Privacy & Data Protection

Data Retention: What It Is & Why It Matters

Data retention is the practice of keeping personal information only for as long as it is genuinely needed, then disposing of it responsibly.

In this explainer

  • Explain what data retention means in plain language
  • Describe the general expectation not to keep information indefinitely
  • Clarify that retention periods depend on purpose and law
  • Show why retention discipline matters for a recovery provider
  • Outline good retention practice and questions to ask

5 min read

What it is

Data retention is about how long personal information is kept and what happens to it afterwards. The underlying expectation in privacy frameworks is that information should not be kept indefinitely 'just in case', but retained only for as long as there is a legitimate need, and then disposed of or de-identified responsibly.

This reflects a simple risk principle: information that is no longer needed but still held is a liability. Reducing the volume of unnecessary information lowers the impact of any breach and respects individuals' interest in not having data about them kept longer than warranted.

How long is appropriate depends on the purpose for which information was collected and on any legal or business requirements to keep it. This explainer stays general, and specific retention periods should be determined against current law and circumstances.

Key requirements

Good retention practice generally involves:

  • Keeping information only while there is a legitimate purpose or legal requirement to do so.
  • Having defined retention approaches rather than keeping everything indefinitely.
  • Securely disposing of or de-identifying information once it is no longer needed.
  • Balancing retention against other obligations, such as records that must be kept for a period.

There is genuine tension here: some information must be retained for legal or legitimate business reasons, while privacy favours not keeping it longer than necessary. The right balance depends on the situation and applicable law.

Why it matters for debt recovery

Recovery generates records, correspondence and financial details about many individuals. Without retention discipline, that information can accumulate well beyond any genuine need, increasing both privacy risk and the potential impact of a breach. Sound retention reduces that exposure.

For a prospective client, retention is a useful indicator of maturity. A provider that can describe how it decides when information is no longer needed, and how it disposes of it, is managing a real risk that careless providers ignore.

Our Trust Centre covers related ideas including data minimisation and the right to erasure.

What to ask a provider

Useful questions include: How does the provider decide how long to keep debtor information? Does it have a retention approach, or does it simply keep everything? How does it securely dispose of information that is no longer needed? And how does it balance retention against any obligations to keep certain records?

Look for evidence of deliberate decisions about retention and disposal. A provider that has never considered when to delete information is carrying, and exposing you to, unnecessary risk.

How Merion approaches it

Merion follows the principle that information should be kept only as long as it is genuinely needed for a legitimate purpose or to meet an obligation, and then disposed of or de-identified responsibly. We aim to avoid keeping personal information indefinitely without reason, balancing retention against any requirements to keep particular records.

This is general information only and not legal advice, and it asserts no certification or specific retention period. Appropriate periods depend on purpose and law, so the OAIC and independent advice are the right sources for specifics.

Key takeaways

  • Retention means keeping information only as long as genuinely needed
  • Information no longer needed but still held is a liability
  • Appropriate periods depend on purpose and legal requirements
  • Retention discipline reduces a recovery provider's risk exposure

Frequently asked questions

How long should personal information be kept?

It depends on the purpose for which it was collected and any legal requirements. This explainer does not state a fixed period; confirm appropriate periods against current law.

Why not just keep everything?

Information that is no longer needed but still held increases privacy risk and the impact of any breach. Privacy frameworks favour keeping it only as long as necessary.

Is this legal advice?

No. This is general information only. For advice, consult the OAIC or seek independent legal advice.

Built on trust

Security and compliance you can verify

Merion handles every account on the facts, within the rules, and with data protected by design. Ask us anything.