Australian privacy law sets no number. Why keeping everything is the riskiest answer, why deleting at once is too, and how to pick a period you can defend.
12 September 2026 · 9 min read
Most businesses that switch on employee monitoring never decide this. The software starts collecting, nobody sets a retention period, and three years later there is a folder containing several hundred thousand screenshots of their staff's screens.
That is not a storage problem. It is the single largest liability most small businesses create for themselves without noticing, and it is created by inaction rather than by a decision.
This is written for the person who has to choose a number. It is not legal advice, and retention obligations differ depending on your industry and what else is in the record.
Australian Privacy Principle 11.2 is the one that matters. It requires an organisation to take reasonable steps to destroy or de-identify personal information when it is no longer needed for any purpose for which it may be used or disclosed.
There is no number in it. No "keep for seven years", no "delete after 90 days". The obligation is tied to purpose: you may hold it while you need it, and you must get rid of it when you do not.
That sounds vague until you turn it around. The question is not "how long am I allowed to keep this?" It is "what am I keeping this for?" If you can answer that, the period follows. If you cannot, you are holding it for no purpose, and APP 11.2 has an opinion about that.
Separately, the Fair Work Act requires employee records — hours, pay, leave — to be kept for seven years. Monitoring output is not that. A screenshot is not a time and wages record, and a seven-year obligation on one does not create permission for the other. Businesses conflate these constantly, usually to justify keeping more.
The instinct is that more evidence is safer. In a dispute, that is sometimes true. Everywhere else it is backwards.
A breach gets worse with volume. The records that make a dismissal defensible are the same records that make a data breach catastrophic. Screenshots can contain anything that was on a screen: a person's banking, their medical appointment, a private message. If you are notified under the Notifiable Data Breaches scheme, the size of what you held is the size of the problem.
Old records rarely help. A dispute about conduct in March is argued with March's evidence. Nobody wins a case with a screenshot from two years ago, but everyone with access can browse it.
It is hard to explain. "We keep it indefinitely" is a sentence you may have to say to an employee, a union, or the OAIC. There is no good version of it. "We keep it for 90 days because that covers our review cycle" is a sentence that ends the conversation.
The opposite reflex is just as costly.
A general protections claim can be lodged well after the event. A workers compensation matter, a performance dispute, an unfair dismissal — these reach back months, and an employer who destroyed the evidence at 30 days has nothing. Not a weaker case: nothing.
So the honest framing for whoever picks the number is this:
> A longer period protects you in a dispute and exposes you in a breach.
Both halves are real. The decision is which risk your business is more likely to face, and it is a decision, not a default. A retention period nobody chose is the worst of both — long enough to be a liability, arbitrary enough to be indefensible.
Start from your own processes. How long does a performance concern take to surface and resolve in your business? If your review cycle is quarterly, a period shorter than a quarter means the records are gone before the conversation that would use them.
Ask what you would actually produce. If a matter went to the Fair Work Commission, what would you hand over? If the answer is "a summary of hours and a pattern of activity" rather than "four thousand screenshots", then you need the summary retained and not the images.
Separate the image from the record. This is the distinction most tools miss. The fact that a capture happened — the time, the application, the window title — is a small, low-sensitivity audit record. The image is the sensitive part. There is no reason those two need the same lifespan.
Write down why. A number with a reason behind it is defensible. The same number picked at random is not, even if it happens to be the same number.
Retention is set per organisation, not by us, because the right period depends on the business.
The important part is what expiry means. When a screenshot passes its retention period the image is destroyed while the record that a capture happened survives — timestamp, application, window title. So the sensitive content is gone on your schedule, and you keep an audit trail proving the policy actually ran.
That last part matters more than it sounds. A retention policy you can only describe is worth much less than one you can demonstrate. If someone asks whether you really deleted the screenshots from eighteen months ago, "yes, and here is the record showing 6,180 images destroyed on that date" is a different answer from "yes, we have a policy".
The cleanup runs nightly against whatever figure you set. Lowering it destroys everything already older than the new number, permanently — which is why the product tells you that at the moment you set it, rather than after.
Pick a number, know why you picked it, and make sure the thing you delete is the thing that was sensitive.
Longer protects you in a dispute. Shorter protects you in a breach. Nobody can make that trade for you, but leaving it unmade quietly chooses the worst version of both.