Keeping business records for the long term: retention, archiving and formats that stay readable

Backups protect against loss; archives keep records usable for years. How to set retention periods, archive data from old systems, keep files readable and destroy records safely.

Businesses create records constantly: invoices, contracts, payroll, timesheets, drawings, inspection results, test certificates, safety records, emails and the data held in accounting, job and quality systems. Most are used intensively for a few weeks or months and then rarely touched. Yet some must be produced years later, for a tax review, a warranty claim, a workplace injury claim, a product recall, a legal dispute or simply to repair a machine built a decade ago.

Keeping records for the long term is harder than it looks. Systems are replaced, file formats become unreadable, the people who understood the data leave, and storage fills with material nobody can find or safely delete. At the same time, keeping everything forever is neither cheap nor lawful in every case: personal information should not be kept once it is no longer needed.

This article explains the difference between backups and archives, how to decide how long to keep records, how to build a simple retention schedule, how to archive data from systems being retired, how to keep files readable over many years, how to store archives securely and how to destroy records properly. It is general information for Australian business owners and managers, not legal advice; retention obligations depend on the business and its industry.

Backups are not archives

Backups and archives are often confused, but they serve different purposes:

BackupArchive
PurposeRecover from loss, damage or attackKeep records available for future reference
ContentsCopies of current systems and filesRecords no longer in active use
Time horizonDays to monthsYears to decades
Typical useRestore after failure, ransomware or deletionRetrieve a specific record for a question or claim
Key requirementFast, complete restorationFindability, integrity and readability over time

A backup from five years ago is a poor archive. It may need the old system to restore it, it may hold records in a format nobody can read, and finding one invoice may mean restoring an entire server. Businesses need both: backups to recover from incidents, covered in the business continuity planning for small businesses article, and archives to keep records usable for as long as they are needed.

How long to keep records

Retention periods come from three sources: legal requirements, the possibility of claims, and genuine business needs.

Some Australian requirements commonly apply to businesses. For example:

RecordsTypical requirement
Tax records, such as income, expenses and GSTThe Australian Taxation Office generally requires business records to be kept for five years
Company financial recordsCompanies must keep financial records for seven years under the Corporations Act
Employee records, such as pay, hours and leaveEmployers must keep employee records for seven years under the Fair Work Act
Work health and safety recordsPeriods vary by record; for example, records of notifiable incidents must generally be kept for at least five years, and some health monitoring records for decades

Other obligations apply in particular industries, such as food, therapeutic goods, building, transport, financial services and chemicals. Requirements change, and the exact starting point of each period matters, so confirm current obligations with your accountant, lawyer or industry body.

Claims and disputes

Records may be needed to defend or pursue claims long after legal retention periods end. Limitation periods for contract and negligence claims are commonly around six years from when the claim arises, and claims about defective products or building work can arise up to ten years or more after supply or completion in some circumstances. A design record, inspection report or delivery record may be the business’s best evidence. Retention decisions for such records should consider the likely life of the product or structure and the potential exposure.

Business needs

Some records are worth keeping because the business uses them: drawings and specifications for products still in service, maintenance histories for equipment, customer purchase histories, cost data for estimating and lessons from past projects.

Personal information: do not keep it forever

Keeping records longer than needed has risks as well as costs. Where the Privacy Act applies to a business, the Australian Privacy Principles require reasonable steps to destroy or de-identify personal information that is no longer needed for a permitted purpose, unless the law requires it to be kept. Old records containing personal information also increase the harm of a data breach. Retention schedules should therefore set maximum periods as well as minimum ones for records containing personal information, such as job applications, customer identity documents and former employees’ details. The privacy policies for small business websites article explains when the Privacy Act applies to small businesses.

Building a retention schedule

A retention schedule lists the kinds of records the business holds and how long each is kept. It does not need to be elaborate.

  1. List record types by function: finance, payroll and people, sales and customers, purchasing, engineering and products, quality, safety, projects, legal and corporate.
  2. Identify the system or location where each is held, including paper files, shared drives, email and business systems.
  3. Set the retention period for each, based on legal requirements, claim exposure and business need, and state when the period starts, such as from the end of the financial year, the end of employment or the end of the product’s life.
  4. Set the action at the end, such as destroy, de-identify, review or keep permanently.
  5. Assign an owner for each record type.
  6. Review the schedule every year or two, and when laws, systems or the business change.
Record typeLocationRetentionStarts fromThenOwner
Sales invoicesAccounting system7 yearsEnd of financial yearDestroyFinance manager
Employee pay recordsPayroll system7 yearsDate of recordDestroyPayroll officer
Unsuccessful job applicationsHR folder12 monthsDecision dateDestroyHR officer
Product drawings and specificationsEngineering systemLife of product plus 10 yearsProduct discontinuedReviewEngineering manager
Inspection and test recordsQuality systemLife of product plus 10 yearsDate of recordReviewQuality manager

The periods in this table are illustrative, not recommendations; set your own with appropriate advice.

When a dispute, claim or investigation is underway or reasonably anticipated, relevant records must be preserved even if their retention period has ended. Destroying such records can have serious consequences in legal proceedings and, in some jurisdictions, can be an offence. A simple legal hold procedure lets a manager suspend destruction of specified records until the matter is resolved.

Archiving data from systems being retired

When an accounting, job or quality system is replaced, its historical data often cannot be fully migrated. Archiving it well requires more than a final backup:

  • Export the data in open, documented formats, such as CSV files for tables and PDF for reports and documents.
  • Document what the data means: table and field descriptions, code lists and how records relate. Without this, future readers may not understand what they find.
  • Produce key reports in readable form, such as annual ledgers, customer histories and stock movement histories, which are often easier to use than raw tables.
  • Keep attachments linked to the records they belong to, using consistent identifiers in file names or an index.
  • Provide a simple way to search, such as a small read-only database or searchable files.
  • Test retrieval by answering realistic questions from the archive before switching off the old system.
  • Record what was archived, where, in what format and for how long.

Keeping the old system running indefinitely in read-only mode is an alternative, but it carries licence, security and maintenance costs, and old software may eventually become impossible to run.

Email and messaging

Email often holds the only record of approvals, variations, customer instructions and supplier commitments, yet it usually sits in individual mailboxes that disappear when people leave. Good practice is to save important emails with the record they relate to, such as the job, contract or product file, rather than relying on personal inboxes. Decide what happens to a departing employee’s mailbox before they leave, and consider whether messaging apps used for work, such as chat groups with site teams, also hold records the business needs to keep.

Formats that stay readable

Digital records can become unreadable even when the files survive intact, because the software needed to open them is no longer available. Reduce this risk by choosing formats designed for long-term use:

Record typeFormats suited to long-term keeping
DocumentsPDF/A, the archival form of PDF defined in the ISO 19005 standard
Tables and structured dataCSV or other plain-text formats, with documentation
ImagesTIFF or high-quality JPEG for photographs; PNG for graphics
DrawingsPDF for drawings; neutral 3D formats such as STEP alongside native CAD files
EmailExport to standard formats or a dedicated archive that can export them

Practical habits help:

  • Prefer open, widely supported formats over proprietary ones for archives.
  • Keep native files as well where they hold information that open formats lose, such as editable CAD models, but do not rely on them alone.
  • Check archives periodically, opening samples to confirm they are still readable.
  • Migrate formats when needed, before the software to read them disappears.

Storing archives securely

Archives need protection from loss, alteration and unauthorised access:

  • Keep more than one copy, in different places, following the familiar principle of several copies on different media with at least one held off-site.
  • Check integrity using checksums or archive tools that detect corruption.
  • Refresh storage media before it ages; hard drives, tapes and optical discs all have limited lives.
  • Control access, especially for records containing personal, financial or commercially sensitive information.
  • Encrypt sensitive archives, and keep the means of decrypting them for as long as the archive must be readable.
  • Know where cloud archives are stored and how they can be retrieved if the service or the business relationship ends.
  • Protect paper records from fire, water and pests, and record what is in each box.

The cyber security basics for small businesses article covers the wider controls that protect business data.

Destroying records properly

At the end of a retention period, records should be destroyed or de-identified deliberately, not left to accumulate:

  • Confirm the period has ended and no legal hold applies.
  • Destroy securely: shred or pulp paper, and use secure deletion or physical destruction for storage devices, including old computers, phones, copiers and backup media.
  • Use reputable providers for large volumes, and obtain certificates of destruction.
  • Record what was destroyed, when and under what authority, without keeping the content itself.

A worked example

This is an illustrative example. An engineering services and fabrication business with 60 staff has 18 years of records: about 400 archive boxes of paper job files in off-site storage, a job management system due for replacement, and shared drives holding drawings, photos and documents.

Retention schedule. With its accountant and lawyer, the business sets retention periods for each record type. Finance and payroll records are kept for seven years. Design drawings, calculations and inspection records for fabricated structures are kept for the life of the structure plus ten years, reflecting potential claims. Unsuccessful job applications are destroyed after 12 months.

Paper archive. A review of the 400 boxes finds that about 180 contain only finance and administration records older than seven years, which are securely destroyed with certificates. Design and inspection records from older jobs are scanned to PDF/A with an index by job number and customer, and the original boxes are retained where originals may be needed. Storage fees fall by roughly 45%.

System retirement. Before the old job system is switched off, its data is exported to CSV with documentation of each field, annual reports are saved as PDF, and attachments are linked by job number. Staff test the archive by answering ten realistic questions, including retrieving the inspection records for a structure built 12 years earlier.

Result. The business can find old records in minutes, has reduced storage costs and privacy risk, and has a schedule that tells staff what to keep and what to destroy.

Applying this in an Australian business

  • Separate backups and archives, and make sure you have both.
  • Build a retention schedule with minimum and, for personal information, maximum periods.
  • Confirm legal requirements with your advisers for tax, company, employee, safety and industry records.
  • Archive retired systems properly, with documentation and tested retrieval.
  • Use open, long-lived formats for archives.
  • Protect archives with multiple copies, integrity checks and access control.
  • Destroy records securely when periods end, unless a legal hold applies.

Questions worth considering

  • Could we find and read a specific record from ten years ago, and how long would it take?
  • Do we know how long each kind of record must be kept?
  • Which old systems hold data we might need, and could we still read it if they stopped working?
  • Are we holding personal information longer than we need to?
  • Who decides when records can be destroyed, and how is that recorded?

Bringing it together

Long-term record keeping protects a business in tax reviews, claims, recalls and disputes, and preserves knowledge it would otherwise lose. Backups recover from incidents; archives keep records usable for years. Build a retention schedule from legal requirements, claim exposure and business needs, set maximum periods for personal information, archive data from retired systems with documentation and tested retrieval, choose formats that stay readable, protect archives and destroy records securely when their time has passed.


Source: KEVOS editorial notes, drawing on general records management and information systems practice. Retention requirements are summarised for orientation only and should be confirmed with your advisers and the relevant authorities. The worked example is illustrative. This article provides general information and does not constitute legal advice.

Need practical engineering, manufacturing or process support? KEVOS can help move the work forward.