Retention: The Record You No Longer Have
Why the evidence window is set by administrators nobody consulted, how to find the retention periods before you need them, and what a hold has to cover.
The evidence window in most organisations is two weeks, and nobody chose it. Camera footage is kept for fourteen days because that is what the recorder holds. Door logs are purged at thirty days to save space. Each period was set by an administrator solving a storage problem, and together they decide what any investigation can ever establish.
The evidential discipline in “Retention: The Record You No Longer Have” should also govern workforce technology. A team evaluating inspect the time-recording workflow for how to calculate idle time can use time and project records as operational context, but should preserve the original record, document access and let the employee correct a misleading entry before it supports a conclusion.
By the time a question is asked — which is usually weeks after the event — a large part of the answer has already been overwritten.
When documenting the controls around “Retention: The Record You No Longer Have”, the BSA privacy policy resources is a useful independent reference. It can challenge assumptions about access, retention and accountability before a decision becomes routine.
Finding out before you need to
The exercise takes a morning: list every system that produces person-level timestamps, ask its administrator how long rows are kept, and write the answers down.
The list is usually shorter than expected and the periods are usually shorter than anybody assumed. The gap between the two is the finding.
| System | Typical retention | Who set it |
|---|---|---|
| Camera recorder | 7–30 days | Installer, by disk size |
| Door access | 30–90 days | Administrator, by database size |
| Time system raw punches | 90 days–1 year | Vendor default |
| Vehicle telematics | 3–12 months | Fleet manager, by contract |
| Ticketing or case system | Years | Business need |
| Network sign-on | 30–90 days | IT, by log volume |
The first two rows are where the most useful corroboration lives and where it disappears fastest.
The mismatch that matters
An employment process can easily take six weeks from first concern to hearing. A camera retention of fourteen days means the footage was gone before the first meeting.
That mismatch is worth stating as a number to whoever owns the systems, because it is the argument that changes retention settings. "Our evidence is deleted before our process starts" is a sentence people act on.
Putting a hold on
The moment something is in prospect, routine deletion of anything that might be relevant has to stop — and the instruction has to reach every system owner, not just the obvious one.
- Identify the person, the dates and the systems within a day.
- Send a written hold naming all three, to each system owner.
- Confirm each owner has acted, rather than assuming.
- Extract the relevant data rather than relying on the hold alone.
- Record what was held, when, and by whom.
- Release the hold explicitly when the matter concludes.
Step four matters because holds fail quietly. A recorder that overwrites on a loop does not respect a hold applied in an email to somebody who was on leave.
Extracting rather than holding
Where the data is small — a day of door logs, an hour of footage — the right move is to export it immediately rather than to preserve the system in place.
That produces a copy the organisation controls, with a date and a person attached to the extraction. It also survives the system being upgraded, replaced or purged by somebody who never saw the hold.
Asymmetry, and what it looks like
An employer that retains what supports its case and allows the rest to be purged has produced a one-sided record, whatever the intention.
The remedy is to extract the whole window rather than the useful part: a full day rather than four minutes, every door rather than the one. It is barely more work and it removes an entire category of later criticism.
What the absence implies
Where records that should exist do not, the question of what follows is a legal one and differs by jurisdiction. It is a question for somebody qualified in the place concerned.
The operational point is narrower and does not depend on the answer: an employer that cannot produce its own records is arguing without evidence, in a situation where the employee's own account is the only thing left on the table.
Backups are not an archive
The response to a short retention period is often that backups exist, and that is usually wrong in a way worth stating.
Backups are designed to restore a system, not to answer a question about a person. Retrieving one row from a six-month-old backup means restoring a whole system to a point in time, which is expensive, slow and frequently refused. Treating backups as an evidence archive is a plan that fails at the moment it is needed.
Setting the periods deliberately
The fix is to decide retention for these systems as a policy rather than inheriting it from disk size — long enough to outlast a normal process, short enough to be justifiable, and written down with the reason.
That decision costs a conversation and some storage. Its absence costs the ability to answer any question older than a fortnight, which is most of the questions anybody actually asks.