Great Plains NetworkingGreat Plains NetworkingGet Support

Small Business Data Retention Policy That Is Ransomware Proof and IRS Compliant

A compliance first playbook for small businesses. Meet IRS retention minima, follow FTC minimization, harden backups to CISA standards, and deploy ransomware-resistant backups.

16 min readBy Great Plains Networking
Small Business Data Retention Policy That Is Ransomware Proof and IRS Compliant — Great Plains Networking
data retention policy small business

Small Business Data Retention Policy That Is Ransomware Proof and IRS Compliant

Business owner reviewing records retention decisions
Business owner reviewing records retention decisions

Keep records only as long as a documented business or legal need requires: start with IRS minimums, layer in any industry rule that runs longer, and back everything up in a way ransomware cannot reach. Tax documents typically need years on file, while old customer inquiries often don't. The fastest first step is a one-day inventory of what you store and where, or a quick professional assessment if you would rather have someone else map it.


TL;DR:

  • Retention periods must follow legal, industry, and contractual requirements, with a general minimum of four years for employment tax records and longer for specific credits.
  • A written retention policy should clearly define record scope, justified retention schedules, assigned responsibility, legal hold procedures, and review processes to ensure compliance and enforceability.
  • Keep customer data only as long as necessary for business or legal reasons, and retain corporate, property, and contractual records for their relevant lifespans plus a buffer period.
  • Implement offline, immutable backups following the 3-2-1 rule and regularly test restore procedures to prevent ransomware destruction and ensure data recoverability.
  • Small teams should conduct an inventory, assign data ownership, automate retention rules, and periodically review their policies, with external support recommended for complex or regulated environments.

Table of Contents

Which Laws Set the Minimum Retention Windows You Must Follow

Retention decisions start with the law, not preference. The IRS instructs businesses to keep employment tax records for at least four years after the tax becomes due or is paid, since these records prove wage payments, withholding, and deposits if the agency ever asks. Certain documentation runs longer: records substantiating COVID-19 paid-leave credits need six years, and Employee Retention Credit documentation needs seven years when that credit applies.

The FTC's guidance for small businesses pushes in the opposite direction for customer data. Its five-point framework, take stock, scale down, lock it, pitch it, plan ahead, treats minimal retention as a security control, not just a paperwork chore. Fewer records sitting in your systems means less exposure if a breach happens.

Which Laws Set the Minimum Retention Windows You Must Follow — overview diagram
Which Laws Set the Minimum Retention Windows You Must Follow — overview diagram

Industry rules can override the general baseline entirely. A dental or medical practice under HIPAA, a business processing card payments under PCI DSS, or a firm bound by a client contract may face retention periods longer or shorter than the tax code requires. When a contract specifies a retention term, that term governs for that document, full stop.

When no law or contract speaks directly to a record type, apply this test: keep it as long as you have a genuine business reason to access it, plus enough buffer to cover a typical audit or claims window. Beyond that, holding data is only risk with no offsetting benefit.

  • Employment tax records: at least 4 years, per IRS guidance.
  • Paid-leave credit substantiation: 6 years.
  • Employee Retention Credit documentation: 7 years, where applicable.
  • Customer information disposal: guided by the FTC's minimization principle once business need ends.
  • Contract terms and industry rules (HIPAA, PCI DSS): follow whichever is longer or more specific.

What Every Written Retention Policy Needs to Include

A retention policy that lives only in someone's head does not survive an audit, a lawsuit, or that person's vacation. Write it down, and make sure it covers these five pieces.

  1. Policy statement, scope, and legal basis: state which records the policy covers, why (tax law, contract terms, industry regulation), and who it applies to.
  2. Retention schedule with justification: for each record type, list how long you keep it and the specific rule or business reason behind that number.
  3. Assigned roles and a single records owner: name one person accountable for enforcement, even in a five-person office, so retention doesn't quietly become nobody's job.
  4. Legal hold and disposal procedures: define how automatic deletion gets paused when litigation is possible, and how routine disposal gets verified and logged.
  5. Training, review cadence, and storage location: specify how often staff review the policy and where the current version lives, so it's findable when someone actually needs it.

Skipping any one of these leaves a gap. A schedule without an owner drifts. A hold process without documentation looks improvised to a court. Treat this list as the skeleton, then fill in specifics for your industry in the next section.

How Long to Keep Different Types of Business Records

Different record types carry different risk profiles, so a single retention number for everything almost always over-keeps some things and under-keeps others.

How Long to Keep Different Types of Business Records — overview diagram
How Long to Keep Different Types of Business Records — overview diagram

Financial and tax records anchor the schedule. The IRS baseline of 4 years for employment tax records is a floor, not a target: many accountants recommend 7 years for general business tax records to cover the outer edge of audit and refund-claim windows, even though the strict legal minimum is shorter for some categories.

Employment and payroll records follow the same 4-year IRS floor, climbing to 6 or 7 years when paid-leave or Employee Retention Credit documentation is involved. Customer records and service data should be scoped to actual business need: once a customer relationship ends and no contract or regulation requires otherwise, the FTC's minimization principle argues for disposal rather than indefinite storage. Contracts, corporate formation documents, and property records typically outlive the business relationship itself, often kept for the life of the asset or entity plus a buffer for potential disputes. Backups and system logs deserve separate treatment: logs used for security monitoring are often useful only for a matter of months, while the backups that contain your actual records should be retained as long as the underlying data requires, not discarded on a shorter schedule just because they're backups.

Record typeTypical retention windowBasis
Employment tax records4 years minimumIRS
Paid-leave credit substantiation6 yearsIRS
Employee Retention Credit records7 yearsIRS
Customer information (post relationship)Disposed once business need endsFTC
  • Financial and tax records: match at least the IRS floor, and confirm with your accountant whether a longer window fits your situation.
  • Employment and payroll: follow the 4, 6, or 7 year IRS windows depending on the record.
  • Customer and service data: keep only as long as a live business or legal reason exists.
  • Contracts and corporate records: retain for the life of the agreement or entity plus a reasonable buffer.
  • Backups and logs: retain backups on the same schedule as the data they contain, and keep security logs long enough to investigate an incident.

Storing Records and Backups So They Survive a Ransomware Attack

A retention schedule means nothing if the records it protects get encrypted or deleted by an attacker before their retention date arrives. CISA's guidance for small and medium businesses recommends the 3-2-1 rule: three copies of your data, on two different media types, with one copy stored offline or off-site. Ransomware actors specifically hunt for connected backups to destroy them before encrypting production systems, which is why an offline or immutable copy, one that cannot be altered or deleted even by someone with administrator credentials, matters as much as having a backup at all.

CISA and allied ransomware advisories reinforce this: segmented, encrypted, offline backups with documented recovery tests are named as core mitigation against ransomware groups that specifically target backup infrastructure.

Beyond the backup copies themselves, a handful of access controls determine whether your retained data stays yours:

  • Encrypt records at rest and in transit, so a stolen laptop or intercepted transfer doesn't hand over readable data.
  • Apply least-privilege access, so employees can reach only the records their role requires.
  • Keep backup credentials separate from everyday admin accounts, and protect them with multifactor authentication.
  • Test restores on a regular schedule, not just backup completion, since a backup nobody has ever restored is a hypothesis, not a plan.
  • Set retention and RPO/RTO targets for backups that match how much data loss and downtime your business can actually tolerate.

Pro Tip: Schedule restore tests on the calendar the same way you schedule payroll: recurring, dated, and owned by a specific person, not left to "whenever someone has time."

A Step-by-Step Way to Roll Out the Policy Without a Big Team

Small teams don't need a compliance department to get this right. They need a sequence.

  1. Inventory what you store and where: spend a day listing record types, storage locations, and rough volumes, using a simple spreadsheet rather than specialized software.
  2. Assign a data owner for each category: financial records to whoever handles accounting, employment files to whoever handles HR, and so on.
  3. Classify records by sensitivity and retention need: three tiers, restricted, internal, and disposable, are usually enough for a small operation.
  4. Automate retention where your tools allow it: Microsoft 365 retention labels, for example, can enforce disposal schedules automatically once configured, removing the need to remember manually.
  5. Lock down access alongside retention: pair your schedule with access controls and data loss prevention settings so records are protected while they're kept, not just deleted on time.
  6. Run a restore test and put a review date on the calendar: confirm backups actually work, then set a recurring date to revisit the whole policy.

None of these steps require new headcount. They require someone deciding to do them in order, this month, rather than treating retention as a someday project.

When to Freeze Deletion for a Legal Hold or Audit

A written retention schedule does not excuse a business from preserving evidence once litigation becomes reasonably likely. Legal-practice guidance built on case law such as the Zubulake line of decisions holds that a business must suspend routine destruction as soon as it reasonably anticipates a lawsuit or regulatory inquiry, even before a complaint is filed.

The scope of a hold typically reaches accessible backups, the copies your team can readily restore and search, though media kept strictly for disaster recovery may be treated differently depending on how burdensome retrieval would be. Litigation hold guidance recommends issuing the hold in writing, naming the records and custodians covered, and documenting exactly when automated deletion was paused.

  • Issue the hold notice in writing the moment litigation becomes reasonably foreseeable, not after a complaint arrives.
  • Identify every system, including backups, that might hold relevant records, and suspend automated deletion there.
  • Document who received the notice and when deletion was paused, since that record is what you show a court later.
  • Lift the hold formally, in writing, once the matter resolves, so normal retention resumes on the record.

How to Destroy Records So They Cannot Be Reconstructed

Disposal is where retention policies most often fail quietly. A shredder that cuts strips instead of cross-cutting, or a "deleted" file that still lives on a drive, defeats the purpose of having a schedule at all.

  • Paper records: use cross-cut shredding, or a certificate of destruction from a shredding vendor for larger volumes.
  • Electronic media: apply NIST-aligned wiping or crypto-erasure, or physically destroy drives that held sensitive data.
  • Cloud storage: understand your provider's versioning and object lock settings, since "deleted" files can persist in backups or version history longer than expected.
  • Every disposal event: log the date, method, records involved, and the manager who approved it.

Keeping the Policy Alive Through Review and Training

A retention policy written once and never revisited drifts out of compliance within a year, as laws change and the business grows into new record types.

  • Review the full policy annually, and immediately after any major regulatory change, new contract type, or security incident.
  • Track a couple of simple metrics: the percentage of records properly classified, and the pass rate on scheduled backup restore tests.
  • Cover retention basics in new-hire onboarding, and repeat the training annually so it doesn't fade from memory.
  • Escalate to outside counsel when a hold or regulatory question gets complicated, and to a managed IT partner when the technical controls, encryption, access logging, backup architecture, outgrow what internal staff can maintain.

Why a Managed IT Partner Often Closes the Gap DIY Leaves Open

Writing a retention schedule is straightforward. Enforcing it against a determined ransomware actor, year after year, without dedicated IT staff, is where most small businesses fall short. Managed IT support can help address that gap with features such as 24/7 monitoring to catch suspicious activity early, backup and recovery services designed around offline and immutable copies, and cybersecurity practices focused on access controls critical to retention policies.

The honest answer on DIY versus hiring out comes down to complexity and staff capacity. A single-location business with straightforward records and one dedicated admin can often manage a retention policy internally, especially with the checklist above. A dental practice under HIPAA, a law firm with client confidentiality obligations, or any business juggling compliance rules on top of daily operations usually reaches a point where same-day response and dedicated monitoring beat piecing it together after hours. Great Plains Networking's immutable backup guidance and backup best practices resource go deeper into the implementation details covered here.

The Part of Retention Planning Most Businesses Get Backward

Most small businesses treat retention as a storage problem: buy more space, keep everything, sort it out later if a lawyer ever asks. That instinct is exactly backward. Every record you keep past its useful life is a record a breach can expose, a record a discovery request can drag into scope, and a record someone has to secure indefinitely for no return.

The conventional advice, "when in doubt, keep it," optimizes for the wrong risk. The FTC's own framing gets it right: minimization is a security control, not just tidiness. The businesses that get hurt worst in a breach are rarely the ones with tight, well-documented schedules. They're the ones sitting on a decade of customer data nobody remembers exists.

If you take one thing from this playbook, prioritize the backup hardening over the schedule's precision. A retention schedule that's slightly too generous is a minor inefficiency. A backup an attacker can reach and destroy is an existential risk. Get the offline, immutable copy right first, then refine the schedule.

— Nicholas

Get Help Turning This Policy Into a Working System

Designing a retention schedule on paper is the easy half. Making sure backups stay untouchable during a ransomware event, access controls actually match your policy, and someone tests restores on schedule takes ongoing attention that most small teams can't spare. Some managed IT providers offer ongoing support for small businesses with 24/7 monitoring, same-day response, and flexible contract terms to accommodate changing needs.

Greatplainsnetworking
Greatplainsnetworking

A free network assessment is a practical place to start if you want a full picture before committing to anything. If you just want a fast gut check on where your current backups and access controls stand, the 10-minute readiness audit gets you that without a sales conversation attached.

  • Managed IT support that keeps monitoring and enforcement running after the policy is written, not just at rollout.
  • Dedicated backup and recovery built around offline, immutable copies rather than a single connected backup.
  • Cybersecurity controls, encryption, access management, that enforce the retention rules you set on paper.

Book a free network assessment or start with the readiness audit, and find out where your current setup already meets the bar and where it doesn't.

Where This Guidance Comes From

The legal and security guidance in this article draws directly from primary government sources rather than secondhand summaries.

Sources

FAQ

What business records need to be kept for 7 years?

Records substantiating Employee Retention Credit claims need to be kept for 7 years when that credit applies, according to IRS guidance. Many accountants also recommend a general 7-year window for broader tax records as a conservative buffer, even where the strict legal minimum is shorter.

How long is a company allowed to keep your data?

There's no single universal limit. The rule depends on the record type: the FTC's minimization principle argues data should be disposed of once the business need ends, while tax and employment records follow the IRS windows regardless of whether a customer relationship continues.

What is a good data retention policy?

A good policy states its legal basis, lists a specific retention window and justification for each record type, names one accountable owner, and includes documented procedures for legal holds and secure disposal. It also gets reviewed at least annually rather than written once and forgotten.

What is the 7-year retention policy?

It typically refers to keeping certain tax-related records, including Employee Retention Credit documentation, for 7 years as recommended or required by IRS guidance. Some businesses apply 7 years as a general default for tax records even where the strict IRS minimum for a specific category is 4 or 6 years.

Recommended

Free Network Assessment

Want help putting this into practice?

We'll audit your security, speed, and hardware in under an hour — no commitment, no sales pitch. Just a clear roadmap of what to fix and why.