retention policy for invoice PDFs and extracted data
Defines retention for invoice documents and extracted data. Use for compliance and storage management. Not for backup strategy.
TL;DR
Keep invoices as long as tax and audit rules require (often 7+ years), then delete: indefinite retention is a breach liability, not an asset. Store originals immutably, keep extracted data linked, and purge PII-containing intermediates (OCR crops, email bodies) on a shorter cycle. Automate the lifecycle; manual purges never happen.
Steps
- Set retention by jurisdiction (tax law governs).
Expected: A compliant schedule.
- Store originals immutable (WORM).
Expected: Tamper-proof archives.
- Purge intermediates (crops, raw emails) sooner.
Expected: Reduced exposure.
- Automate deletion at end of life.
Expected: It actually happens.
- Log all purges.
Expected: Proof of compliance.
When to use
- Compliance programs
- Storage cost control
- Data minimization
When not to use
- Backup and DR
- Active document management
- Legal holds (suspend deletion)
Compatibility
Storage-agnostic; S3 Object Lock, etc.
Variant phrasings
invoice retention policy
AP document retention
how long keep invoices
Root cause
Tax authorities require years of records; privacy law punishes hoarding. A scheduled lifecycle satisfies both.
Edge cases
- Legal holds suspend deletion; integrate with legal
- Jurisdictions differ; apply the longest applicable
- Anonymized analytics copies can outlive source documents
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_O-yqq6dkm-TW0tc5pgZ32A
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.