River
Y CombinatorBacked by Y Combinator
FREE TEMPLATE

Consultant Data Handling Policy Template

Five documents and three sheets that turn a thirty-day destruction clause into a schedule with one row per copy of client data.

Free download  ·  No account needed

Retention and Destruction Note  ·  Alderton Reeve for Havenridge Retail Group  ·  written 09 Apr, three weeks before the deadline

Three clocks, one set of copies

ClockWhat sets itDateAgainst the deadline
ContractMSA 11.4, thirty days from termination on 31 Mar30 AprThe deadline itself
Backup rotation30 dailies, 12 monthlies, 7 annuals, snapshots immutable31 Dec, six years out2,437 days after
Our own claim windowWork papers we could not answer a challenge without31 Mar, six years out2,162 days after

19 datasets, 78 copies, 9 locations. 51 copies purge by the deadline, 19 are retained under the backup carve-out at clause 11.4(b) with the words quoted on every row, and 8 are conflicts: 4 work-paper extracts the clause has no limb for, and 4 on an associate’s laptop.

A certificate reading all Confidential Information has been destroyed is false from the day it is signed until the last annual snapshot rotates out.

Search this and page one hands you contracts. A mutual NDA, a confidentiality clause in the consulting agreement, a data processing agreement, and clause language for return or destruction on completion. The best result adds a real closeout checklist, which asks you to remove client data from all personal devices, cloud sync folders and email archives. That line cannot be ticked honestly, because ticking it requires an enumeration, and no template in the category ships one. This pack is the enumeration, built from what the intake pass already found.

So the unit here is the copy rather than the dataset. Alderton Reeve took 19 datasets from Havenridge Retail Group over a five-month depot network review. Those 19 existed as 78 copies across 9 locations: the workspace, two laptops, attachments inside email threads, a note-taking app, an internal deck, the work papers, an associate's laptop and the backup snapshots. Nineteen datasets is a sentence in a policy. Seventy-eight copies is a schedule of work, and 8 of those rows are things that cannot be done.

Three clocks then run on the same copies. The contract says 30 April, thirty days from termination. The rotation says 31 December six years later, because snapshots are immutable and the disposal rule itself excuses a case where targeted disposal is not reasonably feasible given how the data is held. The practice's own claim window says 31 March six years later, and that one is a floor rather than a ceiling. The spread is 2,437 days, which is how long a one-line certificate stays false.

78 copies, three dispositions, and the eight rows that cannot be done

The Data Register, the Destruction Schedule, the Certificate of Destruction and the Access Log.

Data Register  ·  78 rows, one per copy  ·  8 of 78 shown

The unit is the copy, so one dataset is six rows

CopyDatasetClassPersonalLocationMethod reachableDispositionLast copy gone
C-007Payroll extract by depotRestrictedYesProject workspaceClear, plus version purgePurge28 Apr
C-020Payroll extract by depotRestrictedYesPrincipal’s laptopClearPurge28 Apr
C-036Payroll extract by depotRestrictedYesMailbox, inside a threadClear, thread search then permanent deletePurge28 Apr
C-061Payroll extract by depotRestrictedYesNightly backup snapshotsNone reachable per fileRetain, 11.4(b)31 Dec 2033
C-072Payroll extract by depotRestrictedYesWork papers, inside the modelClear, but the model stops re-performingConflict31 Mar 2033
C-050Safety incident historyRestrictedYesNote-taking appClear, plus trash purgePurge28 Apr
C-058Interview transcripts, 14 namedRestrictedYesInternal capability deckClear, slides re-renderedPurge28 Apr
C-076Interview transcripts, 14 namedRestrictedYesAssociate’s laptopNot ours to runConflictOpen

Five of those eight rows are the same dataset. That is the arithmetic every remove-client-data-from-all-devices checklist leaves out.

Destruction Schedule  ·  12 actions  ·  purge 51  ·  retain 19  ·  conflict 8

Every copy resolves to purge, retain or conflict

ActionScopeCopiesExecutedClause or reasonLast copy goneReminder
A-01Project workspace1528 AprMSA 11.428 Apr14 Apr
A-02Principal’s laptop1228 AprMSA 11.428 Apr14 Apr
A-04Mailbox attachments928 AprMSA 11.428 Apr14 Apr
A-07Backup copies of data received before the year-end1611.4(b), archival copies retained in accordance with routine backup procedures31 Dec 203301 Dec 2033
A-08Backup copies of data received after the year-end311.4(b), last monthly held 12 months01 Apr 202818 Mar 2028
A-09Work-paper extracts417 Apr11.4 has no professional-obligation limb, raised 09 Apr, confirmed in writing 17 Apr31 Mar 203301 Mar 2033
A-10Copies on the associate’s laptop4Their certificate requested 09 Apr, chased 22 AprOpen06 May
A-11Customer master returned, then cleared124 AprTheir instruction of 14 Apr, the controller’s choice28 Apr21 Apr

A blank disposition is the one state this sheet does not allow. It reads as purged on the certificate and behaves as retained in the snapshots.

Certificate of Destruction  ·  issued 29 Apr  ·  status: partial, 4 copies outstanding

Reconciliation, and the four lines nobody puts in writing

DispositionCopiesBasis
Sanitized on 28 Apr51Clear, verified by a second person searching for the dataset names and three sample values
Retained under clause 11.4(b)1930 dailies gone 27 May, 6 monthlies gone 01 Apr 2028, 1 annual gone 31 Dec 2033
Retained by your letter of 17 Apr4Work-paper extracts, for the period stated, subject to clause 11
Outstanding at the subcontractor4Certificate requested 09 Apr, chased 22 Apr, reissue due 13 May
Total78Matches the Data Register row count

Personal data, your instruction followed. 6 of the 19 datasets carry personal data. Asked 09 Apr, answered 14 Apr: delete all six, except the customer master, returned as a CSV to your named recipient on 24 Apr and deleted here on 28 Apr. Both acts are register rows.

The register, the schedule and the access log are available for inspection on request.

Access Log  ·  12 events  ·  5 of 12 shown

Who opened it, from where, and why

EventDatePersonDatasetsEvent typeNote
E-0307 NovAssociate, Kestrel Systems Advisory4 datasetsAccess granted beyond the named teamClient consent in writing 07 Nov, equivalent terms signed 08 Nov
E-0615 JanPrincipalSafety incident historyCopy left an approved locationPasted into the note-taking app, recorded as C-050
E-0919 FebPrincipalStore sales by weekNear missShare link open wider than intended for 40 minutes, scope corrected same day, client informed 20 Feb
E-1031 MarAnalyst7 datasetsAccess revokedWorkspace access removed 01 Apr, one day after the last working day
E-1228 AprPrincipalAll 19Sanitization51 copies, second-person verification, search terms recorded on each row

A log with no incidents across five months reads as a log nobody kept, which is why the near miss is on it.

What's in the pack

01

Data Register

One row per copy rather than per dataset, with the owner, the classification and the sanitization method actually reachable there.

02

Destruction Schedule

Every copy resolved to purge by the deadline, retain under a quoted carve-out with an end date, or conflict.

03

Access Log

One row per access event with the engagement reason, plus the four that matter more: grants, copies leaving, revocations and near misses.

04

How Three Clocks Disagree

Why the contract, your backup rotation and your own claim window produce three different dates on the same copy.

05

Data Handling Policy

The standing policy: allowed locations, four classification bands, access, subcontractors, incidents, and how retention actually works.

06

Client-specific Addendum

A one-page delta against the standing policy, including the requirements you cannot meet as written and what you do instead.

07

Retention and Destruction Note

The note that goes to the client three weeks early, naming each conflict with the options in the order you would prefer them.

08

Certificate of Destruction

Enumerated by disposition and reconciled to the register, following the per-media certificate the sanitization guidelines set out.

How to use it

  1. 1

    Open in River, or take it blank

    Open the pack in River and send the MSA, the security schedule and your own backup configuration, or download the Word documents and CSV sheets and fill them in yourself.

  2. 2

    Census the copies

    Walk the nine locations rather than working from memory, including the recycle bin, mailbox threads, and whatever a financial orientation pass copied out of the board pack.

  3. 3

    Compute the three dates

    Date the contractual clock from its trigger event, the way a restriction register does, then add the rotation date and your own retention floor.

  4. 4

    Raise the conflicts, then certify

    Send the note three weeks out so a client's legal team has time to answer in writing, then write the certificate from the schedule and reconcile the counts.

Frequently asked questions

Is this template free?

Yes. The zip is Word documents and CSV sheets, with no account and no card needed. Edit with AI is the other branch: it creates a free River account, installs this pack as a private Space, and starts filling it in from the contract and the file list you send.

What format are the downloaded files?

The five documents come as .docx and the three sheets as .csv, so they open in Word, Pages, Google Docs, Excel, Numbers and Sheets with no conversion. Add ?format=pdf to the download link if you want the documents as PDF for circulation instead.

What does Edit with AI actually do?

It reads the destruction clause and quotes it back with the trigger event, the period and the computed deadline. Then it builds the register from your own locations and file index, works out the three dates per copy, and marks the rows where the contract and your retention need cannot both be satisfied.

Why one row per copy instead of per dataset?

Because a dataset has one name and six destruction paths. The same extract sits in the workspace, on a laptop, inside an email thread, in a model, in a deck and in a snapshot, with a different owner and a different reachable date on each. The sanitization guidelines document per media for the same reason.

Can I certify destruction while backups still hold the data?

You can certify accurately, which is a different claim. The certificate here says what was sanitized, what is retained under the backup carve-out with the clause words quoted and an end date, and what is still outstanding. A blanket assertion would be false until the last snapshot rotates.

What about the personal data in what the client sent?

Transcripts, payroll extracts and headcount and rota data all count, and three of those usually arrive without anyone thinking of them that way. For those the choice between return and deletion is the client's rather than yours, and copies go unless a law requires them kept.

Does this replace the DPA or the confidentiality clause?

No. Those are contracts, and page one of this query is full of them. This pack is the handling procedure underneath: what arrived, where every copy went, what came off when, and the evidence you hand a security reviewer who asks about the clause you already signed.

Make the destruction clause an executable schedule

Take the Word documents and CSV sheets blank, or send River the MSA and your backup configuration and get the register, the three dates and the conflict list back.

Edit with AI