How Long Should You Keep Insurance Data? Nobody Knows, So You Keep Everything
Ask an insurer what its data retention policy is and you'll usually be handed a document. Ask what actually happens to a policy record fifteen years after the policy lapsed and the answer is almost always the same: it's still there. Insurance has genuine reasons to keep data for a long time — long-tail liabilities, latent claims, regulatory and legal obligations that run for years. But "we might need it" has quietly become "we delete nothing," and that default carries costs and risks nobody signed off on.
Why keeping everything feels safe and isn't
Deleting data feels risky: if a claim surfaces in twenty years, you want the file. So the cautious choice is always to retain, and since nobody is accountable for the cost of retention, the cautious choice always wins. But data you keep is data you must secure, must include in a breach if one happens, must search when a customer exercises a privacy right, and must migrate every time you change platforms. Indefinite retention isn't a neutral default — it's an accumulating liability that grows quietly in the background.
Where it breaks down
- Policy on paper, not in systems. The retention schedule exists as a document; no system enforces it.
- No basis per data type. Everything is kept for the longest period any category might need, because nobody differentiated.
- Copies escape the policy. Even where the system of record expires data, extracts, backups and test copies don't.
- Deletion is unprovable. When something is deleted, there's no evidence trail to demonstrate it to a regulator.
Why it's a data-foundation problem
Retention only works if it's enforced by systems rather than described in a document, and enforcement needs a foundation: knowing what data you hold, where it lives including copies, what legal basis and period applies to each category, and a mechanism that actually expires it with an auditable record. That's the same data-mapping and governance capability that makes privacy requests answerable — which is why insurers who fix one usually find they've fixed a good part of the other.
What good looks like
- Retention defined per data category with a stated legal basis, not one blanket maximum.
- Enforced by systems, so expiry happens automatically rather than aspirationally.
- Copies covered — extracts, backups and non-production environments included in the schedule.
- Auditable deletion so you can evidence what was removed and when.
Keeping everything forever looks like caution and behaves like an accumulating risk: more to secure, more to breach, more to search, more to migrate. Building retention that's actually enforced is exactly the kind of work we do with insurers at IntelliBooks.
The safest data is the data you no longer hold and no longer need. That only helps if you can prove it's gone.
Comments
Post a Comment