skills/legal/data-retention-and-destruction-policy/SKILL.md
Drafts a law firm Data Retention and Destruction Policy covering practice-area retention schedules, secure destruction procedures, legal hold protocols, and compliance infrastructure. Trigger when establishing or updating records management frameworks, drafting retention schedules by matter type, or implementing secure destruction procedures for paper and electronic records.
npx skillsauth add casemark/skills data-retention-and-destruction-policyInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Generates a firm-wide records management policy governing client file lifecycles, retention periods by practice area, secure destruction methods, legal holds, and audit requirements.
Cite applicable authorities in the policy introduction:
| Authority | Applicability | |---|---| | ABA Model Rules 1.6, 1.15 | Confidentiality; safekeeping client property | | State ethics rules | Jurisdiction-specific mandates (controls where more stringent) | | Sarbanes-Oxley | Securities-related matters | | HIPAA | Health law practices | | IRS / IRC § 6001 | Tax work; 7-year documentation standard |
Covered: Client matter files, financial records (trust ledgers, billing), intake records (conflict databases, engagement letters), electronic records (email, cloud, mobile, backups), third-party collaboration platforms.
Excluded: Original client-owned documents (wills, deeds, certificates) — return on matter close; destruction requires written client authorization. Transitory communications (scheduling, duplicates) — delete promptly.
Bound parties: All firm personnel and third-party providers under confidentiality agreements.
| Record Category | Minimum Retention | Basis | |---|---|---| | General litigation / transactional | 6 yrs post-close | Malpractice SOL + margin | | Estate planning | Permanent or client death + admin + SOL | Latent claim risk | | Real estate | 7–10 yrs post-close | Title / environmental latency | | Corporate formation / governance | Entity life + 7 yrs post-dissolution | Ongoing relevance | | Tax preparation | 7 yrs post-filing | IRS extended audit period | | Trust account records | 6 yrs or state bar rule (whichever longer) | Ethics rules | | Firm accounting | 7 yrs | Tax audit exposure | | Conflict / intake records | Duration of firm operation | Ongoing screening | | Destruction logs | 3 yrs | Compliance evidence |
Legal Hold Override: Schedules suspend immediately upon reasonable anticipation of litigation, investigation, or bar proceedings. Require written hold notice (scope, reason, responsible personnel). Retention restarts from hold release, not original close.
Paper: Cross-cut shredding ≥ DIN 66399 P-4. On-site or certified vendor with chain-of-custody and destruction certificates. No regular trash or unsecured recycling.
Electronic:
| Sensitivity | Method | |---|---| | Standard | Cryptographic erasure / multi-pass overwrite (NIST SP 800-88) | | Highly sensitive | Degaussing (magnetic) or physical destruction | | SSDs / flash | Cryptographic erasure or physical destruction (overwrite unreliable) |
OS deletion / recycle-bin emptying is not sufficient.
Scope: Local workstations, servers, cloud, email, mobile, all backup generations, removable media.
Device retirement: Full sanitization or physical destruction before any device leaves firm control. Factory reset is insufficient.
Client notification: Written notice when matter eligible for destruction → reasonable retrieval period → document authorization or non-response.
Destruction log fields: Date, record description/matter ID, method used, personnel who performed/supervised.
| Role | Duties | |---|---| | Records Management Officer | Policy admin, exception auth, hold coordination, audit oversight | | Supervising Attorneys | Annual file review, retention auth, hold initiation | | IT | Automated retention flags, secure deletion, backup compliance | | Admin Staff | Physical destruction, log maintenance, client notifications |
Annual audit: Sample closed files for timely destruction, verify log completeness, attempt recovery on destroyed electronic records, review hold documentation.
Quarterly hold review: Confirm trigger still active, narrow scope where possible, release promptly on resolution with written notice.
Vendor oversight (annual): Review certifications, insurance, security protocols; inspect destruction facilities; require contractual confidentiality, security, and indemnification.
Incident reporting: Immediate report to Compliance Officer for violations/breaches. No retaliation. Triggers: root cause investigation, client notification assessment, regulatory reporting, corrective measures.
tools
Audits the complete in-scope medical-record universe in a litigation matter and produces an attorney-facing, Bates-cited analysis of treatment gaps, missing records or providers, baseline coverage, material billing or production mismatches, and complaint evolution. Use when asked to find missing medical records, analyze treatment gaps or first-care timing, identify absent providers, assess whether a production is complete, or prepare a records-request target list. Use medical-record-chronology instead when the primary request is a chronological clinical narrative.
development
Drafts a legally compliant Private Placement Memorandum for Regulation D offerings (Rule 506(b)/506(c)), covering full disclosure framework including risk factors, capitalization, securities terms, use of proceeds, and investor qualification requirements. Enforces SEC anti-fraud compliance under Section 10(b)/Rule 10b-5, blue sky law considerations, and accredited investor verification under Rule 501. Use this skill when drafting PPMs, offering memorandums, Reg D disclosure documents, or private offering circulars for issuers raising capital from sophisticated investors. Also trigger when the user mentions private placement disclosure, offering memorandum, Reg D fundraising, or accredited investor verification. Even if the user just says "PPM" or "draft our offering memo," use this skill.
data-ai
Generates structured privacy and data protection law briefings across US, EU, UK, and other jurisdictions. Organizes by jurisdiction with compliance deadlines, enforcement actions, and legislative changes. Use when preparing privacy law briefings, compliance updates, regulatory change summaries, or data protection landscape reviews.
testing
Generates structured summaries of prior art references for patent prosecution, validity analysis, and freedom-to-operate assessments. Maps disclosures to claim elements with precise citations. Use when summarizing prior art, analyzing patent landscapes, mapping references to claims, or preparing office action responses.