## TL;DR

Keep invoices as long as tax and audit rules require (often 7+ years), then delete: indefinite retention is a breach liability, not an asset. Store originals immutably, keep extracted data linked, and purge PII-containing intermediates (OCR crops, email bodies) on a shorter cycle. Automate the lifecycle; manual purges never happen.

## Steps

1. Set retention by jurisdiction (tax law governs).
   Expected: A compliant schedule.
2. Store originals immutable (WORM).
   Expected: Tamper-proof archives.
3. Purge intermediates (crops, raw emails) sooner.
   Expected: Reduced exposure.
4. Automate deletion at end of life.
   Expected: It actually happens.
5. Log all purges.
   Expected: Proof of compliance.

## When to use

- Compliance programs
- Storage cost control
- Data minimization

## When not to use

- Backup and DR
- Active document management
- Legal holds (suspend deletion)

## Compatibility

Storage-agnostic; S3 Object Lock, etc.

## Variant phrasings

### invoice retention policy

### AP document retention

### how long keep invoices

## Root cause

Tax authorities require years of records; privacy law punishes hoarding. A scheduled lifecycle satisfies both.

## Edge cases

- Legal holds suspend deletion; integrate with legal
- Jurisdictions differ; apply the longest applicable
- Anonymized analytics copies can outlive source documents

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_O-yqq6dkm-TW0tc5pgZ32A
