How long should you keep client files?
Long enough to do the job and meet your obligations, and no longer. For most creative and professional work that lands somewhere between one and three years after a project closes — but the specific number matters much less than having chosen one, written it down, and having something that actually deletes files when it arrives.
Retention is usually treated as a storage question. It is a risk question. Every file you hold containing other people's information is a liability you are carrying, and most people are carrying far more than they realise.
Both directions have real costs
Too short and you cannot re-deliver when a client comes back, you have no evidence if work is disputed, and you re-upload things at your own expense. The archetype is the expired link and a client who needs the file today.
Too long and you are holding personal data with no current purpose. Under the GDPR, storage limitation is a principle in its own right: personal data must not be kept longer than necessary. Eight years of client shoots on a drive, with no policy, is not thrift. It is a large breach waiting for a lost laptop, with a lot of data subjects in it.
The second failure is more common and much less visible, because nothing ever goes wrong until it goes very wrong.
How to pick a period
Four inputs, in order:
Legal and tax requirements. Invoices and financial records have statutory retention periods in most countries — commonly around seven years. Note that this applies to the records, not usually to the files. You need the invoice for the wedding, not 40 GB of RAW.
Contractual obligations. Read what you signed. Some client contracts require deletion at the end of an engagement; others require retention for a fixed period. Both exist and they pull in opposite directions.
Professional need. How often do clients genuinely come back? For wedding photography, years. For a social media campaign, weeks. Use your actual experience rather than an anxious guess.
Liability window. How long could a dispute realistically arise? This is often what argues for keeping deliverables longer than feels necessary.
Then write one sentence. For example: "Client deliverables are kept for two years after project completion. Working files and RAW originals are deleted six months after final delivery. Financial records are kept seven years."
That is a retention policy. It does not need to be longer than that.
Separate the categories
The single most useful move is to stop treating "client files" as one thing:
Deliverables — the finished work. Keep these longest. They are small relative to everything else and they are what clients come back for.
Working files — RAW, project files, unused takes. Enormous, rarely needed after sign-off, and the bulk of both your storage cost and your exposure. This is where aggressive deletion pays.
Personal data specifically — anything identifying people, including photographs of them. Governed by law rather than convenience.
Financial records — invoices, contracts. Statutory periods, small files. Keep them and stop thinking about it.
Applying one period to all four is how people end up either deleting something they needed or hoarding everything.
Make something actually delete
A policy nobody executes is worse than no policy, because it creates a written expectation you are visibly failing.
Use a service that expires things for the categories where that fits, so deletion is the default rather than a chore.
Put a recurring reminder in the calendar for the categories that need judgement. Twice a year is enough.
Delete on a schedule, not on a feeling. "I'll clear that out when I need the space" is how eight years accumulate.
Check your backups. Deleting the working copy while three years of backups retain everything is the most common way a retention policy achieves nothing. Ask your provider how long deleted data persists in backups.
Tell clients
Two sentences in your terms and in your delivery email:
"Your files stay available until [date]. Working files are deleted six months after delivery — tell us if you need them kept longer."
This does three things at once: it prevents the surprised email in year two, it makes deletion a stated policy rather than something that looks like carelessness, and it gives the client a chance to ask for an exception before it matters.
The compliance framing
If you handle personal data on a client's behalf, you are their processor and retention is one of the things a processing agreement should specify. What that agreement needs to contain. For special-category data — health, biometrics, anything about someone's private life — the argument for short retention is much stronger, and the obligations are sharper.
Note the pleasant coincidence: the compliant answer and the cheap answer are usually the same one. Data you deleted cannot leak, does not need to be secured, and costs nothing to store. It is also the largest environmental lever you actually control, which is a smaller reason but a real one.
If your service decides for you
Most free transfer tiers delete within 7 to 15 days. That is a defensible outcome arrived at accidentally — good for minimisation, bad if you needed the file.
The question is not whether the period is right. It is whether you chose it. If a service's default is doing your retention thinking, you have no policy; you have a coincidence. Services differ substantially on what you can control, and it is worth picking one whose defaults match a decision you actually made.