Employee Owned Since 2022  |  Serving Chicagoland since 1996Support: 630-523-0220Sales: 630-526-8030Remote support

Compliance whitepaper | Insurance

Data Retention and Secure Disposal for Agencies

Decide what to keep, how long to keep it, and how to destroy it

  • Published September 25, 2026
  • 4 min read

Agencies collect years of applications, policy files, emails, and scanned IDs. Without a data retention policy, that information piles up and raises your risk over time. This guide explains how to decide what to keep, how long to keep it, and how to dispose of the rest safely.

Why keeping everything is risky

Many agencies keep every file forever, just in case. However, old data creates real exposure. If an attacker gets in, they can steal records for clients who left long ago.

Old data also slows searches, raises storage costs, and complicates AMS migrations. In addition, you may have to notify former clients after a breach, even if you no longer serve them.

Finally, a clear policy makes your agency easier to defend. When a regulator or carrier asks how you manage records, you can show a schedule instead of a shrug.

Know your legal and contractual requirements

Retention rules come from several places. State insurance regulations often require producers to keep certain records for a set number of years. Carrier agreements may add their own terms, and errors and omissions concerns may favor keeping some files longer.

Other rules push the opposite way. For example, some state data security and privacy laws expect you to dispose of personal information once you no longer need it. Because these rules vary, confirm your schedule with counsel and review each carrier contract.

Build a simple data retention schedule

A retention schedule lists each type of record, how long you keep it, and who approves disposal. Keep it short, so staff will actually follow it.

  • Policy and client files. Keep them for the period your state and carriers require, measured from policy expiration.
  • Applications and signed forms. Follow the same period as the related policy.
  • Scanned IDs and Social Security numbers. Keep them only while the business need lasts, then purge.
  • Accounting and premium trust records. Follow state and tax requirements.
  • Email. Set retention by mailbox type, with longer periods for client service mailboxes.
  • Employee records. Follow employment law guidance from your HR advisor.

Apply retention in your systems

A policy only works when systems enforce it. First, check what your AMS can do. Many systems can archive or purge records after a set period, although settings vary by vendor.

Next, look at Microsoft 365. Retention policies can keep email for a required period and then delete it automatically. Also, clean up shared drives, desktops, and download folders, because sensitive files often hide there.

Finally, remember backups. Old backups can hold data long after you delete it from live systems. So align backup retention with your schedule where possible.

Scanned IDs often end up in several places at once. For example, one driver’s license image may sit in the AMS, an inbox, and a scanner folder. Clean up those extra copies first, because they carry the most risk.

Dispose of paper and devices securely

Secure disposal applies to paper and hardware, not just files. For paper, use locked shred bins and a shredding vendor that provides a certificate of destruction.

For devices, deleting files or reformatting a drive is not enough. Instead, follow a recognized standard such as NIST SP 800-88, which describes ways to clear, purge, or destroy media. Copiers and multifunction printers also store scanned images, so wipe or destroy their drives when a lease ends.

Keep a disposal log for each device, with the serial number, method, and date. This record shows regulators and carriers that you followed your policy.

Handle legal holds and exceptions

Sometimes you must stop deleting. For example, a claim dispute, lawsuit, or regulatory inquiry may require you to preserve related records. In that case, suspend disposal for those files until counsel says otherwise.

Also, decide who can approve exceptions. That way, staff know what to do when a client asks you to delete their data or when a hold ends.

Write down the reason for each hold, the records it covers, and who approved it. Then review open holds regularly, so records do not sit frozen for years without a reason.

How WEBIT helps

WEBIT helps agencies turn data retention rules into working settings in Microsoft 365, file shares, and backups. Through vCIO and vCISO advisory, we also help you plan cleanups before an AMS migration. Learn more about our strategic IT services.

When devices reach end of life, we coordinate secure wiping or destruction and document each step. Our managed compliance add-on can also help you track policies and evidence over time. Contact us to get started.

Key takeaways

  • Keeping everything forever increases breach exposure and cost.
  • Base your data retention schedule on state rules, carrier contracts, and advice from counsel.
  • Enforce retention in your AMS, Microsoft 365, file shares, and backups.
  • Wipe or destroy drives, including copier drives, and keep a disposal log.

Talk to an owner

Want help putting this guide into practice? A 30-minute discovery call gets you honest advice for your environment.

Schedule a discovery call

Insurance IT services

See how WEBIT supports insurance organizations across Chicagoland.

Explore Insurance IT →

More Insurance whitepapers

Browse the full library of guides for your industry.

All Insurance whitepapers →

Two new clients per month. Maximum.

Ready to talk to an owner?

Every conversation starts with an honest look at where you are today. No pressure, no pitch deck, and no obligation.