Our archive access has been debated in three audits. Propose an archival retention and access model for study reports …
Review all applicable regulatory, legal, and industry retention requirements for your organization's documents and agreements.
CautionRetention policies must address legal, regulatory, and business requirements, not just privacy.
Map document types and workflows in Acrobat Sign to the identified compliance requirements.
Log in to the Adobe Acrobat Sign Admin Console with administrator privileges.
Navigate to the retention policy configuration area for your Acrobat Sign account.
Define retention rules at the group level to support different business units or compliance needs.
Best practiceGroup-level rules allow you to align retention with department-specific or jurisdictional requirements.
Set the retention period for each group or document type, specifying the number of years or months documents must be retained after reaching a terminal state (completed, canceled, or expired).
NoteRetention policies are enforced after agreements reach a terminal state.
Enable automatic deletion or archival of documents upon expiration of the retention period, according to your compliance strategy.
Document your retention rules and schedules in your organization's policy repository.
Communicate the retention policy and procedures to all relevant stakeholders and provide training as needed.
Best practiceClear communication and documentation help prevent accidental deletion or noncompliance.
Regularly review and update retention policies to reflect changes in regulations or business processes.
Best practicePeriodic audits ensure ongoing compliance and can reveal gaps in policy enforcement.
Retention policies in Acrobat Sign are configured in the Admin Console and applied automatically after agreements reach a terminal state.
Retention rules can be managed via the Acrobat Sign REST API using the /accounts/{accountId}/retentionPolicies endpoint.
A reusable policy set is a collection of security rules, like password protection or certificate requirements, that you can apply to many documents at once. It matters because it saves time and ensures consistent protection across all your important files. Instead of setting security for each document, you create one set of rules and apply it easily.
Acrobat's Security Policies help by letting administrators define specific retention periods for documents, ensuring files are kept for the required timeframes. These policies can also use strong protection methods like passwords or certificates. This helps meet the data protection and retention requirements of standards like HIPAA for patient data and PCI DSS for credit card information, proving your organization handles sensitive data responsibly.
| Guide Name | Focus |
|---|---|
| Enterprise Admin Guide | General administration and setup for large organizations using Adobe products. |
| Security policies in Acrobat | Specific details on creating and using reusable security rules, including retention, within Acrobat. |
It is important to apply retention policies at the 'terminal state' because this means the document is complete and will not change anymore. This ensures that the final, official version of a document is kept for the correct amount of time, without starting the retention clock too early or too late. It helps maintain compliance and data integrity.