Skip to content
Domexa Technologies

Blog

What to Keep, and for How Long

Keeping everything forever feels safe and isn't. A retention position, meaning what you keep, why, and when it goes, is both a data protection duty and a filing system that works.

Money & records6 August 2026Editorial Team2 min read

The instinct in property is to keep everything, indefinitely, in case it is ever needed. It feels like the cautious option.

It isn't, for two reasons. Holding personal data you no longer have a reason to hold is a liability under Kenya's Data Protection Act, 2019. And an archive nobody has ever pruned is one nobody can search, which means in practice you cannot find the thing you kept it all for.

This is not legal advice. Periods vary with the record and your own obligations, and it is worth taking advice if you hold data at scale. But the shape of a workable position is straightforward.

Decide by category, not by document

Group what you hold, then set a rule for each group:

Financial records: receipts, invoices, ledgers, remittance statements. These are your evidence in any dispute and are usually subject to tax and accounting retention requirements. This is the longest-kept category, and the one where "keep it" is normally the right answer.

Tenancy records: agreements, handover inventories, meter readings, correspondence about repairs. Useful for the length of the tenancy plus a defined period after, because deposit and condition questions surface after someone has left.

Applicant records: the people who enquired, viewed, or applied and were not offered a unit. This is the category almost everybody keeps forever and almost nobody should. There is rarely a reason to hold an unsuccessful applicant's ID copy and employment details indefinitely.

Marketing contacts: anyone who asked to hear from you. Keep while the consent is live, and delete when it is withdrawn or has gone stale.

Write the periods down

An unwritten retention policy is not a policy; it is a habit that changes with whoever is doing the filing. Write one page: category, how long, and the reason. The reason column is what makes it defensible, and what makes it obvious when a period no longer makes sense.

Then actually delete

This is the step that never happens. A retention policy that is never executed is worse than none, because it documents precisely how long you said you would keep things and proves you didn't.

Put a recurring date in the calendar. Twice a year is enough for most agencies.

Don't forget the informal copies

The management system is the easy part. The hard part is the scanned IDs in a WhatsApp group, the spreadsheet on someone's personal laptop, the folder of application forms in a drawer, the email attachments in four inboxes.

Deleting the record from the system while five copies live elsewhere is filing, not deletion. See handling tenant data responsibly for how those copies accumulate in the first place.

The other half: don't lose what you should keep

Retention has a mirror. Backups that have never been restored are a belief rather than a control, and records held only on one person's device leave with that person.

Test a restore once. Most people discover something the first time they try, and it is much better to discover it on a Tuesday than in the week you actually need it.