Do you really need that HR policy from 2010? A retention-first mindset for M365
Storage is cheap, retention is expensive. Keeping everything indefinitely stopped being a defensible position around the time GDPR was drafted. Here is how to have the retention conversation with the people who own the data.
"We might need it one day" is not a retention policy. It is the absence of one. And in 2026 it is also a regulatory liability — the ICO, GDPR and every industry-specific equivalent expect you to retain personal data only for as long as it is needed for the purpose it was collected.
The 2010 HR policy question
Pick a document. Say, the HR expenses policy from 2010. Is anyone using it? No — the 2024 revision superseded it. Is it referenced elsewhere? Search the tenant — probably not. Does keeping it help anyone? Genuinely, no. Does keeping it expose you? If it contains employee names or bank details it is subject to GDPR retention rules, even though nobody is looking at it.
Now multiply that by a decade of accumulated PDFs.
A retention conversation that works
The mistake most IT teams make is trying to write the retention policy on behalf of the business. That never survives contact with a data owner who has never thought about it. What does work:
- Group the tenant by data class — HR, Finance, Legal, Marketing, Engineering, etc.
- For each class, put in front of the owner the top 20 largest and oldest documents.
- Ask three questions per document: "Do you need this? For how long? Where should it live?"
- Codify the answers as retention labels. Turn them on for future content, then run a bulk-apply on the historical corpus.
TSO produces step 2 automatically — the ranked list of oldest largest files per site, ready to hand to the data owner. The conversation is much shorter when the person on the other side of the table is looking at their own files, not a spreadsheet full of GUIDs.
