Back to Articles|Published on 10/3/2026|26 min read
NetSuite Data Retention Policy: Backup, Archive, Delete

Houseblend Article

NetSuite Data Retention Policy: Backup, Archive, Delete

Summary

  1. 01A NetSuite retention policy assigns decisions by record class, entity, jurisdiction, authority, trigger, and owner. Service backups alone do not establish legal retention periods.
  2. 02Keep active records, export for a defined task, archive historical evidence, delete or anonymize only when authorized, and suspend disposal for applicable holds.
  3. 03Full CSV Export does not export all data. Combine extraction routes and preserve Internal IDs, attachments, audit evidence, and metadata so records remain interpretable.
  4. 04Archive acceptance requires completeness, financial, relationship, readability, security, and integrity checks before source data is removed or NetSuite access ends.
  5. 05Finance, privacy, technical, archive, and legal owners share the control process. Review authorities, access, holds, and sampled retrieval at least annually.
Inside this article
  1. 01Executive Summary
  2. 02Introduction and Background
  3. 03What a NetSuite Retention Policy Controls
  4. 04Record Classes and the Source-and-Owner Matrix
  5. 05Decision Workflow: Keep, Export, Archive, Delete, or Hold
  6. 06Export, Archive, and Deletion in NetSuite
  7. 07Migration, Offboarding, and Operating Ownership
  8. 08Data Analysis and Evidence
  9. 09Implications and Future Directions
  10. 10Frequently Asked Questions (FAQs)
  11. 11Conclusion

Executive Summary

A NetSuite data retention policy is a record-class decision schedule, not a statement that Oracle has backups. Oracle describes replication, archival backups, and disaster recovery for service resilience; its public data-management page also says archival backups support customer-initiated restores for 60 days. [1] That statement does not establish a guaranteed point-in-time restore for every account, nor does it choose which invoices, approvals, payroll records, or personal information a company must preserve. The executed agreement, order form, and support terms control the account-specific service position. [2]

The practical decision is to keep in NetSuite, export for a defined task, archive in a governed repository, anonymize or delete when authorized, or preserve under hold. Each choice needs an entity and jurisdiction, a named source of authority, a retention trigger, an owner, and proof that the record and its attachments can be retrieved. The US Internal Revenue Service (IRS) ties tax records to the relevant limitations period and lists different periods for different situations. [3] The Canada Revenue Agency (CRA) generally uses six years after the last related tax year for required business records, with exceptions. [4] These are examples for a schedule, not an ERP-wide rule.

Exports require more than a spreadsheet. Oracle says Full CSV Export does not export all data [5]; its documentation points to reports, saved searches, web services, and SuiteAnalytics Connect for detailed extraction. It recommends preserving Internal IDs so related records can be joined. [6] CRA guidance requires electronically kept tax records to remain readable and retrievable, including after systems change; [7] the IRS likewise expects electronic records to be indexed, preserved, retrieved, and reproduced. [8] A defensible archive therefore tests row counts, balances, IDs, links, attachments, access, and readability before any source data is removed or a NetSuite subscription ends.

Privacy and statutory retention must be reconciled by class. The federal Canadian privacy law limits personal-information retention to its purposes, [9] while Québec law allows destruction or compliant anonymization after purposes are fulfilled, subject to preservation periods. [10] NetSuite's Personal Information Removal feature has documented field and audit-history limits, [11] so an administrator should test it in the current account and route contested requests to privacy and legal owners. This report supplies a working matrix and a review process; it is governance scaffolding, not legal advice.

60 daysOracle public archival-backup window for customer-initiated restores; actual entitlement requires account-specific review
six yearsCanadian required business records generally retained after the end of the last related tax year, with exceptions
100,000 resultsMaximum query return in Oracle REST SuiteQL documentation; an extraction constraint rather than a retention limit

Introduction and Background

A controller often sees one invoice in several forms: a NetSuite transaction, a scanned attachment, a tax-workpaper reference, a customer-facing copy, and an integration payload. Those copies may have different custodians and retrieval methods, but they are still part of the same business event. A useful policy starts with that event and its legal and operational purposes, then assigns an action to each record and copy. The Federal Trade Commission (FTC) recommends inventorying personal information by type and location before setting retention and disposal rules. [12]

The system of record is the authoritative place for an approved fact during operations. The archive is the controlled place where historical evidence remains readable and searchable after ordinary workflows no longer need it. A one-time export is only a transfer until someone proves completeness and assigns custody. A backup is a recovery copy, while replication and disaster recovery support continuity of the service. None of those concepts, by themselves, establishes a legal retention period. Oracle's public description concerns availability, replication, and backups, and its disaster recovery help addresses restoration of an account in a designated data center. [13]

This distinction matters for both US and Canadian entities. An IRS tax rule can depend on the return and the underlying transaction, while a Canadian corporate tax year is a fiscal period. Payroll and privacy obligations can use other triggers. When several rules apply, the schedule needs the longest applicable obligation and any live hold, with counsel deciding conflicts and exceptions. The IRS itself tells businesses to check other requirements before discarding records no longer needed for tax. [3] [14] [15]

The intended readers are finance, records, privacy, legal, and NetSuite administration leaders. The matrix below is a design template. Its example periods are limited to their named authorities and must be completed for each entity, record class, and contract. It is not legal advice.

What a NetSuite Retention Policy Controls

Separate the mechanisms

Table 1 distinguishes mechanisms that are often called "retention" even though they answer different questions.

MechanismQuestion it answersOwner and evidenceBoundary
Service replication and disaster recoveryCan the hosted service resume after an infrastructure disruption?Oracle operates the service; customer reviews the applicable service documents.It does not assign a statutory period to a customer invoice.
Backup and operational restoreCan a recoverable copy support a specific restoration request?Oracle's public page mentions a 60-day archival-backup window; the customer checks actual entitlement and scope. [1]Do not assume any arbitrary historical point or record-level recovery.
NetSuite operational historyCan current users inspect transactions, approvals, and changes?Administrator validates record types and System Notes coverage. [16]Check deletion coverage separately.
ExportCan selected data be extracted for audit, migration, or analysis?Data owner approves scope; administrator produces and reconciles files.Export alone does not prove long-term readability.
Governed archiveCan authorized people retrieve authentic historical evidence later?Records owner controls formats, access, fixity, and retrieval tests. [17] [18]Its content and retention period still need a schedule.
Retention schedule and holdWhat is kept, for how long, from which trigger, and when may it be destroyed?Counsel and records owner approve authority and exceptions. [19]Hold suspends scheduled disposal until released. [20]

The table suggests a control chain: identify the record, decide the applicable duty, preserve the needed content and context, test retrieval, and only then approve disposal. The National Archives' guidance on migration emphasizes retrievability and usability; it is a useful design benchmark, not a private-sector legal requirement. [17]

Why the platform backup is not the company's archive

Oracle says production account data is backed up multiple times daily for disaster recovery. This is a service fact, not an assurance that a controller can select a record, date, or attachment and obtain it on demand. A company should obtain current account-specific contract and support wording before treating any published window as an operational recovery objective. [21] [2]

The question is also one of responsibility. The IRS says using a third-party records custodian does not relieve the taxpayer of recordkeeping responsibilities. CRA's current electronic-record guidance says the same for outsourced recordkeeping in Canada. These authorities support a customer-owned inventory, access plan, and test evidence even when a cloud provider operates resilient infrastructure. [22] [23]

Figure 01
Service backup and governed archive
Service backup
  • A recovery copy supports continuity alongside replication and disaster recovery.
  • Review current account-specific contract and support wording before treating a published window as a recovery objective.
Governed archive
  • Historical evidence remains readable and searchable after ordinary workflows no longer need it.
  • Define the schedule, preserve linked evidence, control access, and test integrity and retrieval.

Record Classes and the Source-and-Owner Matrix

The first implementation decision is classification. General ledger transactions, source documents, employment records, customer and vendor details, item and production records, approvals, integration logs, attachments, and shopper analytics should not inherit one period from the NetSuite account. A transaction may need a different trigger from its customer master, while an attached invoice may be essential to explain the posted amount. The IRS identifies invoices and receipts as transaction support; CRA requires source documents alongside electronic records. [24] [25]

Table 2 is a starter decision matrix with a separate custody and approval checklist. "Set" and "Pending" mean the organization must enter and approve its specific value before authorizing disposition. The example period is the rule stated by the linked authority, not a universal answer. Complete a separate schedule entry for each jurisdiction and actual legal entity, and map its system of record. The legal-hold override checklist field should point to a tracked hold ID, not a free-text memory.

Record/data class and examplePurposeTrigger dateRetention period / authorityAction
GL and transactions — US: Journal, invoice, credit memoBooks, tax, auditReturn filing date; early returns, refund claims, and property records remain pending separate tax review. Enter the actual applicable date before calculating disposition.Applicable IRS limitations period to be entered; no automatic disposal for early returns, refund claims, or property records.
[3]
Keep then archive
GL and transactions — Canada: Journal, invoice, credit memoBooks, tax, auditPending actual trigger date under the CRA rule and exceptions; no destruction date authorized until completed.CRA generally six years after last related tax year.
[4]
Keep then archive
Source documents and tax — Vendor bill, receipt, tax fileSubstantiate entries and filingsRelated tax year and filing dateMatch applicable tax record; assess CRA late-filing and exception rules
[24] [26]
Export then archive
Payroll and employment tax — Payroll journal, tax remittanceWage and tax supportTax due or paid, whichever laterIRS employment-tax records at least four years
[27]
Keep or archive
Wage-computation support — Time and pay calculationFair Labor Standards Act supportPending record-specific legal review; do not calculate a destruction date from record creationAt least two years for supplementary basic records under 29 CFR 516.6; payroll records require separate review under 29 CFR 516.5
29 CFR 516.6; 29 CFR 516.5
Archive
Personnel records — Employee master, approvalEmployment administrationRecord actionEEOC generally one year; other rules may extend
[28]
Keep or archive
Vendor/customer masters — Entity record, addressPayables, receivables, servicePurpose ends, subject to tax evidenceDefine minimum and maximum by purpose and law
[29] [9]
Minimize; delete/anonymize when lawful
Item and production — Item, lot, work orderTraceability and costingProduct event or period closeNamed industry and contract authority to be entered
[19]
Keep or archive
Approvals and audit trail — Workflow history, System NotesExplain authorization and changeRelated transaction eventFollow underlying record schedule; verify log coverage
[16]
Export and archive
Integrations and interfaces — API payload, exception logReconcile data movementInterface event or reconciliation closeBusiness schedule and privacy purpose to be entered
Pending applicable business schedule or law; no retention authority assigned
Keep short term or archive selected evidence
Attachments and File Cabinet — Contract, signed approvalProve transaction or agreementContract end or related tax yearMatch controlling document and transaction rule
[30] [25]
Export and archive
Shopper analytics and other PII — SuiteCommerce event dataAnalytics or service purposeCollection or purpose endOracle's six-month shopper-analytics rule applies only to that feature
[31]
Feature-specific deletion or lawful archive

Custody and approval checklist for Table 2

This remains an incomplete template. Complete the checklist for every record class and actual legal entity before approving disposition. For GL and transactions, create separate US and Canadian schedule entries; do not calculate a destruction date for early returns, refund claims, or property records until tax counsel has documented the applicable rule, dates, and property-disposal linkage. A hold overrides scheduled disposal.

GL and transactions

  • Jurisdiction/entity: Set US/CA entity.
  • System of record: NetSuite until closed; archive after validation.
  • Legal-hold override: Hold ID or none.
  • Archive format: CSV plus schema, PDF when needed.
  • Attachments included: Yes, if source support.
  • Related-record keys: Internal ID, document number, subsidiary.
  • Encryption/access owner: Finance archive owner.
  • Deletion approver: Controller plus counsel.
  • Restore/retrieval test date: Enter date.
  • Counsel signoff: Required.
  • Last review: Enter date.

Source documents and tax

  • Jurisdiction/entity: Set entity.
  • System of record: File Cabinet or linked source.
  • Legal-hold override: Hold ID or none.
  • Archive format: Original file plus manifest.
  • Attachments included: Yes.
  • Related-record keys: Transaction ID, file ID, hash.
  • Encryption/access owner: Tax records owner.
  • Deletion approver: Controller plus counsel.
  • Restore/retrieval test date: Enter date.
  • Counsel signoff: Required.
  • Last review: Enter date.

Payroll and employment tax

  • Jurisdiction/entity: US employer, set state.
  • System of record: Payroll provider plus NetSuite postings.
  • Legal-hold override: Hold ID or none.
  • Archive format: CSV, payslip source where lawful.
  • Attachments included: As applicable.
  • Related-record keys: Employee token, period, journal ID.
  • Encryption/access owner: Payroll privacy owner.
  • Deletion approver: Payroll lead plus counsel.
  • Restore/retrieval test date: Enter date.
  • Counsel signoff: Required.
  • Last review: Enter date.

Wage-computation support

  • Jurisdiction/entity: Covered US employer.
  • System of record: Payroll/time system.
  • Legal-hold override: Hold ID or none.
  • Archive format: Native plus readable export.
  • Attachments included: Yes.
  • Related-record keys: Employee token, pay period.
  • Encryption/access owner: Payroll privacy owner.
  • Deletion approver: Payroll lead plus counsel.
  • Restore/retrieval test date: Enter date.
  • Counsel signoff: Required.
  • Last review: Enter date.

Personnel records

  • Jurisdiction/entity: Covered US employer.
  • System of record: Human resources system.
  • Legal-hold override: Hold ID or none.
  • Archive format: Portable export with access log.
  • Attachments included: As applicable.
  • Related-record keys: Employee token, action ID.
  • Encryption/access owner: HR privacy owner.
  • Deletion approver: HR plus counsel.
  • Restore/retrieval test date: Enter date.
  • Counsel signoff: Required.
  • Last review: Enter date.

Vendor/customer masters

  • Jurisdiction/entity: Set entity and privacy law.
  • System of record: NetSuite while active.
  • Legal-hold override: Hold ID or none.
  • Archive format: CSV plus mapping.
  • Attachments included: Review individually.
  • Related-record keys: Entity ID, transaction IDs.
  • Encryption/access owner: Privacy owner.
  • Deletion approver: Privacy lead plus counsel.
  • Restore/retrieval test date: Enter date.
  • Counsel signoff: Required.
  • Last review: Enter date.

Item and production

  • Jurisdiction/entity: Set entity and industry.
  • System of record: NetSuite or manufacturing system.
  • Legal-hold override: Hold ID or none.
  • Archive format: CSV plus schema and lineage.
  • Attachments included: As applicable.
  • Related-record keys: Item ID, lot ID, work order.
  • Encryption/access owner: Operations data owner.
  • Deletion approver: Operations plus counsel.
  • Restore/retrieval test date: Enter date.
  • Counsel signoff: Required.
  • Last review: Enter date.

Approvals and audit trail

  • Jurisdiction/entity: Set entity.
  • System of record: NetSuite plus separate archive.
  • Legal-hold override: Hold ID or none.
  • Archive format: CSV with timestamps and actor IDs.
  • Attachments included: Relevant evidence.
  • Related-record keys: Record ID, event ID.
  • Encryption/access owner: Internal controls owner.
  • Deletion approver: Controller plus counsel.
  • Restore/retrieval test date: Enter date.
  • Counsel signoff: Required.
  • Last review: Enter date.

Integrations and interfaces

  • Jurisdiction/entity: Set entity.
  • System of record: Integration platform.
  • Legal-hold override: Hold ID or none.
  • Archive format: Structured log plus schema.
  • Attachments included: Exception evidence.
  • Related-record keys: Source ID, target ID, run ID.
  • Encryption/access owner: IT security owner.
  • Deletion approver: IT plus counsel.
  • Restore/retrieval test date: Enter date.
  • Counsel signoff: Required.
  • Last review: Enter date.

Attachments and File Cabinet

  • Jurisdiction/entity: Set entity.
  • System of record: File Cabinet or document repository.
  • Legal-hold override: Hold ID or none.
  • Archive format: Original binary plus manifest.
  • Attachments included: Entire class.
  • Related-record keys: File ID, parent record ID.
  • Encryption/access owner: Records owner.
  • Deletion approver: Controller plus counsel.
  • Restore/retrieval test date: Enter date.
  • Counsel signoff: Required.
  • Last review: Enter date.

Shopper analytics and other PII

  • Jurisdiction/entity: Set privacy jurisdiction.
  • System of record: Feature-specific store.
  • Legal-hold override: Hold ID or none.
  • Archive format: Minimal export if justified.
  • Attachments included: Usually no.
  • Related-record keys: Pseudonymous event ID.
  • Encryption/access owner: Privacy owner.
  • Deletion approver: Privacy lead plus counsel.
  • Restore/retrieval test date: Enter date.
  • Counsel signoff: Required.
  • Last review: Enter date.

Sanitization-control note for integrations: NIST SP 800-88 Rev. 2 describes media sanitization as making access to target data infeasible for a given level of effort. Use it as a sanitization-control reference; the integration row's retention authority remains pending. [32]

The matrix is deliberately incomplete where authority depends on the company. A record's source URL is evidence for the rule, while counsel signoff approves its application to the entity. A blank test date means archive readiness has not been established. Payroll illustrates why even US federal periods diverge: the IRS employment-tax rule, DOL payroll rule, and DOL wage-computation rule use different scope and triggers. [27] [33] The File Cabinet and System Notes rows also require separate sampling because Oracle documents that original System Notes and System Notes v2 differ in deleted-record coverage.

A durable archive is one whose contents can still be understood and produced when requested, not merely one that has occupied storage for a stated number of years.

Decision Workflow: Keep, Export, Archive, Delete, or Hold

A policy becomes operational when every class travels through the same approval path. The FTC recommends a written policy saying what information must be kept, for how long, and how it will be disposed of. The Canadian privacy regulator advises minimum and maximum periods rather than indefinite accumulation. [19] [29]

  • Identify the record and copies. List NetSuite record types, File Cabinet attachments, exported reports, integrated applications, user downloads, and backups that contain the same information. [12] [34]
  • Name the entity and jurisdiction. A group-wide label is insufficient when tax, employment, and privacy rules differ by legal entity and place. [3] [4]
  • State the purpose and system of record. Separate current operational use from audit evidence, statutory records, analytics, and temporary transfers. [9]
  • Choose the trigger. Use the exact event in the source rule, such as tax year, filing, payment, disposition, or end of purpose. [35] [14]
  • Record the named authority. Link the primary law, regulator guidance, contract, or approved business schedule and identify its reviewer. [36]
  • Check for holds. Suspend disposal for a relevant hold and document release before resuming the schedule. The National Archives' federal freeze definition is a useful conceptual model, not a private-company mandate. [20]
  • Choose the least excessive action. Keep active records in NetSuite; export for a defined audit or migration task; archive closed evidence; minimize personal information; delete only when authorized. [37]
  • Set archive controls. Name the format, metadata, parent-child keys, encryption, access owner, and restoration test. [38] [18]
  • Approve and log disposal. Require the record owner and legal/privacy reviewer to authorize deletion, then retain a disposition certificate without preserving excess personal data. [32]

A privacy deletion request is an input to this workflow, not an automatic deletion command. California's official consumer FAQ recognizes deletion requests and exceptions for legal obligations and claims. Canadian federal law says personal information should be destroyed, erased, or made anonymous when no longer required for identified purposes. Québec law similarly allows destruction or compliant anonymization after the purpose is achieved, subject to preservation periods. The privacy owner should isolate data whose purpose has ended, legal counsel should identify any still-applicable record duty or hold, and the administrator should implement only the approved scope. [39] [40] [41] [10]

Export, Archive, and Deletion in NetSuite

Extract a complete, interpretable record

Oracle's Full CSV Export is a starting point, not a complete account archive. Its help says the option does not export all data. [5] Oracle lists saved searches, reports, SOAP web services, and SuiteAnalytics Connect as other routes for detailed data. It notes that including Internal ID preserves relationships among exported rows. A practical extraction plan maps each record type to a route and records what is missing. [6] [42]

  • Reports and saved searches: Export defined populations with dates, filters, field lists, and saved definitions; use reports where transaction totals are easier to reconcile. [43]
  • SuiteAnalytics Connect: Confirm the add-on is licensed and the export role has the required permissions. Oracle warns that the NetSuite2.com schema differs from the older source. [44]
  • Application programming interfaces (APIs): Use a tested integration for incremental extracts and retry logging. Oracle documents a 100,000-result maximum for SuiteQL through REST, so partition larger populations or use a suitable alternative. [45]
  • File Cabinet: Download needed files and folders separately, preserve folder paths, and join file IDs to parent records. Oracle says folder downloads retain structure in a ZIP. [30]
  • Audit history: Export System Notes or other notes separately where needed; Oracle says original System Notes do not retain deleted transaction and record details, while System Notes v2 retains information for supported types. [16]

A valid archive should preserve content, context, and proof of integrity. The IRS says computerized records should identify underlying source documents and reconcile to books and returns. CRA's electronic-record memorandum requires audit trail links between source documents and summarized accounts and expects records to remain readable after a system change. The Library of Congress describes file-level fixity logging and comparison as an integrity practice. These sources support a manifest containing field layouts, record IDs, timestamps with time zones, attachment names, checksums, extraction software version, and reconciliation results. [46] [47] [18]

  • Completeness test: Compare exported counts by class, subsidiary, period, status, and deletion flag with source searches. Investigate every mismatch.
  • Financial test: Reconcile trial balances, transaction totals, tax reports, and open items to signed period-end reports. [46]
  • Relationship test: Join parent and child IDs, customer/vendor references, item and lot keys, and attachment IDs across files.
  • Readability test: Open random records without NetSuite access, render attachments, and reproduce a requested audit trail. CRA explicitly requires continued electronic readability and exportability. [7]
  • Security test: Confirm role-restricted access, encryption, export logging, retention tags, and recovery from the archive's own backup. The FTC advises limiting sensitive-record access to a legitimate business need. [48]
  • Integrity test: Store a manifest of hashes or checksums, then compare it in periodic retrieval tests. The Library of Congress uses recorded fixity metadata to monitor changes. [18]

Delete only after dependencies and authority are clear

NetSuite deletion mechanics differ by object. Oracle says it does not retain details of a deleted transaction, even when the audit trail records that deletion occurred. It also documents restrictions on deleting a transaction linked to another transaction or held in a closed accounting period. Consequently, deleting old data is a controlled project: select the population, review downstream references, archive required evidence, obtain approval, test in a safe environment, execute in batches, and retain a minimal disposition log. [49] [50]

NetSuite's Personal Information Removal feature can replace personal information in fields, records, and audit logs, but Oracle documents exclusions, including sublist fields and some address information needed for tax and shipping calculations. The feature leaves audit history logs while changing specified values. Its request and run permissions are separate. Administrators should verify current account behavior, customization, integrations, and exports before promising a complete erasure result. [11] [51] [52]

Figure 02
Validate the archive before removing source data
  1. 01Check completeness

    Compare exported counts with source searches by class, subsidiary, period, status, and deletion flag. Investigate every mismatch.

  2. 02Reconcile financial totals

    Reconcile trial balances, transaction totals, tax reports, and open items to signed period-end reports.

  3. 03Verify relationships

    Join parent and child IDs, customer/vendor references, item and lot keys, and attachment IDs across files.

  4. 04Test independent readability

    Open random records without NetSuite access, render attachments, and reproduce a requested audit trail.

  5. 05Confirm security controls

    Confirm role-restricted access, encryption, export logging, retention tags, and recovery from the archive backup.

  6. 06Check integrity over time

    Store a manifest of hashes or checksums and compare it in periodic retrieval tests.

A policy that cannot pass its own retrieval test should remain in remediation.

Migration, Offboarding, and Operating Ownership

Before a migration or NetSuite offboarding, decide which records stay operational and which become archive-only. Houseblend's own migration service page says its work includes deciding which historical data and open transactions move into NetSuite and which remain archived; its managed support page describes administration, roles, searches, and reporting support after go-live. This is a relevant implementation capability, not a legal authority or a substitute for the customer's record owner. [53] [54]

Oracle's June 15, 2026 hosting policy says it applies only when the customer's agreement or order refers to it. [2] Where it applies, it advises retrieving data while access remains active, describes a request-based retrieval period after termination, and then a deletion process. A finance team should compare that policy with its executed documents and complete extraction, access-control transfer, and retrieval acceptance before reducing licenses or relying on post-termination access.

  • Scope owner: The controller signs off account balances, open items, tax support, and transaction populations. [46]
  • Privacy owner: The privacy lead identifies personal-information purpose, minimization, requests, and deletion exceptions. [37]
  • Technical owner: The NetSuite administrator maps fields, roles, saved searches, APIs, File Cabinet attachments, and System Notes coverage.
  • Archive owner: Records management validates format, metadata, access, encryption, integrity, and repeatable retrieval. [38] [18]
  • Decision owner: Counsel approves legal periods, holds, and final disposal rules; the business owner confirms the operational need. [36]

Table 3 locates implementation support without treating a services firm as the custodian of the company's legal obligations.

Delivery routeWork it can performDecision and accountability boundary
Internal finance, records, privacy, and IT teamSet rules, approve holds, reconcile records, own repository access.The organization owns the schedule and signoff. [22]
Houseblend NetSuite servicesIts published migration scope includes historical/open-data decisions and validation; its managed support scope includes admin and reporting requests. [53] [54]Service scope must be agreed separately; counsel and record owners approve retention and deletion.
Archive software or external repository operatorStore approved packages, enforce access, run retrieval and integrity tests. [18]A supplier's storage capability is evidence only after the organization tests it; outsourcing does not move tax responsibility. [23]

The table keeps procurement honest: implementation labor, archive storage, and legal decision authority are separate. An internal team can perform all the work, but it should still document acceptance criteria and a named owner for each step. Annual review should refresh legal authorities, Oracle feature behavior after releases, permissions, and sampled archive retrieval. The privacy commissioner recommends regular reviews of whether personal information is still needed.

The annual control packet should show six completed checks:

  • Authority: Confirm each linked law, guidance page, and contract term still applies to the entity.
  • Population: Reconcile record counts and financial totals against the approved extraction scope.
  • Readability: Retrieve a sampled record and attachment without the source application.
  • Security: Reapprove access roles, encryption ownership, and service accounts.
  • Holds: Reconcile active hold IDs, release approvals, and suspended deletion jobs.
  • Disposition: Review due-for-deletion populations and retain the approval trail. [37]

Data Analysis and Evidence

The most consequential numbers in this topic are retention triggers and scope, not market-size estimates. The IRS lists a three-year general income-tax record period when its exceptions do not apply, [55] six years for a substantial omission of income, [56] seven years for a worthless-securities or bad-debt claim, [57] and four years for employment-tax records after the tax is due or paid, whichever is later. [27] These periods describe different facts. They do not produce a rule that every NetSuite record should be kept seven years.

Canadian required business records generally stay six years after the end of the last related tax year; [4] CRA guidance states exceptions for late filing, objections, and certain long-term records. [58] Its September 2026 electronic-record memorandum expects electronically readable records and continued ability to export required information in a common nonproprietary format. [7] Thus an old CSV with lost headers, broken encodings, or missing linked documents could fail the practical retrieval test even if it sits in storage for the nominal period.

Employment and privacy data show why a single account-wide timer is mathematically wrong. The US Department of Labor specifies three years for covered payroll records [59] and two years for wage-computation records under its Fair Labor Standards Act guidance; [33] the Equal Employment Opportunity Commission generally specifies one year for covered personnel records. [28] Québec's current private-sector law adds purpose-based destruction or compliant anonymization, subject to required preservation. [10] Each rule must be mapped to the correct class and covered entity.

For capacity planning, use the measured export rather than an invented "cost per record": projected archive bytes = annual records × measured average bytes per record × years retained × growth factor. (Hypothetical Example) If a tested sample averages 8,000 bytes and the organization expects 100,000 new records each year for six years with a 1.2 growth factor, the illustrative result is 5.76 billion bytes before replicas, indexes, and attachments. The inputs are hypothetical; the formula is a capacity estimate, not a legal requirement or price quote. Measure attachment size and multiple record classes separately, then rerun the estimate after actual exports.

The NetSuite figures are also feature-specific. Oracle's public service page refers to 60 days of archival backups for customer-initiated restores. [1] Oracle's SuiteCommerce Analytics privacy page says shopper analytics data is deleted six months after collection [31] and temporary identifiable information after 30 days plus an offline index period. [60] Those periods do not describe core ERP transaction retention. Oracle's REST SuiteQL documentation caps a query at 100,000 results, [45] which is an extraction-planning constraint, not a retention limit.

Implications and Future Directions

The immediate governance improvement is to make each deletion or archive decision reproducible. A reviewer should be able to start with an invoice ID, find the controlling schedule row and named authority, see the hold check, open the archived transaction and attachment, inspect the reconciliation result, and identify who approved disposition. The IRS's electronic-record guidance emphasizes indexed, retrievable, reproducible records; CRA's guidance emphasizes usability after system changes. [8] [61]

A second implication is that privacy programs and finance programs should use the same inventory. PIPEDA's schedule language asks for minimum and maximum periods, while the FTC advises inventorying personal information by type and location. This encourages a shared data map for NetSuite, integrations, exports, attachments, and backups, with separate legal bases for financial evidence and personal data. Québec's anonymization rules also require re-identification risk analysis and periodic reassessment, so replacing a name with a code is not automatically a final disposal action. [62] [12] [63]

The architecture should be tested after each meaningful NetSuite release, integration change, entity acquisition, repository migration, or records-rule update. The National Archives describes sustainable electronic formats in terms of access throughout the record lifecycle. The Library of Congress's fixity process illustrates how integrity evidence can be generated and compared. These are design references; the controlling legal rule remains the authority assigned to each matrix row. [38] [18]

Finally, the operating model needs a calendar. Review the schedule and legal sources at least annually; sample retrieval by record class; review user access and encryption ownership; and record any exception or hold release. Re-run export validation before license reduction or system retirement. A policy that cannot pass its own retrieval test should remain in remediation, regardless of the number of years written into the schedule. [37] [61]

Frequently Asked Questions (FAQs)

Does NetSuite keep all accounting data for seven years?

No universal period follows from NetSuite's service documentation. The IRS uses different periods for different tax situations, and CRA generally uses six years for required business records with exceptions. The correct answer depends on the entity, record, trigger, applicable laws, and holds. [57] [4]

Is NetSuite backup the same as an archive?

No. Oracle describes replication, backups, and disaster recovery to support service resilience, including a public 60-day archival-backup statement. An archive needs a customer-defined schedule, searchable content, linked evidence, access control, integrity checks, and periodic retrieval tests. Check the executed contract for the actual recovery position. [1] [17]

How can a team archive historical NetSuite data?

Map record classes first, then combine the relevant reports, saved searches, web services or SuiteAnalytics Connect extracts with File Cabinet files and audit evidence. Preserve Internal IDs, field layouts, timestamps, attachment relationships, and reconciliation results. Validate a sample without NetSuite access before approving the archive. [6] [7]

Can old transactions simply be deleted?

Deletion should follow the approved schedule, hold check, export test, and linked-record review. Oracle says details of a deleted transaction are not retained, and it documents restrictions for linked transactions and closed periods. NetSuite's personal-information tools have separate coverage rules. [49]

What happens during NetSuite offboarding?

Extract and verify required data while access is active, map every attachment and dependent record, transfer ownership to a governed repository, and perform an independent retrieval test. The current Oracle hosting policy applies only where incorporated into the customer's agreement or order, so contract review is essential before relying on any post-termination access window. [2] [23]

Conclusion

A useful NetSuite data retention policy turns broad compliance language into a controlled decision for each record class. It distinguishes service backup, operational restore, current system history, export, and governed archive. It names the legal or business source of each period, identifies the entity and trigger, stops disposal for holds, and assigns an owner who can prove retrieval.

The matrix is the working instrument. Populate its open fields with counsel and record owners, verify NetSuite feature coverage and the executed Oracle agreement, test the actual exports and attachments, and record every deletion approval. Revisit the schedule when law, contracts, entities, or system architecture change. A durable archive is one whose contents can still be understood and produced when requested, not merely one that has occupied storage for a stated number of years. The first practical milestone is a signed row for each material class and a test package that a second person can retrieve independently. That test should include both the business record and the evidence needed to interpret it, such as its source document, parent key, timestamp, and approval history. If the test fails, the team has a specific remediation item before it changes access or deletes the source.

External Sources (63)

About

Houseblend

Make NetSuite work better for your finance and operations teams with Houseblend. We help design, implement, integrate and improve ERP systems, with practical support for the people who use them every day.

Houseblend is a NetSuite consulting firm serving finance and operations teams. We help organizations implement ERP systems, connect business applications, improve existing configurations and maintain the systems that support everyday work. Our audience includes finance leaders, controllers, operations managers, NetSuite administrators and implementation teams.

Implementation and architecture

Houseblend provides NetSuite implementation, architecture and data migration services. We help teams evaluate how business processes, reporting requirements and existing data should fit together in an ERP environment. Training supports the people responsible for adopting and operating the resulting system.

Integrations, customization and AI

Our services include NetSuite integrations and customization, as well as AI integrations and AI transformation work. These engagements connect ERP data and workflows with the broader application landscape. The right design depends on the organization's systems, controls and operating needs.

Improve and support an existing system

Houseblend offers NetSuite health checks, optimization, managed support and project rescue services. We also provide expertise for analytics and specialist workflows, including NetSuite Analytics Warehouse, warehouse management and field service management. Published educational material helps teams investigate options and prepare informed questions for their implementation or support work.

Work with Houseblend

Explore NetSuite implementation, integrations, managed support and AI integrations. Contact Houseblend to discuss your current system and priorities.

Article examples explain concepts rather than promising a particular license, product capability, delivery schedule or outcome. Engagement scope is confirmed with the Houseblend team.

Disclaimer

This document is provided for informational purposes only. No representations or warranties are made regarding the accuracy, completeness, or reliability of its contents. Any use of this information is at your own risk. Houseblend shall not be liable for any damages arising from the use of this document. This content was generated with assistance from artificial intelligence tools, which may contain errors or inaccuracies. Readers should verify critical information independently. All product names, trademarks, and registered trademarks mentioned are property of their respective owners and are used for identification purposes only. Use of these names does not imply endorsement. This document does not constitute professional or legal advice. For specific guidance related to your needs, please consult qualified professionals.