data-retention-and-destruction-policy

Drafts a law firm Data Retention and Destruction Policy covering practice-area retention schedules, secure destruction procedures, legal hold protocols, and compliance infrastructure. Trigger when establishing or updating records management frameworks, drafting retention schedules by matter type, or implementing secure destruction procedures for paper and electronic records.

11 stars

Best use case

data-retention-and-destruction-policy is best used when you need a repeatable AI agent workflow instead of a one-off prompt.

Drafts a law firm Data Retention and Destruction Policy covering practice-area retention schedules, secure destruction procedures, legal hold protocols, and compliance infrastructure. Trigger when establishing or updating records management frameworks, drafting retention schedules by matter type, or implementing secure destruction procedures for paper and electronic records.

Teams using data-retention-and-destruction-policy should expect a more consistent output, faster repeated execution, less prompt rewriting.

When to use this skill

  • You want a reusable workflow that can be run more than once with consistent structure.

When not to use this skill

  • You only need a quick one-off answer and do not need a reusable workflow.
  • You cannot install or maintain the underlying files, dependencies, or repository context.

Installation

Claude Code / Cursor / Codex

$curl -o ~/.claude/skills/data-retention-and-destruction-policy/SKILL.md --create-dirs "https://raw.githubusercontent.com/CaseMark/skills/main/skills/legal/data-retention-and-destruction-policy/SKILL.md"

Manual Installation

  1. Download SKILL.md from GitHub
  2. Place it in .claude/skills/data-retention-and-destruction-policy/SKILL.md inside your project
  3. Restart your AI agent — it will auto-discover the skill

How data-retention-and-destruction-policy Compares

Feature / Agentdata-retention-and-destruction-policyStandard Approach
Platform SupportNot specifiedLimited / Varies
Context Awareness High Baseline
Installation ComplexityUnknownN/A

Frequently Asked Questions

What does this skill do?

Drafts a law firm Data Retention and Destruction Policy covering practice-area retention schedules, secure destruction procedures, legal hold protocols, and compliance infrastructure. Trigger when establishing or updating records management frameworks, drafting retention schedules by matter type, or implementing secure destruction procedures for paper and electronic records.

Where can I find the source code?

You can find the source code on GitHub using the link provided at the top of the page.

SKILL.md Source

# Data Retention and Destruction Policy

Generates a firm-wide records management policy governing client file lifecycles, retention periods by practice area, secure destruction methods, legal holds, and audit requirements.

## Prerequisites

- Firm profile — practice areas, office locations, jurisdictions
- Current systems — DMS, cloud storage, email, backup infrastructure
- State bar rules — jurisdiction-specific ethics rules on client files
- Existing policies — information security, conflicts, client intake
- Vendors — certified document destruction services in use

## Quick Start

1. Gather firm profile and current systems inventory
2. Map applicable regulatory authorities to practice areas
3. Draft retention schedule by record category
4. Define destruction procedures (paper + electronic)
5. Establish legal hold protocol
6. Assign roles and build audit/training infrastructure

## Workflow

### 1. Regulatory Framework

Cite applicable authorities in the policy introduction:

| Authority | Applicability |
|---|---|
| ABA Model Rules 1.6, 1.15 | Confidentiality; safekeeping client property |
| State ethics rules | Jurisdiction-specific mandates (controls where more stringent) |
| Sarbanes-Oxley | Securities-related matters |
| HIPAA | Health law practices |
| IRS / IRC § 6001 | Tax work; 7-year documentation standard |

### 2. Scope

**Covered:** Client matter files, financial records (trust ledgers, billing), intake records (conflict databases, engagement letters), electronic records (email, cloud, mobile, backups), third-party collaboration platforms.

**Excluded:** Original client-owned documents (wills, deeds, certificates) — return on matter close; destruction requires written client authorization. Transitory communications (scheduling, duplicates) — delete promptly.

**Bound parties:** All firm personnel and third-party providers under confidentiality agreements.

### 3. Retention Schedule

| Record Category | Minimum Retention | Basis |
|---|---|---|
| General litigation / transactional | 6 yrs post-close | Malpractice SOL + margin |
| Estate planning | Permanent or client death + admin + SOL | Latent claim risk |
| Real estate | 7–10 yrs post-close | Title / environmental latency |
| Corporate formation / governance | Entity life + 7 yrs post-dissolution | Ongoing relevance |
| Tax preparation | 7 yrs post-filing | IRS extended audit period |
| Trust account records | 6 yrs or state bar rule (whichever longer) | Ethics rules |
| Firm accounting | 7 yrs | Tax audit exposure |
| Conflict / intake records | Duration of firm operation | Ongoing screening |
| Destruction logs | 3 yrs | Compliance evidence |

> **Legal Hold Override:** Schedules suspend immediately upon reasonable anticipation of litigation, investigation, or bar proceedings. Require written hold notice (scope, reason, responsible personnel). Retention restarts from hold release, not original close.

### 4. Destruction Procedures

**Paper:** Cross-cut shredding ≥ DIN 66399 P-4. On-site or certified vendor with chain-of-custody and destruction certificates. No regular trash or unsecured recycling.

**Electronic:**

| Sensitivity | Method |
|---|---|
| Standard | Cryptographic erasure / multi-pass overwrite (NIST SP 800-88) |
| Highly sensitive | Degaussing (magnetic) or physical destruction |
| SSDs / flash | Cryptographic erasure or physical destruction (overwrite unreliable) |

OS deletion / recycle-bin emptying is **not** sufficient.

**Scope:** Local workstations, servers, cloud, email, mobile, all backup generations, removable media.

**Device retirement:** Full sanitization or physical destruction before any device leaves firm control. Factory reset is insufficient.

**Client notification:** Written notice when matter eligible for destruction → reasonable retrieval period → document authorization or non-response.

**Destruction log fields:** Date, record description/matter ID, method used, personnel who performed/supervised.

### 5. Roles

| Role | Duties |
|---|---|
| Records Management Officer | Policy admin, exception auth, hold coordination, audit oversight |
| Supervising Attorneys | Annual file review, retention auth, hold initiation |
| IT | Automated retention flags, secure deletion, backup compliance |
| Admin Staff | Physical destruction, log maintenance, client notifications |

### 6. Training

- **New hire:** Policy overview, confidentiality, records handling, non-compliance consequences
- **Annual refresher:** Updates, audit findings, best practices
- **Records staff:** Technical destruction methods, hold procedures
- All training documented with signed acknowledgments

### 7. Auditing

**Annual audit:** Sample closed files for timely destruction, verify log completeness, attempt recovery on destroyed electronic records, review hold documentation.

**Quarterly hold review:** Confirm trigger still active, narrow scope where possible, release promptly on resolution with written notice.

**Vendor oversight (annual):** Review certifications, insurance, security protocols; inspect destruction facilities; require contractual confidentiality, security, and indemnification.

**Incident reporting:** Immediate report to Compliance Officer for violations/breaches. No retaliation. Triggers: root cause investigation, client notification assessment, regulatory reporting, corrective measures.

### 8. Policy Maintenance

- Annual review by Records Management Officer + firm leadership
- Interim review on: statutory/ethics changes, new technology, significant breach
- Amendments communicated within 30 days, incorporated into training
- Maintain version history with effective dates and approval records

## Pitfalls

- **[VERIFY]** State bar trust account minimums (commonly 5–7 yrs; varies by jurisdiction) — state rules control where more stringent
- **[VERIFY]** Malpractice SOL and discovery rule before setting retention floors; adjust if jurisdiction exceeds 6-year baseline
- **No indefinite retention** — holding beyond policy without justification increases breach exposure
- **Metadata** — electronic destruction must cover embedded metadata, not just visible content
- **Cloud/SaaS** — confirm contractual deletion rights; obtain vendor deletion certifications
- **Backups** — must include all generations; omitting backups leaves data recoverable
- **Malpractice carve-out** — allow attorneys to flag closed matters for extended retention with written justification and RMO approval

Related Skills

validating-clinical-data-quality

11
from CaseMark/skills

Structures data quality assessment with completeness, accuracy, and consistency validation. Use when auditing clinical data, assessing data quality, or validating data integrity.

managing-health-data-governance

11
from CaseMark/skills

Structures health data governance programs with stewardship roles, policies, and data quality standards. Use when establishing data governance, defining data stewardship, or managing data policies.

managing-health-data-exchange

11
from CaseMark/skills

Structures health information exchange with HL7 FHIR, C-CDA, and interoperability requirements. Use when managing data exchange, implementing FHIR APIs, or ensuring interoperability.

managing-data-safety-monitoring

11
from CaseMark/skills

Structures DSMB operations with interim analysis protocols and stopping rules. Use when managing DSMBs, conducting interim analyses, or implementing stopping criteria.

managing-clinical-data-quality

11
from CaseMark/skills

Structures data quality management with query resolution, source data verification, and audit trails. Use when managing clinical data quality, resolving data queries, or conducting SDV.

analyzing-pharmacovigilance-data

11
from CaseMark/skills

Structures post-marketing safety surveillance with signal detection and PSUR reporting. Use when analyzing safety signals, preparing PSURs, or managing pharmacovigilance data.

analyzing-epidemiological-data

11
from CaseMark/skills

Structures epidemiologic analysis with incidence, prevalence, rate calculations, and statistical inference. Use when calculating disease rates, analyzing epi data, or interpreting population statistics.

analyzing-clinical-trial-data

11
from CaseMark/skills

Structures clinical trial data analysis with primary endpoint evaluation and safety reporting. Use when analyzing trial results, evaluating endpoints, or preparing statistical reports.

analyzing-clinical-data-warehouses

11
from CaseMark/skills

Structures clinical data warehouse queries for quality measurement, research, and operational analytics. Use when querying clinical data, building analytics reports, or extracting research datasets.

whistleblower-protection-policy

11
from CaseMark/skills

Drafts a U.S. whistleblower-protection policy for corporate and nonprofit organizations. Triggers when the user needs a whistleblower policy, retaliation-prohibition clause, hotline-reporting framework, compliance-ethics policy, or governance document addressing SOX, Dodd-Frank, OSHA, or state whistleblower statutes.

whistleblower-policy

11
from CaseMark/skills

Drafts board-adoptable whistleblower protection policies for public companies and non-profits. Covers SOX, Dodd-Frank, and state statute compliance, reporting channels, investigation procedures, anti-retaliation, and governance oversight. Use when drafting whistleblower policies, ethics reporting procedures, or compliance programs.

unclaimed-property-policy

11
from CaseMark/skills

Drafts an enterprise Escheatment and Unclaimed Property Policy covering property identification, dormancy matrices, due diligence notices, NAUPA-format reporting, remittance, recordkeeping, and audit preparedness across all US state jurisdictions. Use when establishing or updating an unclaimed property compliance framework, preparing for state audits, or evaluating voluntary disclosure programs.