How Long Should Your Business Keep Data? A Data Retention Guide for St. Louis Small Businesses

Let me ask you something: If you found a box of old business files in your office closet, would you know which ones you could safely throw away?

Most business owners would hesitate. You might worry that an old email contains an important agreement, that a tax document could be needed later, or that deleting a client file could create a legal problem.

So you keep everything.

It makes sense. But keeping every file forever is not the same as protecting your business.

The short answer: It depends on the type of data

There is no single data retention period that applies to every business record in Missouri. The right answer depends on what the information contains, why you created it, which regulations apply, and whether you may need it for an audit, dispute, or legal claim.

For many St. Louis small businesses, a practical starting point looks like this:

  • Tax and accounting records: Often seven years after the end of the tax year
  • Payroll and employment tax records: At least three to four years, depending on the record and applicable rule
  • Routine email: Often two to three years
  • Important business email: Retain with the related contract, financial, or HR record
  • Client files and contracts: Commonly five to seven years after completion or the last transaction
  • Hiring records: At least one year in many cases
  • Personnel files: Often seven to ten years after termination as a risk-based practice
  • Covered employee medical records: Employment duration plus 30 years under applicable OSHA rules

These are planning guidelines, not legal advice. Your attorney, CPA, or compliance professional should review any formal policy for your industry.

Why keeping everything forever creates risk

Think about your business data like the contents of your home.

You would not keep every receipt, expired credit card, old prescription, and duplicate key forever. The more sensitive items you leave lying around, the more difficult it becomes to protect the things that actually matter.

Your digital records work the same way.

Keeping unnecessary data forever can create:

  • Higher storage and backup costs
  • More files for employees to search through
  • Greater exposure during a ransomware attack or data breach
  • More sensitive information sitting in old email accounts
  • Confusion about which document is the official version
  • Increased legal and compliance risk if information is mishandled

And here’s where it gets scary: A forgotten spreadsheet containing Social Security numbers or banking details can be just as sensitive as the information you actively use today.

Deleting data on a schedule is not careless. When done correctly, it is part of a responsible data protection strategy.

Organized business records representing email, financial, client, and HR data categories

A practical data retention guide for small businesses

1. Email: keep the important messages, not every message

Email is often where retention policies become confusing.

A routine scheduling message usually does not need to be kept for seven years. A message approving a contract, changing payment terms, documenting an employee decision, or confirming a customer commitment is different.

Treat important email as a business record.

A practical approach is:

  • Keep routine operational email for two to three years
  • File contract-related messages with the appropriate client or legal record
  • Keep financial and tax-related messages with the records supporting that tax year
  • Keep important HR messages with the employee’s personnel documentation
  • Avoid storing sensitive information such as passwords, payment details, or Social Security numbers in email

Missouri generally focuses on what a record documents rather than whether it is stored as paper, a PDF, or an email. The content determines its importance.

2. Financial and tax records: seven years is a common business standard

The IRS generally advises businesses to keep many tax records for at least three years, with longer periods applying in certain circumstances.

Missouri tax guidance commonly requires relevant records to be retained for at least three years after the related tax becomes due or is paid, whichever is later. You can review the Missouri Employer’s Tax Guide and the IRS guidance on how long to keep business records.

Why do many businesses choose seven years?

It creates a simple, conservative schedule for invoices, receipts, bank statements, ledgers, expense reports, and supporting tax documents. It can also make audits, insurance questions, financing requests, and historical reviews easier to manage.

Keep certain records longer or permanently when appropriate, including:

  • Ownership and formation documents
  • Major contracts and loan agreements
  • Intellectual property records
  • Property records
  • Documents related to unresolved disputes

Your CPA can help determine which financial records require special treatment.

3. Client files: retain what supports the relationship

Client files may include contracts, proposals, invoices, project records, communications, and completed work.

There is not one universal Missouri retention period for every private-sector client file. Instead, consider the purpose of each record.

A reasonable starting point is to keep:

  • Contracts for the length of the agreement plus five to seven years
  • Financial records for at least seven years after the last transaction
  • Project documentation for five to seven years after completion
  • Warranty or service records for the applicable warranty period plus a reasonable buffer

If the file contains personal, medical, financial, or confidential information, apply stronger security controls and use the stricter retention period when categories overlap.

4. HR records: separate ordinary personnel files from sensitive medical data

Employment records often need more careful planning than business owners expect.

Under the Fair Labor Standards Act, employers generally retain payroll records for at least three years and wage-computation records, such as time cards and schedules, for at least two years. The Department of Labor’s recordkeeping guidance explains these minimums.

The IRS requires employment tax records to be retained for at least four years after the tax is due or paid, whichever is later. Missouri withholding guidance generally uses a three-year minimum.

Many small businesses choose a five- to seven-year schedule for payroll and wage records to avoid managing several overlapping deadlines.

For other HR records:

  • Keep hiring and recruiting records for at least one year, when applicable
  • Consider retaining general personnel files for seven to ten years after termination
  • Keep workers’ compensation records for at least five years, or longer if a claim remains open
  • Store medical and accommodation information separately from general personnel files
  • Follow the OSHA medical-record requirements when they apply, including the employment duration plus 30-year rule for covered records

Here’s the important distinction: A personnel file and an employee medical file should not automatically live in the same folder.

Retention is not the same as backup

Now imagine that your retention policy says you need to keep a client contract for seven years.

Where does that contract live?

If it exists only on one employee’s laptop, you have a retention problem. If it is in Microsoft 365 but has never been backed up independently, you may have a recovery problem.

Cloud applications provide availability, but they do not always provide the complete backup and recovery protection your business needs. That is why it is important to understand whether your business really needs SaaS backups.

A good data protection plan combines:

  • A written retention schedule
  • Secure cloud storage
  • Automated backups
  • Tested recovery procedures
  • Access controls and multi-factor authentication
  • A process for securely deleting expired records

Backups should preserve the information you still need. They should not become an excuse to keep every piece of data forever.

Two professionals reviewing a cloud backup and data recovery plan for a small business

How to build a manageable retention policy

So, what can you do first?

Start small. You do not need to classify every file in one afternoon.

Step 1: Create a data inventory

List where your business stores information:

  • Email and Microsoft 365
  • Accounting and payroll software
  • Shared drives
  • Cloud applications
  • Employee laptops
  • Customer relationship systems
  • Paper files and removable drives

Step 2: Group data by business purpose

Use clear categories such as financial, client, HR, legal, operational, and marketing.

The goal is to identify what the data is: not just where it happens to be stored.

Step 3: Assign a retention period

Choose a period based on legal requirements, business needs, and risk. When a record fits multiple categories, use the longer or stricter period until a qualified professional advises otherwise.

Step 4: Define secure disposal

Expired paper files should be shredded. Digital records should be securely deleted from active systems and addressed in backup policies.

Do not simply move sensitive files to an “old” folder where they remain accessible indefinitely.

Step 5: Add a legal hold process

A legal hold means pausing normal deletion when you reasonably expect litigation, an audit, an investigation, or another formal dispute.

This step matters. A file scheduled for deletion should not be removed if it may be relevant to a current issue.

Step 6: Review the policy annually

Your business changes. Your software changes. Regulations change.

Review the policy at least once a year and whenever you add a new cloud application, open a location, hire employees, or begin handling more sensitive information.

How St. Louis businesses can make retention easier

Whether your business operates in St. Louis, St. Charles County, Chesterfield, Clayton, O’Fallon, the Metro East, or elsewhere in Missouri, the challenge is usually the same: You need access to useful records without creating a permanent warehouse of sensitive data.

That is where professional support can help.

St. Louis managed IT services can bring structure to storage, access, backups, security updates, and recovery planning. A proactive IT strategy helps you identify where information lives before an outage or breach exposes the gaps.

You may also need:

And ransomware protection must be part of the conversation. Your retention policy cannot help if an attacker encrypts the only copies of your records. Review this ransomware protection guide for practical security fundamentals.

Platinum Web Services also provides 24/7 support for IT emergencies, because data loss and security incidents do not wait for convenient business hours.

Keep what matters. Protect it. Dispose of the rest.

A strong data retention policy is not about deleting your history. It is about knowing what your business must preserve, how long you need it, and how to protect it while you keep it.

You should not have to choose between keeping everything and risking data loss.

With the right retention schedule, secure cloud services, tested backups, and dependable data recovery planning, you can keep the records that support your business without carrying unnecessary risk forever.

If you would like help reviewing your data retention and protection strategy, contact Platinum Web Services. We help small businesses across St. Louis and Missouri turn complicated IT decisions into a clear plan.

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *