How Long Should You Keep Security Patrol Records?
How long to keep security patrol records: practical retention tiers, spoliation risk, and defensible deletion. Get the operator's retention guide.
There's no single statute that answers this for patrol logs, so retention is a risk decision. A common working framework: keep everything readily accessible for 12–24 months of active operations, keep site records for the contract term plus two years, keep incident-linked records substantially longer, and let a legal hold override everything. Digital storage is cheap; missing records in a lawsuit are not.
"How long do we keep this stuff?" is one of the most common operational questions I get from other guard company owners — and one of the most consequential, because the record you shred in year two is the record a plaintiff's attorney demands in year three. Here's the framework we use across Ranger Guard's four markets — Houston, Corpus Christi, Las Vegas, and Florida — stated as practice, not law.
Why does the security report retention period matter so much?
Two forces pull in opposite directions.
Claims surface late. Premises-liability and injury claims commonly appear one to four years after the incident, because personal-injury statutes of limitation typically run two to four years depending on the state — and can extend further for minors or late-discovered injuries. Wage-and-hour claims under the FLSA commonly reach back two to three years of timekeeping. The DAR that proves your officer completed all patrol rounds the night of an assault is worthless if it was purged eighteen months in. This is the same math behind "the guard wasn't there" disputes: the side with records wins.
Keeping everything forever has costs too. Old records are discoverable — every stale log is something you may have to search, produce, and explain. Privacy laws like CCPA/CPRA push toward retention limits on personal data (see our data privacy guide). And unmanaged archives rot: media on ex-supervisors' phones, spreadsheets on dead laptops, paper binders at closed sites.
So the answer isn't "keep everything" or "purge aggressively" — it's a written schedule with tiers.
What does a practical patrol record retention schedule look like?
Here's a working structure many operators converge on. Treat it as a starting point to adapt with counsel:
| Tier | Records | Common practice | Why |
|---|---|---|---|
| Active operations | DARs, patrol/checkpoint logs, GPS clock-ins, schedules | 12–24 months readily accessible | Client questions, invoice disputes, QA, and pattern analysis all draw on the recent window |
| Site/contract records | All records for a client site | Contract term + 2 years | Most claims tied to a site surface within the limitation period after service ends |
| Incident-linked | Reports, media, GPS, schedules, and communications tied to any incident | Substantially longer — commonly 4–7 years, longer for injuries to minors | Statutes of limitation, insurer requirements, and the long tail of litigation |
| Employment/payroll | Timekeeping, schedules, personnel files | Per FLSA/state rules — commonly 3+ years for payroll, 2+ for timecards | Wage-and-hour exposure; state guard-licensing rules (Texas DPS Private Security, Florida Chapter 493) may add requirements |
| Legal hold | Anything covered by a hold | Until released in writing | A hold overrides every tier — see the legal hold guide |
Two rules make the tiers work. First, incident-linked beats routine: the moment a record connects to an incident, it inherits the longer clock. Second, the hold trumps all: no schedule ever justifies deleting held records.
What's the storage cost vs. risk math?
This used to be a real tradeoff. In the paper era, seven years of DARs for a mid-size company meant rooms of banker's boxes. Digitally, it's a rounding error: commodity cloud storage commonly runs on the order of a few cents per gigabyte per month, and even a busy operation's reports, logs, and GPS data measure in gigabytes, not petabytes. For perspective, over a year of SNTNL running Ranger Guard's full daily operations — 400+ employees, every report, photo, scan, and GPS ping — totals 150+ GB. The storage cost of keeping that entire history is trivially small next to a single day of legal fees in a negligent-security case.
So for digital records, the honest math is lopsided: the marginal cost of longer retention is near zero, while the cost of a missing record can be case-deciding. The place to be disciplined isn't patrol logs — it's high-volume personal data (visitor IDs, continuous video) where privacy exposure genuinely grows with age. Watch the vendor angle too: some guard-software pricing effectively meters your history through storage caps or paid archive access, and per user reviews on Capterra as of mid-2026, getting historical data out of legacy platforms at contract end is a recurring pain point. SNTNL's answer is structural — free data export always, so your history is never hostage to a subscription. That matters most in exactly the scenario covered in our switching-at-renewal playbook.
How do you delete records defensibly?
Deletion isn't the risky part — undocumented, inconsistent deletion is. Courts accept that businesses dispose of records; what draws sanctions is disposal that looks selective or continues after a duty to preserve arose. Defensible disposal looks like:
- A written retention policy with the tiers above, approved by management and reviewed with counsel.
- Consistent execution — deletion runs on schedule for everything in a tier, not ad hoc when someone "cleans up." Automation helps here: a platform schedule applies uniformly; a supervisor with a delete key doesn't.
- A hold check before every purge — nothing under legal hold or connected to a known incident, claim, or investigation gets touched.
- A disposal log — what category was deleted, when, under which policy provision. You want to testify "records were destroyed per our standard schedule, documented here," not "someone must have deleted them."
- Coverage of shadow copies — the policy means little if originals purge on schedule while copies live on in text threads and personal phones. Centralized capture, the heart of proof of service, is what makes a retention policy actually true.
If your retention "policy" is currently whatever your old software purges by default, it's worth an hour to fix. Book a demo and I'll show you how Ranger Guard keeps its full operational history organized, holdable, and exportable — without anyone managing banker's boxes.
This is general information, not legal advice — verify current requirements with your attorney.
Keep reading
What Do You Do When a Client Says Your Security Guard Was Not On Site?
A client says your security guard was not on site. Here's the first-hour triage, the attendance evidence hiera…
How Does GPS Clock In for Security Guards Actually Stop Off-Site Punches?
How GPS clock in for security guards works, how to set geofence radius, and how to stop guards clocking in fro…
QR Code vs NFC vs GPS Guard Checkpoints: Which Should You Actually Use?
QR code vs NFC vs GPS guard checkpoints: cost, fraud resistance, and where each fails. Get the honest comparis…