Establish data retention and minimization policies to reduce your organization’s attack surface
January 15, 2026
The value of data today is greater than ever before, with companies looking for ways to optimize its collection and utilization to provide customers with timely, personalized experiences. As data’s value increases, so do the associated risks and costs. Cloud storage alone accounts for 30% of a company’s overall IT budget, with one terabyte (TB) of data costing $3,351 per year on average. That’s a cool $1M in storage costs alone for 300 TB of data. Apart from the rising costs of data storage, data breaches are also becoming more prevalent with the volume and variety collected by organizations today. he average damage of a data breach in 2025 sat at $4.4M.
The problem is clear. More data, more costs, more risk. More value? That’s up to how your organization makes use of it. Hoarding data or collecting it without a clear purpose not only increases the issues of storage cost and breach risk mentioned above, but also violates the GDPR, CPRA, and other major privacy regulations’ principles of data minimization and data retention policies.
Personal data shall be “adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed”
– GDPR, Article 5(1)(c)
Well, if it’s so clear that data minimization and data retention is the answer to high storage costs, data breach risks, and non-compliance issues, why isn’t everyone doing it? More than 80% of the data stored by organizations is unstructured.
This means it’s in the form of:
This data also usually becomes meaningless in 90 days, and nearly a third of it is considered redundant, obsolete, and trivial (ROT). ROT data not only adds empty data storage costs, it’s also prime fodder for data breaches as it typically sits outside secure systems. It expands the attack surface of your company, which is all the possible risk areas from which an unauthorized user or attacker could breach your system.
Keeping these concerns with unstructured data and a growing attack surface in mind, most privacy regulations today call out the need to include data minimization practices as a part of standard operation procedures. Recent enforcement actions from the Federal Trade Commission (FTC) show that privacy and data security best practices have data minimization as a key tenet. Companies can start to include this in their data workflows, using privacy by design principles in their products or services to ensure data is minimized from the outset and collection and use are clearly communicated to customers.
Now that the solution of incorporating privacy by design into your products and services from their inception is clear, the next step is figuring out how to integrate them into your processes seamlessly.
To kick things off, look at your most common data workflows and scenarios. Analyze your metadata to see relevant fields data created, last accessed/modified. Identify when data stops being necessary, where data is commonly deleted in these situations, and see how this could correlate to a data retention schedule.
After identifying where data is deleted and formulating a retention schedule around these scenarios, you can apply these retention periods to your data, e.g. archiving or deleting SharePoint files after they cross a certain time threshold.
When your retention periods are defined and deletion methods are established, using a tool to power this mechanism is the most efficient way to go about this process.
OneTrust Data Use Governance enables organizations to operationalized data use with ongoing, automated programmatic enforcement rather than treating data governance as one-time cleanup exercise.
With unified visibility across structured and unstructured data, OneTrust enables teams to:
By unifying data classification, policy orchestration, and continuous oversight, OneTrust enables organizations to reduce unnecessary data exposure, lower regulatory risk, and facilitate faster innovation with trusted data.
To see how OneTrust Data Use Governance helps you operationalize data governance at scale, request a demo today.
On-demand webinars
Join our webinar to explore how data leaders are strengthening AI governance with trusted data foundations, quality management, and transparent practices.
On-demand webinars
Discover how to modernize data governance for the AI era in this OneTrust webinar. Learn how to move from manual, static governance to dynamic, policy-centric enforcement with OneTrust Data Policy Enforcement.
On-demand webinars
This webinar will explore the how AI is affecting the data landscape, focusing on how data teams can extend common data practices to support AI’s unique use of data.
White Paper
Download this white paper to learn how to adapt your data governance program, by defining AI-specific policies, monitoring data usage, and centralizing enforcement.
eBook
Learn why discovering, classifying, and using data responsibly is the only way to ensure your AI is governed properly.
eBook
Download our new eBook and learn how to leverage the value of data governance across industries, including financial services, healthcare, retail, and manufacturing.
Infographic
Learn the impact a data governance program has in manufacturing and how it enables greater efficiency across your supply chain
Infographic
Make sure you choose the right data discovery solution for your organization with our comprehensive breakdown of key benefits and features to look for.
Infographic
Learn how data governance can help manage the high volume and sensitivity of data that runs through your retail operations.
Infographic
Learn how data governance can help your healthcare organization effectively manage its protected health information (PHI) and other sensitive data.
Infographic
Learn how data governance can help address common challenges in the financial services industry and protect your most critical information.
On-demand webinars
Our expert speaker will demonstrate how common real-world data challenges can be identified, addressed, and reported on, leading to better data governance, security, and alignment with business goals.
On-demand webinars
Explore the concept of data minimization and its crucial role in enhancing security, privacy, and reducing risk.
On-demand webinars
Join the first part of our Data Discovery Dispelled webinar series where we will discuss the hidden sensitive information that could pose risks for your organization.
Upcoming webinars
Join us for a journey into the heart of data management as we explore the depths of data within organizations and shed light on how technology can enhance data security, privacy, and compliance.
Data Sheet
Explore our OneTrust Data Discovery and Security data sheet to learn how you can discover and control your data while enabling your teams.
eBook
Download this eBook and learn practical methods in building a flexible data governance program that aligns with your business.
On-demand webinars
See how OneTrust Data Discovery can help your organization achieve complete data visibility to empower your security program and reduce risk.
On-demand webinars
Join OneTrust and KPMG for a dialogue with Information Security leaders on managing the balance between risk and reward when handling sensitive customer information.
On-demand webinars
Join us for a two-hour deep dive into data discovery and how OneTrust helps privacy, IT, and security teams understaind their data and achieve risk reduction goals.
Infographic
Explore three key integration capabilities of OneTrust Data Discovery and Microsoft 365.
On-demand webinars
Join this webinar to learn how OneTrust is enhancing its privacy management, data governance, and consent and preferences solutions to help organizations tackle data sprawl and enable regulatory agility.
Data Sheet
Download our onboarding and offboarding management data sheet and learn how OneTrust Certification Automation can help reduce your risk exposure and improve compliance.
White Paper
Download our white paper and learn how privacy teams help organizations establish and implement policies that ensure AI applications are responsible and ethical.
Infographic
Unstructured data poses risks due to its open access and lack of governance, and CISOs need to implement measures to track, de-risk, and protect it.
On-demand webinars
Join us for a discussion on driving better business use and outcomes from data while ensuring regulatory requirements are met.
On-demand webinars
Join us for a discussion on the latest trends in trusted data and how you can take critical steps to build trust in data practices
On-demand webinars
Watch this webinar and discover how automated data discovery is helping clients in South Africa create value and demonstrate trust.
On-demand webinars
Watch this webinar and discover how automated data discovery is helping clients in Türkiye create value and demonstrate trust.
On-demand webinars
Watch this webinar and discover how automated data discovery is helping clients in Romania create value and demonstrate trust.
On-demand webinars
Watch this webinar and discover how automated data discovery is helping clients in Hungary create value and demonstrate trust.
On-demand webinars
Watch this webinar and discover how automated data discovery is helping clients in Israel create value and demonstrate trust.
On-demand webinars
Learn how you can take the first steps towards data intelligence and advance your privacy program to the next phase of automation and maturity.
On-demand webinars
In this free webinar, learn how to automate the classification and mapping of sensitive data and speed compliance.
On-demand webinars
Learn how properly governed data leads to better data quality, increased data intelligence and more trusted data.
On-demand webinars
In the final webinar in the series, we explore the final step on the path towards data intelligence - using and improving your data.