Businesses spend money moving data, protecting data and buying platforms to govern data. Yet a question remains unanswered in many programmes: what information are we managing, and what should happen to it? Until that question has an owner and an answer, retention and deletion exercises risk becoming expensive acts of guesswork.
I see teams trying to achieve too much without understanding classification. They want cleaner repositories, stronger privacy controls and better analytics, but lack an agreed view of the records underneath. Classification provides that view by connecting information to its purpose, sensitivity, business value and obligations. Labelling makes those decisions visible and, where systems support it, actionable.
This matters because a confidential label cannot tell an organisation how long to retain a record. A payroll file and a rejected job application may both contain sensitive information, yet require different retention decisions. Sensitivity classification and retention rules must work together, supported by record categories, accountable owners, retention triggers and arrangements for legal holds.
For executives, the consequence reaches beyond compliance. Classification informs architecture: which systems should hold particular records, which repositories are authoritative, and where access or duplication needs attention. It helps distinguish information essential to operations from material that has accumulated through habit. That distinction gives investment decisions a basis stronger than the volume of files discovered.
Consider a customer record held in a banking platform, exported into a spreadsheet and copied into a shared folder. Deleting it from the source does not resolve the lifecycle of the copies. A credible programme connects classification with discovery and lineage, so the organisation can identify downstream records, assess their purpose and apply the appropriate controls.
Residency requires the same discipline. Classification can identify information whose location deserves scrutiny, but a label cannot prove where it is stored or accessed. That requires verified system inventories, cloud configurations, supplier evidence and mapping of data flows. Executives should demand this distinction, because confidence built on a label alone can conceal gaps across outsourced infrastructure.
Unstructured information presents a particular challenge. Email, collaboration platforms and legacy drives contain contracts, identity documents, working drafts and forgotten exports, often within the same repository. Treating everything alike encourages blanket retention or reckless deletion. Classification helps teams prioritise repositories where sensitive content, broad access, unclear ownership and expired business purposes create the greatest exposure.
It also gives substance to the discussion about redundant, obsolete and trivial data, known as ROT. Age alone does not make a document disposable, and archiving does not establish a reason to retain it. Business owners must confirm continuing value, applicable obligations and exceptions before disposal. Otherwise, an archive becomes a quieter place to accumulate the same unresolved problems.
The discipline extends into extraction, transformation and loading, or ETL. When data moves into reporting environments, staging areas or analytical platforms, its context can disappear while copies multiply. Pipelines should preserve or recreate relevant classification metadata, record lineage and apply destination retention rules. Temporary datasets need expiry controls, while transformed outputs require assessment of their sensitivity and purpose.
A practical roadmap begins with a bounded estate and a business sponsor. Agree the classification scheme, identify owners, map priority systems and repositories, then connect record categories to retention schedules. Pilot discovery and labelling before scaling automation. Test deletion against legal holds, dependencies and recovery arrangements, and retain evidence that disposal occurred across the agreed scope.
Responsibility must sit with the business, supported by technology, privacy, security and records management teams. No single function can determine value, configure controls and validate every exception without participation from the others.
Boards should measure progress through outcomes: fewer unmanaged copies, clearer ownership, verified retention coverage and completed disposal of records without a continuing justification. Counting labels applied tells only part of the story. The executive question is whether classification changes decisions about what the organisation keeps, protects, moves and removes. When it does, data governance becomes an operating discipline with a commercial purpose, rather than another programme whose ambition exceeds its understanding.
- business a.m. commits to publishing a diversity of views, opinions and comments. It, therefore, welcomes your reaction to this and any of our articles via email: comment@businessamlive.comÂ
Michael Irene, CIPM, CIPP(E) certification, is a data and information governance practitioner based in London, United Kingdom. He is also a Fellow of Higher Education Academy, UK, and can be reached via moshoke@yahoo.com; twitter: @moshoke







