A little storytime to frame this post: Yesterday, I received an email from an unknown sender inviting me to buy tickets to an lower tier MMA event in a city I had never been to at a venue I had never visited.

How, I asked myself, did they even get my email to send me this? Why?

I am decidedly not a combat sports fan. I have never attended or purchased anything more closely related to this sport than an Under Armour polo (it's fuchsia, if you wanted to know). So, as I was scrolling to the bottom in search of the legally-required Unsubscribe link, I was looking for who it came from and trying to make connections.

At the bottom of the email was a copyright notice for a G-League basketball team. But I'd never attended a game of theirs. Not even NBA Summer League. But this led me down the right path. I had attended a game of their parent NBA club years ago before I moved states and cities.

I plugged this into my email search function because I am absolutely terrible about deleting things out of my email and found the old ticket receipt and attendance "Things to Know" email venues send out to remind you not to bring a purse or handgun. I knew it was a while ago, but now I had an exact date:

December 27, 2017.

Why do I tell this story? Because despite the fact that I had not purchased anything from this NBA team in nearly a decade, they still retained my email (and presumably other associated data) in their marketing database in what is a pretty clear indication of a data privacy and security failure.

Lesson #1: Data Retention Costs Money

The more data you store, the more money it costs you. No great insight there, just basic facts. While the costs of data storage have come down fairly significantly in the last decade, with the rush on data centers led by AI demand we have seen AWS raise prices this year. Other services will likely follow. What goes down does not always continue to go down and pushback against construction of data centers as demand rises will likely spike costs at some point in the near future.

Fun fact: I once paid for an entire compliance program's standup cost (aka my salary) by implementing such significant data retention cuts on a company that had been collecting everything about everyone from the company's inception over a decade prior. Good privacy compliance can actually save your bottom line.

Lesson #2: Data is a Double Edged Sword

The lesson for a long time was collect everything and store it forever; if you don't use it today, you'll figure out how to use and monetize it tomorrow. But personal data should now be considered a regulated asset and it increasingly carries regulatory and data breach risk that cannot always be offset by the gains from monetizing the data. Every piece of personal data you collect may be necessary or useful in some fashion, but does the use outweigh the cost and risk of retaining that data?

With the cost of a data breach increasing 9% to $4.4M USD per year according to IBM, businesses need to understand that each individual record held is potentially a ticking time bomb waiting for an accident to happen. As folks say in security, it's not if you'll get breached, it's when.

In addition to data breach costs, you may find yourself subject to penalties from regulators as a result of holding onto data long past its "sell-by" date. Most modern privacy laws, such as the EU General Data Protection Regulation and the California Consumer Privacy Act have requirements that data collection and storage be limited to what is necessary to accomplish the purpose. Art 5 of the GDPR requires data collection be "adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’)[.]" Failure to comply with minimization principles can subject a business to substantial penalties.

Lesson #3: Bad Data Muddies Your Marketing and Analytics

People like me in the above story pollute your dataset if you're a company trying to perform marketing and analytics on your users. We are Fool's Gold. We once bought something from you, which is the strongest indicator that we'll buy from you again (Amazon studied this years ago trying to understand customer behavior and the prevailing indicator of purchase was had purchased before). But if someone hasn't bought from you in 9 years, it's extremely unlikely that person is ever going to buy from you again unless you're in an extremely long tail business - like my mortgage company, I suppose, although I would prefer they would just lose my contact information from their marketing database, especially after they sold my mortgage to another bank.

When you pan for gold, you sift out the fool's gold, rocks, dirt, and other junk to get down to the real gold which is actually useful and lucrative for your business. The same thing should happen to your customer (and other) databases. Sift out the bad data to retain the true golden records of loyal customers.

Setting a data retention policy for corporate data isn't a one size fits all approach, either. Between legally-mandated retention policies, internal product development goals, and customer lifecycles, each business may find itself adopting different retention policies for each database. While not necessarily the most important aspect of any privacy or data governance program, data retention policies form a key part of any program and remain crucially important from an operational perspective to navigate different legal and business requirements.

If you need any help navigating data retention issues or various internet, privacy, and security laws, reach out to us at Brandi@BennettTechLaw.com for help.