Buried in the claims about the Partnered Health breach is a detail that should bother every Australian business holding customer records. The attackers describe the data as spanning 1999 to 2026.
Take the specific organisation out of it, because this is not really about them. Twenty seven years is a long time. It means records belonging to people who stopped being customers two decades ago, who have moved house several times, changed names, and in some cases died, were still sitting on a live system reachable from a compromised account.
Every record you keep is a record you have to defend
Security spending goes almost entirely into defending the perimeter around the data. Almost none goes into reducing how much data is inside it. That is backwards, because the second option is permanent and free.
A file you deleted in 2019 cannot be encrypted, cannot be exfiltrated, cannot appear on a leak site, and cannot be bundled and resold three years after your incident. It is the only control with a hundred per cent success rate. Yet retention reviews get scheduled, deferred, and quietly dropped, because deleting things feels risky and keeping them feels free.
Keeping them is not free. You just pay for it later, and the bill arrives on someone else's schedule.
The law already asks you to do this
Australian Privacy Principle 11.2 is not subtle. If you hold you no longer need for any purpose you are permitted to use it for, and you are not required by law to keep it, you must take reasonable steps to destroy it or de-identify it.
That is an existing obligation, not a nice to have. Most organisations we assess are technically in breach of it and have never thought about it, because nobody audits the absence of a deletion process until there is an incident and the volume of exposed records becomes the story.
Why it does not happen
Three honest reasons. Nobody owns it, so it sits between IT, legal and operations and never lands. Deleting feels irreversible in a way that keeping does not, so the safe-seeming choice is always to defer. And the systems make it hard, because practice management software and shared drives were built to accumulate, not to expire.
The first two are cultural and can be fixed with a decision. The third is real work, but less than people assume.
A retention pass that actually finishes
Start with one system, not all of them. Pick the one holding the most sensitive personal information, usually the practice management system, the CRM, or the shared drive where scanned documents go to die.
Write down what categories of record it holds and how long each genuinely needs to be kept. Some of this is set for you. Health records in most Australian states must be kept for seven years from last contact, and for a child until they turn 25. Employee records, tax records and contracts have their own periods. Anything without a legal minimum is a business decision, and the honest answer is usually far shorter than current practice.
Then deal with the backlog before you build the process, because the backlog is where the risk actually sits. Old exports, one-off extracts, the folder of scanned forms from a 2014 system migration, mailboxes belonging to people who left years ago. That material is rarely in anyone's retention policy and it is exactly what ends up in a leak.
Finish by making it recurring and boring. An annual pass that runs is worth more than a perfect policy that never does.
It is unglamorous work and it never appears in a board pack as an achievement. It is also the only thing on your security roadmap that reduces your exposure permanently rather than defending it a bit better each year.



