / Oregon restrictions

3. Apply the "Shortest Defensible Period" Rule

When no specific legal requirement mandates a retention period, default to the shortest period that serves a legitimate business need. This approach aligns with the data minimization requirements in Maryland, Colorado, Connecticut, and other states, and reduces your exposure in the event of a data breach.

4. Automate Deletion Where Possible

Manual deletion processes are error-prone. Implement automated data lifecycle management tools that flag or delete data when retention periods expire. This is especially important for honoring consumer deletion requests within the 45-day (California) or 30-day (most other states) response windows.

5. Document Everything

Your data retention policy should be a living document, reviewed at least annually. Maintain records of when data was collected, when retention periods expire, and when deletion occurs. This documentation is critical evidence if a state AG investigates your data practices.

6. Account for Legal Holds and Exceptions

Include procedures for suspending normal deletion when data is subject to litigation holds, regulatory investigations, or ongoing contractual obligations. Define who can authorize a hold and how normal retention resumes when the hold is lifted.

Sample Data Retention Policy Template

Here is a simplified template structure you can adapt for your organization:

SectionContents
1. Purpose and ScopeWhy the policy exists, who it applies to, and which data it covers
2. DefinitionsKey terms: personal data, sensitive data, processing, retention period, deletion
3. Data InventoryTable of all data categories with storage locations and data owners
4. Retention ScheduleTable mapping each data category to its retention period with legal justification
5. Deletion ProceduresHow data is securely deleted (overwriting, degaussing, certificate of destruction for physical media)
6. Legal HoldsProcess for suspending deletion during litigation or investigations
7. Consumer Deletion RequestsIntegration with DSAR (data subject access request) workflow; response timelines by state
8. Roles and ResponsibilitiesWho owns the policy, who enforces it, escalation paths
9. Training and AwarenessHow employees are trained on retention and deletion requirements
10. Review ScheduleAnnual review cadence, triggers for ad-hoc review (new laws, new data categories)

Data Retention Policy vs. GDPR vs. US State Laws

If your business also handles data from EU residents, your data retention policy needs to satisfy both GDPR and US state law requirements. Here is how they compare:

AspectGDPRUS State Laws (Composite)
Explicit retention period disclosureRequired (Articles 13-14)Required in California; implied elsewhere
Data minimizationCore principle (Article 5(1)(c))Maryland (strict); 15+ other states (moderate)
Purpose limitationCore principle (Article 5(1)(b))Most state laws require it
Right to erasureBroad (Article 17)All 20+ state laws include it
Automated deletion mandateImplied by storage limitationCalifornia Delete Act for data brokers (Aug 2026)
Penalties for over-retentionUp to 4% annual revenue$2,500–$25,000 per violation (varies by state)

The practical takeaway: if you build your data retention policy to satisfy GDPR requirements, it will generally meet US state law requirements as well. The key gap is that US state laws are enforced by individual state AGs, and penalties can stack across states.

Step-by-Step: Building Your Data Retention Policy in 2026

  1. Identify which laws apply — Use the Privacy Law Calculator to determine your multi-state compliance obligations.
  2. Conduct a data inventory — Map every category of personal data you collect, store, and process. Include third-party processors and cloud services.
  3. Research legal minimums — Identify mandatory retention periods from tax law, employment law, industry regulations (HIPAA, PCI-DSS, SOX), and state-specific requirements.
  4. Set retention periods — For each data category, pick the shortest defensible period that satisfies legal obligations and business needs.
  5. Define deletion procedures — Specify how each type of data is securely deleted. For databases, backups, and third-party systems, document the full deletion chain.
  6. Integrate with DSAR workflows — Ensure your consumer deletion request process references the retention schedule and can locate all instances of a consumer's data.
  7. Get stakeholder sign-off — Legal, IT, marketing, HR, and executive leadership should all review and approve the policy.
  8. Train your team — Every employee who handles personal data should understand the retention schedule and deletion procedures.
  9. Implement automated controls — Set up automated alerts or deletion triggers in your data systems. Review the state-by-state comparison to ensure you meet the strictest applicable standard.
  10. Schedule annual reviews — Review the policy at least annually or whenever new state privacy laws take effect. Six states activate new laws in 2026 alone.

Common Data Retention Policy Mistakes

  • Keeping everything forever — The biggest mistake. Unlimited retention violates data minimization laws and maximizes breach impact.
  • One-size-fits-all periods — Different data categories have different legal requirements. A single "keep for 5 years" policy will be either too long or too short for most data.
  • Forgetting backups — If your retention policy says "delete after 2 years" but your backups keep data for 7 years, you are not compliant.
  • Ignoring third-party processors — Your vendors may retain data longer than your policy allows. Ensure contracts include retention and deletion clauses.
  • No enforcement mechanism — A policy that exists only on paper provides no legal protection. You need automated systems and regular audits.

Frequently Asked Questions

Is a data retention policy legally required in the US?

No single US federal law mandates a standalone data retention policy document. However, multiple state privacy laws create obligations (data minimization, purpose limitation, deletion rights, retention period disclosure) that effectively require one. California and Minnesota both require retention disclosures in the privacy notice, and Illinois BIPA requires a publicly available retention schedule for biometric data. Businesses subject to HIPAA, PCI-DSS, or SOX also have sector-specific retention requirements.

Which state privacy laws require you to disclose your retention period?

Three, and each phrases it differently. California requires the privacy notice to state the length of time the business intends to retain each category of personal information, or the criteria used to determine that period (Cal. Civ. Code § 1798.100(a)(3)). Minnesota requires a description of the controller’s retention policies plus the date the notice was last updated (Minn. Stat. § 325M.16, subd. 1(a)(7)–(8)). Illinois BIPA goes furthest for biometric data specifically: the retention schedule and destruction guidelines must be a written policy made available to the public (740 ILCS 14/15(a)). The other state comprehensive privacy laws impose a duty to limit retention but do not require you to publish the schedule.

What should a US data retention policy contain?

At minimum: a data inventory listing every category of personal information you hold; a defined retention period for each category tied to a specific business purpose or legal obligation; the trigger that starts the clock (collection date, last transaction, end of the customer relationship); the disposal method and who executes it; legal-hold and litigation-hold exceptions that suspend deletion; the owner accountable for the schedule; and a review date. If you are subject to California or Minnesota, the per-category periods or the policy description also have to appear in your public privacy notice — not just in the internal document.

How long should I keep customer data?

There is no universal answer. Retention periods should be set per data category based on the specific business purpose and applicable legal requirements. For example, purchase records may need 7 years for tax purposes, while marketing cookies should typically be retained for no more than 13 months. The key principle across all state laws is: do not keep data longer than reasonably necessary.

What happens if I do not have a data retention policy?

Without a data retention policy, you risk: (1) violating state data minimization requirements, particularly Maryland MODPA; (2) being unable to efficiently process consumer deletion requests within the legal timeframes; (3) increased liability and damages in the event of a data breach; and (4) difficulty demonstrating compliance during a state AG investigation. The penalties for non-compliance range from $2,500 to $25,000 per violation depending on the state.

Does the CCPA require me to disclose retention periods?

Yes. Under Cal. Civ. Code § 1798.100(a)(3), California businesses must disclose the length of time they intend to retain each category of personal information, or if that is not possible, the criteria used to determine the retention period; the CCPA regulations at § 7012 carry the same requirement into the privacy policy content rules. The statute pairs the disclosure with a hard limit: personal information may not be retained "for longer than is reasonably necessary for that disclosed purpose."

How does a data retention policy relate to data minimization?

Data minimization (limiting what you collect) and data retention (limiting how long you keep it) are two sides of the same coin. A robust compliance program addresses both: collect only what you need, keep it only as long as necessary, and delete it securely when the purpose is fulfilled. Our data minimization guide covers the collection side in detail.

This article provides general educational information and is not legal advice. Consult qualified legal counsel for guidance specific to your organization. Published: March 29, 2026. Last verified: August 4, 2026.

Put This Guide Into PracticeSponsored

Termly can turn the requirements above into a maintained privacy policy, consent banner, and data-request workflow.

Start Free with Termly