Audit hits next quarter and IT asked me to set enterprise retention and access rules for [documents=customer contracts…
Sign in to the Adobe Acrobat Sign web application as an account administrator.
Navigate to the admin settings by selecting the account menu and choosing the option for account or admin settings.
Locate and select the section for data governance or retention policies.
Choose to create a new retention rule or edit an existing rule.
Specify the retention period by entering the number of days, months, or years that completed agreements and associated data should be retained before deletion.
CautionRetention policies only apply after an agreement reaches a terminal state, such as completed, canceled, or expired.
Define the scope of the rule, such as which agreement types, users, or groups it applies to.
Save or activate the retention rule to enforce the new policy.
Review the list of retention rules to confirm the new or updated rule is active and correctly configured.
Best practiceRegularly review retention rules to ensure compliance with changing organizational or regulatory requirements.
Retention policies are managed in the admin section and take effect automatically for agreements that reach a terminal state.
Retention policies can also be managed via the Acrobat Sign REST API using the /retentionPolicies endpoints.
A reusable policy set in Adobe Acrobat is a collection of security rules, like password or certificate protection, that you can apply to many documents. It matters because it saves time and ensures all documents follow the same security standards. This helps keep your information safe and makes sure you meet compliance rules like HIPAA or ISO 27001 without having to set rules for each document separately.
Adobe Acrobat supports Microsoft Purview Information Protection (MPIP). This means that retention policies you set in MPIP can also apply to your PDF documents in Acrobat. It helps create a single system for managing how long documents are kept across different applications. This integration makes it easier to enforce consistent data governance and compliance rules for all your files.
Applying retention policies at a document's 'terminal state' is important because it ensures the document is complete and no longer being changed. This prevents accidental deletion of active work and ensures that the final, approved version is the one that follows the retention rules. It helps maintain data integrity and compliance.
| Feature | General Acrobat Documents | Acrobat Sign Data Governance |
|---|---|---|
| Scope | Applies to PDFs and other documents managed within Acrobat. | Specifically for agreements, audit trails, and data within Acrobat Sign. |
| Admin Access | Set by account/group-level admin in Acrobat's enterprise policy settings. | Configured in Acrobat Sign's dedicated data governance settings. |
| Purpose | Controls how long general document files are stored or deleted. | Manages retention for legally binding e-signatures and related data. |
| Compliance Focus | Broad compliance (PCI DSS, HIPAA, SOC 2, ISO 27001). | Focus on e-signature regulations and legal requirements for agreements. |