Category: Records Retention Policy

Making The Most Out of A Retention Schedule – A New 7-Minute Master Series from CAPP

A Records Retention Schedule is a TOOL that EMPOWERS organizations to GOVERN and DEFENSIBLY DISPOSE of their information.

Records retention is first and foremost about complying with laws and regulations. However, a retention schedule, when properly developed and utilized, is not simply a tool that tells you how long you must keep (or when to destroy) your records, it is a blueprint that provides powerful insight into the information lifecycle and knowledge management capabilities of your company as a whole.  It saves you money on storage and helps shape the way you curate your information enterprise-wide.

Records retention is first and foremost about complying with laws and regulations. However, a retention schedule, when properly developed and utilized, is not simply a tool that tells you how long you must keep (or when to destroy) your records, it is a blueprint that provides powerful insight into the information lifecycle and knowledge management capabilities of your company as a whole.  It saves you money on storage and helps shape the way you curate your information enterprise-wide.

OUR RETENTION SCHEDULES:

Serve as a primary tool for ensuring records compliance with federal, state, local laws, regulations and business requirements
Identify business continuity records
Document all records categories, records formats, systems of record, retention requirements and data classifications
Can be updated automatically and integrate with IT infrastructure

Reach out to us today to schedule a free consultation at 323-413-7432

7 Ways to Prepare Data in the Age of Privacy and Information Governance

7 Ways To Prepare Data In The Age Of Privacy and Information Governance

7 Tips for Data Preparation in the Age of Information Governance

Content may still be king, but now the rights to some of it may belong to the people! In response to the EU’s General Data Protection Requirement (GDPR) and recent stateside efforts to enshrine data protection including the California Consumer Privacy Act (CCPA), organizations are revisiting the efficacy of their Data and Information Governance (IG) programs. Laws and regulations vary by industry and company size but each intend to protect consumer’s personal data by prescribing technical and governance standards backed by stiff penalties for non-compliance.

Notably, while many companies are already familiar with records retention laws, these latest controls also introduce a duty to destroy data once no longer required for a legitimate business purpose. For entities that have grown accustomed to leveraging cheap digital storage, this new responsibility presents a number of logistical hurdles.

However, directives on how you may use your customer’s data or any other information you store doesn’t necessarily have to be burdensome. In fact, these new guardrails present numerous opportunities to implement better governance, monetize the lifecycle of information assets and foster trustworthy relationships that can actually enhance the customer experience.

These 7 tips can help prepare your data to support an IG strategy:

  1. Automate Retention Schedules – Legal and compliance requirements are the cornerstones of corporate governance programs. Yet tracking the multitude of historical and emerging state, federal and international laws and regulations that affect your data decisions can be a monumental task that even the most robust law departments aren’t prepared for. Consider leveraging SaaS software to keep your Risk, Compliance and Legal staff current on the latest citation changes to these nuanced instructions. These tools empower you to defensibly destroy and cleanse costly data no longer useful to your organization.
  2. Cover Your Assets – Satisfying new compliance requirements like GDPR and CCPA means it’s not enough to simply know what kinds of records you keep, you need to know what systems they’re kept in and how that data flows between them. That’s why Chief Data Officers and Enterprise Architects are increasingly embracing asset management tools that not only perform diagnostics on their application stack but allow them to inventory their attributes and map related processes that inform long-term strategic roadmap planning. Tools like these also help support application rationalization projects which in turn aid in classification and disposal of unneeded data.
  3. Introduce Big Buckets – The biggest challenges with enforcing retention across an enterprise are “event triggers” that complicate how long sets of records must be retained. For example, an employee file might be held X years following a termination “event.” Big Bucket strategies allow you to simplify and group “like” records together to support more efficient destruction actions while assuming some risk. Work with your governance partners to determine reasonable standards for a Big Bucket policy and quantifying the acceptable amount of risk your company is willing to assume to achieve cost and efficiency benefits.
  4. Enforce Legal Holds – Cleansing your data lakes and silos to save costs and minimize risk is an exercise in defensible destruction but requires awareness of outstanding legal holds. A company that spoliates evidence subject to a legal hold, even without malice, can be fined and suffer adverse inference litigation rulings resulting in unfavorable judgments. Additionally, healthy oversight of records under a preservation hold doesn’t just make good legal sense, it can also help better identify opportunities for even more defensible destruction, cost reduction and risk mitigation.
  5. Activate File Analysis – The tricky thing about new laws like the CCPA is that they require companies to find and produce data for the consumer wherever it exists. That can be a cumbersome test for many entities that have hundreds or thousands of repositories. Luckily, advanced File Analysis tools can plug directly into your network and help quickly identify sensitive and personally identifiable information (PII). They can also help you deduplicate records and find redundant, obsolete and trivial data clogging your systems, also known as ROT. These tools produce a tangible ROI that management can point to as a prime example of why IG works.
  6. Embrace Content Migrations – Unless you’ve only lived in one home your entire life, you’ve probably experienced the cathartic process of cleansing your old wares in preparation for a move. Bringing in a new content management system is not much different and it’s a unique opportunity to apply retention to your data, discard ROT and provide employees with more accurate knowledge resources.
  7. Bake-in Best Practices – Information Governance is not a “one and done” proposition, it’s a rinse and repeat discipline that only works when management sees to it that organizational culture is along for the ride. These days a basic understanding about data handling is vital for every new hire. Concepts like records retention, data protection and privacy should be part of any overall corporate training plan.

By complementing policy frameworks and toolsets with the types of Information Governance approaches noted here we can better enable our workforce to hone their knowledge skills, achieve defensible destruction and improve audit outcomes. In effect, we are future proofing ourselves for a business world destined to face increased scrutiny and under siege from data breaches and privacy issues with seemingly no end in sight. IG is the bright light at the end of that tunnel.

Rafael Moscatel, CRM, IGP, is the Managing Director of Compliance and Privacy Partners, LLC. Reach him at 323-413-7432, follow him on Twitter at @rafael_moscatel or visit http://www.capp-llc.com to learn more.

Originally published in Document Media Magazine, July 2019.

Less is more, gaps are opportunities and relationships matter: A Case Study in Information Governance at #AIIM2018!

AIIM 2018 is just around the corner and I’m thrilled to be presenting my Case Study at this great conference which takes place April 10-13th, in San Antonio! Hope you can join me and so many like-minded in San Antonio this year or later in May when I’ll also be speaking about a program which was recently honored by ARMA International with its Excellence for an Organization Award!  Here are a few slides from my session which will be held on April 12th at 5PM.

This slideshow requires JavaScript.

Farmers Insurance Wins Trade’s Highest Award For Records And Information Governance

Earlier this month, Farmers Insurance Group, Inc. was honored with the highest award for Records Management and Information Governance, “Excellence for an Organization,” by ARMA International. The award recognized the achievements that our organization has made in the implementation and enhancement of our Records and Information Governance program as defined by the Generally Accepted Recordkeeping Principles® and the ARMA Maturity Model®. ARMA announced the award in InfoPro Magazine and at the ARMA Live Conference in Orlando.

ARMA 8

June 2016 Member Spotlight: Rafael Moscatel, IGP, CRM

Very proud to be featured by ARMA’s Info Pro publication this month!

Jun 15, 2016

ARMA received the following nomination from April Dmytrenko, CRM, FAI, for the Member Spotlight:

Meet Rafael Moscatel, IGP, CRM

Rafael Moscatel is a Certified Records Manager (CRM) and Information Governance Professional (IGP) with more than 20 years of experience implementing world-class records retention, data governance, and compliance programs for large enterprises. He designed process transformations, led team-building efforts, and spearheaded change management initiatives in a variety of complex and highly regulated industries. His expertise includes developing document management strategies, decommissioning legacy systems, performing risk assessments, and performing audit remediation.

Rafael truly understands his field and specifically IG and technology. He was instrumental in rolling out the enterprise-wide program at Paramount Pictures. Now he is working for Farmers Group, where he has established an outstanding IG framework from which to continue to support an effective program. He is proactive, strategic, and not only a talented RIM professional but an excellent business professional. He develops outstanding collaborative relationships, understands the value of senior management support and involving the business units, and is a strategic risk taker.

Moscatel lives and works in Los Angeles. He serves as the director of information governance for Farmers Group, Inc. He has been an ARMA member for 12 years.

As you can tell, Rafael is a great fit for the Member Spotlight, an honor meant to recognize members’ involvement within the profession and the association. If you would like to network with him, you can contact him through LinkedIn www.linkedin.com/in/rafaelmoscatel or at rafaelmoscatelcrm.wordpress.com

Read More Here….

ARMA Spring Conference

Please join me and some of my esteemed colleagues at the Annual ARMA-GLA Spring conference taking place this April at the Microsoft Technology Center in Playa Vista on April 15th, 2016!

DETAILS:

REGISTRATION CUT OFF:   April 8, 2016
CANCELLATION POLICY:  Full Refund if Canceled before April 8.   $50 cancellation fee if cancelled after April 8.
TRANSFER POLICY:  Registrations are transferrable anytime PRIOR to the event.   Attendance can not be SPLIT.  One attendee per admission only.   Please contact Event Organizer for transfer requests.
LOCATION:
The Microsoft Technology Center

The Paperless Office

By Rafael Moscatel

The extent to which any organization can reduce its dependency on paper is largely determined by laws and the industry regulations it faces, the technology available to it and how well its leaders manage change, internally as well as for customers.

Here are some thoughts on how to begin solving the paper problem around your office:

Understand the affordances of paper  One of the most thorough examinations of the issue of paper and its role in our lives and workplaces came in 2002 when MIT press published The Myth of the Paperless Office.  The book’s findings make a case for the “affordances of paper” and stress that to reduce paper production and consumption we must understand the underlying habits and processes driving how our clients and colleagues work.

Attorneys for example often require a contextual or “case at a glance” perspective that a chronological or issue focused file offers… a “story telling” approach to presenting information which can’t always be matched even with the best software. Similarly, auditors or project managers will often work with and create aggregated records which serve a specific purpose for which imaging might be overkill or too costly. And contrary to popular belief, there still exist quite a few scenarios where it remains more affordable, practical and efficient to even store information in paper form. Conversion costs and risks required to maintain the digital lifecycle of infrequently referenced documents and avoid bitrot* can often exceed those associated with retaining the same materials in paper form.

Make the right policy changes with executive level support  Every Records or Information Governance policy initiative or project your business undertakes should have senior level executive support and reflect the best practices within your industry.

Here are some policy and procedural ideas to consider that can act as catalysts for change.

  • Get a Retention Policy / Schedule, implement it and regularly enforce it -A Retention Schedule (often in line with a data map) is the most effective tool for properly managing records and information and its necessity cannot be understated.  It not only protects an organization and keeps paper and electronic storage costs low, it gives executives a tool for understanding and navigating the massive network of silos and records their businesses create.
  • Institute an E-signature Policy for all contracts under a specified financial threshold
  • De-duplicate emails and all other electronic content repositories systematically
  • Identify where duplicates are created, determine why and what can be done to prevent them going forward
  • Take a “final draft and / or executed version” approach to your document lifecycle rules Continue reading “The Paperless Office”