Skip to content

Data Retention: How Long to Keep What in Texas

By Donovan Brown
October 5, 2026
7 sections
Data Retention: How Long to Keep What in Texas — Cyber Security article cover card from LayerLogix, with a database icon

Keeping every file forever feels safe until a breach or lawsuit turns your archive into evidence. Here's how long to keep records and why trimming matters.

01

The Old File Share Nobody Remembered

A client in Sugar Land called us in a panic last year. During a routine audit ahead of a sale, their accountant stumbled on a network share with customer files going back to 2009 — Social Security numbers, old credit applications, scanned driver's licenses. Nobody had looked at it in a decade. Nobody had a reason to delete it either, because nobody had ever decided when it should go away. That folder turned a routine due-diligence review into a three-week legal scramble, because buyers don't want to inherit a decade of unmanaged PII, and neither does your cyber insurer.

This is the part of data governance that gets skipped. Everyone talks about backups and firewalls. Almost nobody sits down and asks: how long do we actually need to keep this, and what happens if we just... don't delete anything?

02

Why "Keep Everything" Feels Safe But Isn't

The instinct to hoard data makes sense on the surface. Storage is cheap. Deleting something you might need later feels riskier than keeping it. But every file you retain past its useful life is a liability sitting on your network, not an asset. It's one more thing an attacker can steal, one more thing a plaintiff's attorney can subpoena, one more thing your cybersecurity team has to monitor and protect.

Ransomware economics make this concrete. When an attacker encrypts or exfiltrates your systems, the recovery bill scales with how much data you're restoring and how much exposure you have to clean up — the median recovery cost, excluding any ransom paid, sits at $375,000, though a small number of very large incidents pull the average well above a million (Sophos, State of Ransomware 2026). A ten-year archive of customer records you didn't need is pure downside in that scenario. It doesn't make your business more resilient. It just makes the breach bigger.

And most victims don't pay anyway — 69% of ransomware victims refused to pay, up from 65% the year before (Sophos 2026), which means recovery and remediation costs are increasingly where the real damage happens. Less unnecessary data means a smaller remediation job.

03

What Texas Law Actually Requires

There's no single statute that tells a Texas business "keep everything for X years." Instead, retention obligations come from a patchwork, and you need to know which rules apply to your industry:

  • Financial and tax records: The IRS generally expects supporting documentation for three to seven years depending on the filing situation; many CPAs recommend seven years as a safe default for income tax records.
  • Employment records: Federal rules under the FLSA and related statutes generally require payroll records for three years and records used to calculate pay for two years. Texas Workforce Commission unemployment records have their own schedules.
  • Healthcare records: HIPAA requires covered entities to retain certain documentation — policies, risk assessments, authorizations — for six years from creation or last effective date. If you handle protected health information, this isn't optional, and our HIPAA compliance guidance covers the documentation piece in detail.
  • Financial institutions and their vendors: Under the FTC Safeguards Rule, entities handling consumer financial data need documented retention and disposal procedures as part of their information security program — see our breakdown of the FTC Safeguards Rule requirements.
  • Customer PII with no ongoing business need: This is the category that gets people in trouble. There's often no legal requirement to keep it at all once the business relationship ends, yet it's the category businesses are most likely to hoard indefinitely because nobody owns the decision to delete it.

None of these rules say "keep it forever." They all specify a window. Past that window, you're holding data with no legal upside and real downside.

04

SB 2610 Changes the Math for Texas Employers

Texas SB 2610, effective September 1, 2025, gives businesses with 20 to 99 employees a real incentive to get their data hygiene in order. If you implement the CIS Controls IG1 safeguards — 56 specific controls covering things like asset inventory, access management, and data protection — you're shielded from exemplary damages in a breach lawsuit. It doesn't eliminate liability and it doesn't create a new way for someone to sue you, but it does take the largest category of damages off the table if you can show you followed the framework (Texas SB 2610).

A documented data retention and disposal policy is part of that IG1 control set. If you're a mid-sized Texas employer and you haven't looked at this law yet, it's worth a conversation with whoever manages your managed IT services relationship, because the controls overlap heavily with what you should already be doing.

05

Where the Old Data Actually Hides

In our experience doing network assessments across Houston, The Woodlands, and Round Rock, the forgotten data almost always lives in the same five places:

  • Shared drives and old file servers nobody has audited since a migration.
  • Email archives — mailboxes of departed employees, kept "just in case," full of attachments with sensitive data.
  • Backup systems retaining full images going back years, often without anyone tracking what's actually in them.
  • Old SaaS accounts and trial systems from vendors you stopped using but never offboarded.
  • Local downloads folders and desktops — exports people pulled for a project and never deleted.

Credential abuse shows up in 39% of breaches as the connecting thread (Verizon 2026 DBIR), and old, unmanaged accounts with lingering access to stale data are exactly the kind of foothold that makes that stat possible. Tightening access with something like privileged access management closes part of that gap, but it works a lot better when there's less orphaned data sitting around for a compromised account to reach.

06

Building a Retention Schedule That Works

You don't need a 40-page policy document to start. You need a short table that maps data categories to retention periods and a disposal method, reviewed once a year. Here's the practical sequence:

  • Inventory first. You can't set a retention period on data you don't know you have. Run a discovery pass across file servers, email, and cloud storage.
  • Classify by type and obligation. Tax, HR, health, customer PII, and general business files each get their own retention clock, driven by the strictest applicable rule.
  • Set automatic expiration where you can. Microsoft 365 retention policies and auto-delete rules can enforce schedules without relying on someone remembering to clean up. If you're already on Microsoft 365 managed services, this is usually a policy change, not a new purchase.
  • Document destruction, not just deletion. A legal hold or an audit will ask you to prove when and how something was destroyed, not just that it's gone.
  • Build a legal hold exception process. Litigation, audits, or active investigations override the schedule — make sure your IT team and legal counsel know how to flag a hold before the auto-delete rule fires.

Backup retention deserves its own line item here. A seven-year email retention policy doesn't mean much if your backup vendor is quietly keeping full snapshots for ten years in a system nobody classified. If you're evaluating cloud services or backup vendors, ask directly how long they retain data by default and whether that default matches your actual policy.

07

Frequently Asked Questions

How long should a small business keep customer records after the relationship ends?

It depends on the industry, but absent a specific legal requirement, most businesses can justify deleting customer PII within one to three years of the last transaction, once tax and warranty windows close. The goal is to tie the retention period to an actual business or legal reason, not habit.

Does deleting old data hurt us in a future lawsuit?

Deleting data on a documented, consistently applied schedule is normal business practice and generally defensible. What gets businesses in trouble is deleting data after litigation is reasonably anticipated, or having no policy at all and deleting selectively. A written schedule applied before any dispute arises is your protection.

Do we need different retention rules for AI tools like Copilot?

Not different rules, but tighter enforcement. Microsoft 365 Copilot only surfaces data a user already has at least view permission to — it exposes existing oversharing rather than creating new risk (Microsoft Learn). If an old file share full of stale PII is visible to too many people, Copilot will happily surface it in a search result. Cleaning up retention and permissions before rolling out AI tools matters more than most IT teams realize.

What's the fastest way to find out what we're sitting on?

A network and data assessment is the starting point — it tells you where sensitive files actually live, who can access them, and how old your backups and archives really are. That's usually the first deliverable in a proper IT audit.

If you've never done a data inventory or your retention policy is "we keep everything," start with a free IT assessment and get a clear picture of what's on your network before a breach, lawsuit, or buyer finds it for you. Our team works out of The Woodlands and Round Rock with 100% Texas-based support — reach out and we'll walk through what a realistic retention schedule looks like for your business.

Back to Blog
Keep Reading

Related Articles

Need Expert IT Support?

Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.

Call NowBook a Call