A data retention policy is one page that says how long each kind of record is kept and how it is destroyed, sitting on top of a schedule that says it category by category. The page is easy. The schedule is where the work is, and its size surprises people: every category of record multiplied by every classification label is a rule somebody has to be able to execute, in every system that holds a copy.
What the policy page states
Scope, who owns it, that records are kept only as long as there is a reason, that the reason is either a legal or contractual obligation or a stated business need, that the schedule is the authority for periods, and how records are destroyed at the end. Five or six sentences. Keeping the periods themselves out of the signed page is what lets you correct a period without asking everybody to agree again.
Why categories multiply by labels
A retention rule that ignores classification is either too short for the confidential copy or too long for the public one. If your scheme has three labels, each category needs a rule for each label it can appear under, which is why a modest nine categories and three labels is already twenty-seven rules. That number is worth seeing before you commit to the periods, because each rule has to be executable in every system holding a copy.
The half that is already decided for you
Payroll and tax records, safety records, and anything a customer contract obliges you to keep have periods set outside the organisation, and the policy should say so rather than restate them as choices. Separating the decided from the discretionary is the fastest way to shrink the drafting: in most small organisations about half the schedule is not yours to choose, and the argument is only ever about the other half.
Destruction, which is the part that gets forgotten
A retention period with no disposal step is a maximum nobody enforces. Say who destroys, how, and how it is evidenced, and remember the backups. NIST's media sanitization guidance frames the decision the useful way round: the sanitization method follows from the confidentiality categorisation of the information, so the classification scheme is doing double duty at both ends of the record's life.
Questions people ask about data retention policy
How long should we keep things by default?
Pick a defensible default for anything with no legal period, write it down, and revisit it. A stated default is enforceable; an unstated one becomes forever.
Do backups have to follow the schedule?
They have to be addressed by it. Many organisations state a shorter backup cycle and accept that a record may survive in a backup for that window. What does not work is not mentioning backups.
Who signs a retention policy?
Everybody it binds, against the version in force. The schedule beneath it changes without a new signature, which is exactly why the two are separate documents.