A legal request arrived for a complete case file from 2012. We hold records for that period because we are required to, the retention policy says so, the storage is paid for, and an auditor had confirmed the arrangement twice. It took nine weeks to produce the file and two of the four parts were never recovered at all.
The problem was never whether the data existed. It was whether anything could read it.
The original system was retired in 2015. What we kept was a database export in the vendor's own format, which requires the vendor's software, which requires a licence server that was switched off with the rest of the estate. The scanned correspondence was in a proprietary image container produced by a document platform whose supplier no longer exists. One set of records was a backup of a database engine whose last supported version will not install on any operating system we are allowed to run. And the part we did recover arrived as a table of codes: status values, product identifiers and branch numbers whose meanings lived in the retired application's configuration, not in the export. We had the rows and no way to say what any of them meant.
None of this was a storage failure. Every byte we intended to keep was still there, backed up and replicated, on media we could read. We had conflated keeping data with being able to use it, and the policy only ever mentioned the first.
There are three honest options for anything held beyond the life of the system that made it, and the choice has to be made deliberately. Keep the application running, which is expensive and gets more expensive. Migrate to a format that can be read without a specific product, carrying the reference data and field definitions alongside it so the records interpret themselves. Or accept that the material will become unreadable, write that down, and let the people who own the obligation decide whether that is acceptable.
We now test readability rather than assume it. Once a year we pick a random record from each archive and retrieve it end to end, the way a request would. The first year, two of seven archives failed.
Retention is a storage decision. Readability is a commitment with an annual cost, and only one of them was in the policy.
– Serguey Shinder
Top comments (0)