I’m about to say something that might ruffle a few feathers. Ready? Deep breath. Here we go: We’re overusing indefinite retention periods in our retention schedules.
There, I said it.
Now, before the records hoarders clutch their banker’s boxes in protest—relax. I know your struggle. I know you want to keep everything forever… and ever… and ever. Your commitment is admirable. Your office floor? Probably less visible. But it’s time to talk about change.
Indefinite retention lives at the intersection of records, privacy, cybersecurity, legal, compliance, and everyday business operations. If you keep information, you also must protect it, explain why you still need it, and show that your retention practices are more than a hopeful shrug in policy form.
One of the biggest sources of confusion in the retention world is the casual interchangeability of “permanent” and “indefinite” as if they were interchangeable. They’re not.
Permanent retention means forever. Full stop. No take-backs. These are your articles of incorporation, charters, and by-laws—the crown jewels of your organization. You don’t toss those. Ever.
Indefinite retention, on the other hand, is like the “we’ll see” of recordkeeping. It doesn’t mean forever—it means you’ll revisit the decision someday.
The key word here is revisit. If “indefinite” appears in a schedule, it should come with a defined owner, a documented reason, and a review trigger. Otherwise, indefinite starts to look less like governance and more like indecision wearing a blazer.
Done right, indefinite retention supports genuine business needs such as keeping policies, programs, or procedures readily available. Done wrong, it becomes the catchall for anything no one has the courage to delete.
Indefinite retention is popular because it caters to two familiar office personalities:
These decisions come with a cost. Storage isn’t free, and over-retention increases risk. With today’s budget pressures, privacy laws, and the growing need for defensible disposal, indefinite isn’t a cautious strategy—it’s a ticking time bomb.
And the discovery side of this is not exactly a spa day. If you keep it, someone may expect you to search for it, review it, and produce it. The more you retain, the more you may have to sift through during litigation, audits, investigations, or regulatory requests.

Let’s be fair: indefinite retention isn’t all bad. It has its place—just a much smaller place than many schedules suggest.
Indefinite makes sense when:
Think: internal policies, procedures, or awards packages. Not: every sticky note from every staff meeting.
If you’re not sure where to start, here’s one easy win: personnel records.
Unless the law says otherwise, don’t default to indefinite retention here. The litigation exposure and privacy risks are enormous. Keeping old HR files forever is like rolling out the red carpet for a data breach, and no one wants to explain that to the board.
Instead, defined trigger events can save you from the “indefinite” trap. For personnel records, that might mean tying retention to a clear milestone, such as separation from employment, final benefit payment, resolution of a claim, or another event that starts the retention clock. That’s very different from “keep it indefinitely because HR might need it someday.” One gives you a defensible timeline. The other gives you a privacy problem waiting patiently in a filing cabinet.
Indefinite retention isn’t the villain—it’s just not meant to be the star of your schedule. Think of it like the coworker who microwaves fish in the breakroom: acceptable in very specific situations but best avoided whenever possible.
So, next time you review your retention schedule, here are three smart next steps:
Use “indefinite retention” sparingly, strategically, and with intention. Your records program (and your budget) will thank you.
For more practical insights on how to approach retention in a way that is realistic, supportable, and aligned with legal, privacy, and operational needs, watch the webinar recording of Indefinitely Maybe: When Retention Decisions Become Compliance Risk.
Share