Much has been written about the common-law duty to preserve proportionate information that is potentially relevant to reasonably anticipated litigation.
Much less has been written about the duty to destroy information. For example, Maryland’s Public Information Act limits the records that governmental entities may retain. It provides that:
The State, a political subdivision, or a unit of the State or of a political subdivision may keep only the information about a person that:
(1) is needed by the State, the political subdivision, or the unit to accomplish a governmental purpose that is authorized or required to be accomplished under:
(i) a statute or any other legislative mandate;
(ii) an executive order of the Governor;
(iii) an executive order of the chief executive of a local jurisdiction; or
(iv) a judicial rule; and
(2) is relevant to accomplishment of the purpose.
Md. Code, Gen. Provs. Art. 4-102 (emphasis added).
A public record with temporary value which may be destroyed after the passage of a specified period of time is deemed “non-permanent.” COMAR 14.18.02.02
Additionally, each Maryland unit of government is required to establish records disposal schedules. Md. Code, State Gov’t. Art. §10-610(a); COMAR 14.18.02.02(13); 14.18.02.15. Destruction is permissive if the State Archivist refuses to accept tendered public records. Id., §10-616(c)(1). As to other materials, “[t]he State Archivist may set classes of materials that the public official may destroy if the public official no longer needs the materials.” Id., §10-617(b). Section 10-615 enumerates exceptions.
Of course, especially in non-governmental organizations, solid information governance calls for defensive deletion of material such as “ROT,” redundant, obsolete, or trivial records. Materials that an entity is not required to retain, either by law or for proper functioning of the business, should be considered for destruction.
UPDATE: L. Kress & T. Trifon, Spoliation: When the Duty to Preserve Data Outweighs the Obligation to Delete | Locke Lord LLP – JDSupra (Aug. 8, 2024)(“Several state privacy laws also impose a data minimization requirement, including California, Colorado, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, and Virginia. These states all require companies to ensure that the collection, use, retention, and sharing of consumer personal information is necessary and proportionate to the purpose for which the information is collected and stored. Companies subject to data minimization requirements must ensure that their legal holds are sufficiently tailored to avoid unnecessary retention of consumer personal information.”).
UPDATE: Maryland’s New Approach to Data Minimization Creates Unique Compliance Issues | Cozen O’Connor – JDSupra (Aug. 27, 2024).