Draft retention and naming rules that survive an audit — define retention periods by document type, add mandatory file…
Sign in to the Adobe Admin Console with your administrator account.
Navigate to the Acrobat Sign product settings for your organization.
Select the section for data governance or retention policies.
Choose the option to create or edit retention rules.
For each document type or category, define a new retention rule by specifying the document type, category, or business need.
Set the custom retention period (in days, months, or years) for each rule according to your organization's requirements.
CautionRetention periods are enforced automatically; expired documents will be deleted and cannot be recovered.
Save each retention rule and ensure it is enabled.
Review all active retention rules to confirm correct application to the intended document types.
Best practiceFor complex organizations, consider grouping similar document types under a single rule to simplify ongoing management.
Retention rules can be managed in the Admin Console under Acrobat Sign settings, allowing you to set different durations for each document category.
The Acrobat Sign REST API supports retention policy management via the /agreements and /retention endpoints for automated rule configuration.
A reusable policy set is a group of security rules, like password or certificate protection, that you can apply to many documents. It matters because it saves time and ensures all important documents follow the same security standards. This helps maintain consistent protection across your organization, making it easier to manage security and comply with regulations like ISO 27001.
If your company needs to follow HIPAA rules, Acrobat's retention feature helps by letting you set specific time limits for how long patient data is kept. This ensures sensitive information is stored for the required period and then managed correctly. The feature supports compliance with standards like HIPAA, giving you tools to meet legal and industry requirements for data governance and security.
Retention rules are managed by an administrator because they affect the entire company and ensure everyone follows the same rules. This helps maintain consistent security and compliance for all documents. If every user set their own rules, it would be hard to meet important standards like PCI DSS 3.0 or SOC 2 Type II.
| Action | Description |
|---|---|
| Design Retention Policies | This is the first step where you plan and decide the overall strategy for how long documents should be kept, based on legal or business needs. |
| Define Retention Policy | This is the next step where you put your design into action by setting the exact time periods (like 15 years) and specific rules within the system. |