Data hoarding: a board-level courage test

Most organisations keep far more information than they need. It sits in old email accounts, shared drives, forgotten SharePoint sites and the digital equivalent of boxes under the stairs. Nobody is quite sure what is in it, and nobody feels able to remove it.

This is usually described as caution, or as corporate memory. It is neither.

Why it happens

Very little data hoarding exists because a regulation demands it. It exists because deleting something feels riskier than keeping it, and because nobody has been given the authority to decide. Keeping everything "just in case" is not a decision to keep. It is the absence of a decision.

Why it matters to a board

Hoarded information is not neutral. It carries costs that rarely appear on a risk register:
- Exposure. Information you no longer need can still be lost, stolen or requested. UK GDPR says personal data should be kept no longer than necessary, and a breach or a subject access request will reach into the archive whether or not anyone remembers it is there.
- Drag. People spend time searching, and cannot be sure the document they found is the current one.
- Fragility. When knowledge lives in personal inboxes, it leaves with the person. That is not corporate memory. It is dependence on individuals.

A simple test

Lean thinking offers a useful discipline: be clear about why something exists and who it serves. Applied to information, that gives three groups:
1. What we are legally or contractually required to keep.
2. What actively helps us serve customers, beneficiaries or operations.
3. Everything else.

Only the first two have a reason to stay. The third is waste, even if it is digital and appears free to store.

[Optional, Nic to confirm or remove: When I was architect and project lead for restructuring how an international nuclear organisation stored and classified its information, the technical migration was the easier part. The harder part was ...]

Questions for the board

- What information are we legally required to keep, and for how long? Is that written down and followed?
- Who owns the decision to dispose of information, and do they feel able to make it?
- What are we keeping simply because it feels safer than deciding?
- If we suffered a breach or received a subject access request tomorrow, how much of what we hold would we struggle to explain?

The courage part

Disposing of information needs someone to say: we have looked at this, we understand our obligations, and we are confident it can go. That takes clarity, ownership and visible backing from the top. Without the board's support, the rational choice for any individual is to keep everything and hope.

Corporate memory has value only when it is accessible, intentional and current. Otherwise it is digital clutter, quietly becoming tomorrow's risk.

Next
Next

Why boards should rehearse the bad day