Keeping Data Is a Risk Decision

Estimated reading time: 8 minutes

Every piece of personal information an organisation continues to hold creates an ongoing responsibility to protect it.

Good governance means knowing not only what you collect, but why you still need to keep it.

Organisations collect personal information for legitimate reasons. Customers create accounts, employees join businesses, students enrol, and information accumulates through everyday operations.

But relationships change. Accounts become inactive, employees leave, customers move on and systems are replaced. The information associated with them does not necessarily disappear.

On 3 September 2026, Mathspace confirmed unauthorised access to an internal reporting system. Its investigation found that information relating to more than one million people across Australia and New Zealand, specifically 1,079,819 people, had been downloaded.

One detail creates a useful governance question. Mathspace confirmed that an account did not need to be active for information retained in the affected reporting database to be involved.

This does not establish that Mathspace retained information unnecessarily or unlawfully. It does raise a broader question many organisations rarely revisit. If we are continuing to hold information, do we still understand why we need it?

Sources: Mathspace, Mathspace Data Breach: What Happened and What Affected Users Should Know, 5 September 2026. Full citations in the References section below.

Information Can Outlive the Relationship That Created It


Organisations often think carefully about information when it is first collected. Why do we need it? Where will it be stored? Who should have access? How will it be protected? Less attention is typically given to what happens later.

A customer may leave, an employee may move on or an account may become inactive, while the information associated with them remains across operational systems, reporting databases, archives, backups or third party environments. The Mathspace incident is a reminder of something worth sitting with. Inactive does not necessarily mean deleted.

Inactive does not necessarily mean deleted.

This creates a useful question for leadership to ask of its own systems. Does the lifecycle of our information still reflect the reason we collected it in the first place?

Retained Information Continues to Create Responsibility


Information can appear passive when nobody is actively using it. But while an organisation continues to hold personal information, responsibilities around security, privacy, access and governance remain attached to it.

Australian Privacy Principle 11 requires covered entities to take reasonable steps to protect the personal information they hold. Where personal information is no longer needed for a permitted purpose, reasonable steps may also be required to destroy or de identify it, subject to applicable exceptions. New Zealand's Privacy Principle 9 similarly states that organisations should not keep personal information longer than required for a purpose for which it may lawfully be used.

Governance QuestionWhat It Actually Asks
How well are we protecting our information?Whether current security controls match the sensitivity of what is held
Do we still need to hold all of it?Whether continued retention still serves a legitimate, current purpose

Both questions matter. Most organisations are comfortable answering the first. Fewer can answer the second with confidence.

Retention Should Have a Purpose


The lesson here is not that organisations should delete information as quickly as possible. Legal, regulatory, contractual and operational requirements often provide legitimate reasons for keeping particular information. The important distinction is whether retention is intentional.

Organisations should be able to explain each of the following for their important information categories:

  • Why the information was collected
  • Why it is still required
  • What requirements apply to it
  • How long it should remain
  • Who is responsible for reviewing it
  • What happens when that purpose ends

The Retention Test

The goal is to move an organisation from one position to another.

We still have it because nobody has removed it.

to

We still have it because there is a clear reason to keep it.


What Business Leaders Can Learn


Know what information you hold. Good retention decisions depend on visibility. Leadership should understand what important personal information exists across the organisation and where it is held, a starting point that a vDPO engagement is often built around before any policy work begins.

Connect retention to purpose. Information should have a reason for continuing to exist. Retention should reflect legitimate business needs and applicable regulatory requirements rather than simply following the path of least resistance.

Do not confuse inactive with deleted. An inactive account or an ended relationship does not necessarily mean the underlying information has been removed. Those two ideas are often assumed to be the same thing until an incident shows otherwise.

Look beyond primary systems. Historical information can remain in reporting systems, archives, backups, cloud environments and third party platforms long after it has left the system leadership tends to think about first.

Make disposal part of governance. Review, deletion and de identification should be deliberate processes with clear ownership, rather than occasional clean up activities left to whoever notices the problem. This is the same governance discipline explored in Board Cybersecurity Responsibilities in 2026, and where tools and implementation support can help put a workable review cycle in place.

Questions Every Executive Should Ask


  • What personal information do we currently hold?
  • Why are we still holding it?
  • What requirements determine how long it should remain?
  • What happens when an account becomes inactive?
  • Where does historical information remain?
  • Do reporting systems, archives or backups contain additional copies?
  • Which third parties retain information on our behalf?
  • Who is responsible for reviewing retention?
  • What triggers deletion or de identification?
  • Can we demonstrate that our disposal processes actually work?

If leadership cannot confidently answer these questions, the issue may not be a missing control. It may be a lack of visibility over the information lifecycle itself.

Reducing Information Can Reduce Exposure


Cybersecurity conversations often focus on adding protection through stronger authentication, access management, monitoring and other controls. Those protections remain important. But organisations can also reduce exposure by considering how much information genuinely needs to remain within the environment in the first place.

Instead of only asking how to protect everything the organisation has, it is worth also asking what the organisation actually needs to keep. Data minimisation does not replace cybersecurity. It reduces the amount of unnecessary information that needs to be protected, which is one reason documented retention decisions form part of the same evidence trail discussed in The Evidence Gap.

At SeComPass, we help organisations approach privacy and cybersecurity through business risk, governance and accountability. Through privacy and data protection advisory, cybersecurity assessments and governance support, we help leadership teams understand where important information exists, where responsibilities sit and whether information handling practices reflect actual business and regulatory requirements.

Key Takeaways


  • Personal information does not stop creating responsibility once an account goes quiet or a relationship ends
  • Australian Privacy Principle 11 and New Zealand Privacy Principle 9 both point to the same underlying question, whether continued retention still serves a genuine purpose
  • Retention should be intentional, with a clear reason, a clear owner and a clear end point rather than left to accumulate by default
  • Historical information often exists well beyond primary systems, in reporting databases, archives, backups and third party platforms
  • Reducing unnecessary information is a practical way to reduce exposure, alongside the technical controls organisations already rely on

Understand What You Are Still Holding

Do You Know Why You Are Still Holding That Information?

The Executive Readiness Review helps leadership teams understand what personal information the organisation holds, why it is retained and whether current governance reflects actual business and regulatory requirements. It includes:

  • A clearer picture of what personal information exists and where it lives
  • Review of why that information is still being retained
  • Assessment against Australian and New Zealand privacy retention obligations
  • Strategic priorities for building a workable review and disposal cycle

Understand what you hold, understand why you need it, and govern it appropriately.

Start the Executive Readiness Review →

References


  • Mathspace. "Mathspace Data Breach: What Happened and What Affected Users Should Know," 5 September 2026. blog.mathspace.co
  • Office of the Australian Information Commissioner. "Australian Privacy Principle 11: Security of Personal Information." oaic.gov.au
  • Office of the Privacy Commissioner New Zealand. "Privacy Principle 9: Retention of Personal Information." privacy.org.nz
  • Office of the Privacy Commissioner New Zealand. "How long does an agency have to keep records for?" privacy.org.nz

This article is for general informational purposes only and does not constitute legal, technical, or professional cybersecurity or privacy advice. SeComPass recommends engaging a qualified adviser before making decisions based on this content. Mathspace confirmed that information retained in the affected reporting database could relate to inactive or former users. This does not establish that the information was retained unlawfully or unnecessarily, and the reference above should be read only as the starting point for a broader governance question rather than a conclusion about Mathspace's practices.

Next
Next

The Hidden Value in an Organisation’s Information