Project Record Retention: Backups, Archives and Legal Holds

Backups are not archives. Learn how contractors should handle project record retention, preserve evidence during disputes and delete data safely when allowed.

3 min readBy Ironfield Cyber Team

Contractors generate records for years: contracts, change orders, daily reports, photos, correspondence, submittals, payroll and more. Questions about how long to keep them, where to store them and when to delete them often get answered by accident. Files accumulate on servers and cloud platforms until someone cleans up, or until a dispute makes everyone wish the cleanup had not happened.

Backups, archives and retention policies serve different purposes. Mixing them up leads to gaps and unnecessary risk.

Backups are not archives

A backup is a copy of data for recovery after loss, corruption or attack. It is designed for restoring systems to a recent state, and older copies are typically rotated out.

An archive is a long-term store of records you must or want to keep, organized so you can find specific items years later.

A retention policy says how long each type of record is kept and when it is destroyed.

Relying on backups as your archive is risky. Backups are often not searchable, may not preserve the right versions and are usually deleted on a schedule that has nothing to do with your legal needs.

Decide what to keep, and for how long

Retention periods depend on contracts, laws and industry practice. Your attorney, your insurer and your accountant can tell you what applies. Considerations include:

  1. Contract requirements, including owner and government terms
  2. Warranty and claim periods, which can be long for construction work
  3. Tax and payroll record requirements
  4. Safety and regulatory documentation obligations
  5. Insurance policy conditions

Create a simple schedule that lists each record category, the retention period, the owner and the storage location. Do not guess at legal periods. Confirm them.

Build a workable archive

Choose a location

Use a controlled repository with access limits, MFA and audit logs, separate from active working files. Cloud storage, a records platform or a managed file store can all work if configured carefully.

Organize it

Use a consistent structure by project and category. Include an index so staff can find what they need. Keep metadata, such as dates and authors, intact.

Preserve formats

Choose formats that will remain readable. Open formats such as PDF for documents are helpful. Keep original files when they matter, such as native models or photos with metadata.

Protect and back it up

An archive needs its own backup, preferably isolated from your main network. Test restoring from it. Records you cannot retrieve are not really kept.

Legal holds

When a dispute, claim, investigation or lawsuit is reasonably anticipated, you may be required to preserve relevant records, even if your retention schedule would normally allow deletion. This is called a legal hold, and failure to preserve evidence can have serious consequences.

Practical steps:

  • Know who can authorize a hold, usually with counsel
  • Be able to suspend automatic deletion in email, file storage and backups quickly
  • Identify the people and systems that hold relevant records, including personal phones and messaging apps
  • Record what was preserved and when
  • Release the hold only when counsel confirms it is appropriate

Ask your attorney to help you build this process before you need it.

Delete safely and on schedule

Keeping everything forever is not a safe default. Old data increases exposure if you are breached and adds cost. When the retention period ends and no hold applies:

  1. Confirm approval from the record owner.
  2. Delete from all locations, including archives, shared drives and backups where practical.
  3. Use secure deletion for sensitive data.
  4. Document what was deleted and when.

If a contract requires return or destruction of data, such as CUI at the end of a project, follow those terms and keep proof.

Handle personal data with care

Records often include employee information, bank details and identification numbers. Limit access, protect them with encryption and delete them when no longer needed.

Common mistakes

  • Treating backup copies as the archive
  • Keeping everything with no schedule or owner
  • Deleting records during an ongoing dispute
  • Leaving project records on departing employees' devices
  • Forgetting records in cloud platforms and messaging apps
  • Having no way to find records quickly

A hypothetical example

Consider a hypothetical subcontractor served with a claim for work completed several years ago. Email auto-deletes after one year, and the project platform account was closed after the job ended. Without a retention schedule or a hold process, the company cannot show its daily reports or correspondence. A defined archive and hold procedure would have preserved them.

Getting organized

Ironfield Cyber helps contractors and energy companies align backups, archives and retention schedules and set up processes to preserve records when it matters. If your project records are scattered or kept by default, we can help you build a plan that works with your counsel's guidance.