PicaJet

Reference Glossary

Retention policy

A retention policy specifies how long each class of asset must be kept before it can be archived or deleted, typically driven by legal, regulatory, or contractual requirements.

Why it matters in a DAM

Different asset classes carry different retention obligations — a contract or a clinical trial image might need to be kept for years under regulation, while a seasonal marketing banner has no such requirement — and treating them identically either over-retains data unnecessarily, a real risk under privacy law for assets containing identifiable people, or deletes something a regulator or counterparty later asks to see.

A worked example

Asset class Marketing creative, legal and compliance documents, personal-data-containing photos, financial disclosures
Retention trigger Creation date, contract end date, campaign end date, or last-use date
Required period Set by internal policy or by regulation, e.g. contractual term or statutory minimum
Action at end of period Archive, delete, or flag for legal review before deletion

Common mistake

Teams apply one blanket retention rule to the whole DAM library instead of setting it per asset class, so personal-data-containing images and time-limited legal documents end up governed by the same schedule as evergreen marketing creative.

Retention obligations do not come from a single source: some are set by data protection law where an asset contains identifiable people, some come from contracts with photographers, agencies, or talent, and some are purely internal decisions about how long marketing creative stays relevant enough to be worth storing in the active library.

The practical failure is applying one retention rule across an entire DAM instance rather than differentiating by asset class. A photo library holding both product shots with no personal-data implications and event photography with identifiable attendees needs different retention treatment for those two categories, but a single blanket policy configured at the system level cannot express that distinction unless the DAM supports rules scoped to metadata or asset type.

Retention policy and asset lifecycle are related but not the same thing: the lifecycle describes the stages an asset moves through, while the retention policy is what sets the clock on how long it stays in each stage before the next transition — typically archiving or deletion — becomes mandatory rather than optional.

Frequently asked

What typically sets the retention period for a given asset class?

Legal, regulatory, or contractual requirements — for example data protection law for images containing identifiable people, or contract terms with photographers, agencies, or talent.

Why is applying one blanket retention rule across an entire DAM a mistake?

Different asset classes carry different obligations — treating personal-data-containing photos and time-limited legal documents the same as evergreen marketing creative either over-retains data unnecessarily or deletes something a regulator later asks to see.

What's the risk of over-retaining assets that contain identifiable people?

It's a real risk under privacy law, since data protection regulations often require deleting personal data once it's no longer needed for its original purpose.

How is retention policy different from asset lifecycle?

The lifecycle describes the stages an asset moves through; the retention policy sets the clock on how long it stays in each stage before the next transition — typically archiving or deletion — becomes mandatory.

What can trigger a retention period besides the asset's creation date?

A contract end date, a campaign end date, or a last-use date, depending on what the applicable retention obligation is actually tied to.

What should happen at the end of a retention period?

Archive, delete, or flag the asset for legal review before deletion — the specific action depends on the policy and the asset class involved.