Customer attachments remain after the support case is closed
Closing a ticket changes a workflow state, not a retention justification. Build a disposition register: for each file category record why it was collected, where copies actually live and whether a current purpose remains. The UK ICO's storage-limitation guidance ties retention to a justified purpose that is reviewed, and notes that offline storage is not erasure; it sets no universal period. Where a verified legal, tax or contractual hold exists, preserve through authorized review; otherwise record an authorized deletion or restricted-retention decision per category. Feed the result back into intake so the same files stop accumulating.
For: An authorized support lead or owner at a research-only merchant deciding what happens to customer attachments after the cases they arrived with are closed.
List the attachment categories your support channel actually receives, then map where each category ends up: the ticket system, staff mailboxes, local downloads, shared drives and any exports or reports that embedded them. Backups and archives belong on the map as items for their system owner to assess, not as copies you can personally clear.
Assume duplicates until shown otherwise. A file attached to a ticket often also exists in the notification email, in the sender's outbox and on someone's desktop. Closing the case changes none of these locations, which is why case closure cannot double as a retention decision.
Record the original purpose for each category
For each category, write down why the business requested or accepted the file: to see a checkout error, to verify an order question, to read a document the customer chose to send. The purpose is the anchor for every later decision, because retention that cannot be traced to a purpose is retention by habit.
Where the original purpose is unclear, mark the category unresolved rather than inventing a justification. That unresolved mark is itself useful: it usually identifies a prompt or saved reply that asks customers for material the business never defined a need for, which is an intake problem to fix.
Decide continuing need per category
The UK ICO's storage-limitation guidance frames retention as keeping personal information no longer than necessary, justified by purpose and reviewed, and it notes that moving data to offline storage is not erasure. The guidance is UK-specific and under review, and it sets no universal period; its value here is the discipline of asking whether a current purpose exists for each category.
Give each category one of three decisions: delete because the purpose is spent, restrict and retain with a stated reason and an owner, or unresolved pending a named question. Just-in-case is not a reason, and a blanket keep-everything rule is a decision to accumulate risk without a purpose.
Check holds before deleting
Before any deletion, confirm whether a verified legal, tax or contractual hold covers the category. Verified means a named person confirmed it against the actual obligation; a vague sense that records should be kept is not a hold, and a hold is not a reason to retain categories it does not cover. Jurisdiction-specific retention questions go to qualified review.
Files under a verified hold are preserved through the authorized process with access restricted appropriately. Files outside any hold and without a continuing purpose move to deletion. Both directions need the same care, because deleting under a hold and retaining without need are both failures of the register.
Execute, document and prevent recurrence
Record the execution for each location: date, method and who confirmed it. Clearing the ticket copy while the mailbox copy and a downloaded file remain is not disposition. Where a location cannot be cleared, such as a backup cycle, record the owner's stated handling instead of claiming completion.
Close the loop at intake: adjust the support prompts and saved replies so categories with no defined purpose stop being requested. For a Prism consultation about the public wording around what you ask customers to send, describe the website, the research-only catalog and the prompt at issue, without attachments or customer content in the public form; scope, responsibilities, fees and terms are agreed before work.
Attachment disposition register
Complete one register per support channel, with one line per file category. Record decisions and executions, never attachment contents. A category without a defined purpose or a confirmed hold check stays unresolved. The final column is left for your dated record and owner.
Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.
Attachment disposition register. The last column is for temporary notes.
Register item
What to record and the decision it supports
Your record
File category
What to record and the decision it supportsType of attachment and the cases it covers. Groups files so a decision applies to a category, not one memorable file.
Original purpose
What to record and the decision it supportsWhy the business requested or accepted the file. Retention must trace to a purpose; an unclear purpose stays unresolved.
Locations and duplicates
What to record and the decision it supportsTicket system, mailbox, downloads, shared storage and exports. Closing a case changes none of these; each needs its own disposition.
Continuing need
What to record and the decision it supportsThe current operational reason, if any, to keep the category. Separates a live need from retention by habit.
Hold check
What to record and the decision it supportsAny verified legal, tax or contractual hold and who confirmed it. Files under a verified hold are preserved through authorized review, not deleted or assumed.
Disposition decision
What to record and the decision it supportsDelete, restrict and retain, or unresolved, with the approver. Makes the decision explicit and owned rather than implied by case closure.
Execution record
What to record and the decision it supportsDate, method and locations actually cleared or restricted. Offline storage is not erasure; record what happened where.
Intake correction
What to record and the decision it supportsChange to what the support channel requests going forward. Stops the same files accumulating again.
These are temporary notes. Leaving or reloading this page may clear them. Worksheet entries are not sent automatically. If you copy notes into the consultation message and submit the form, Prism receives them as part of your request.
Limits
ICO storage-limitation guidance is UK-focused and under review; it supplies a principle, not a retention schedule for your business.
No universal retention period is stated here; legal, tax and contractual holds need qualified verification before deletion.
Deleting one copy is not disposition; duplicates in mailboxes, exports and backups need owner-confirmed handling.
Keep attachment contents and customer identifiers out of the register and the public consultation form.
ICO: Storage limitation — checked 2026-10-01. The ICO states personal information should be kept no longer than necessary, with retention justified by purpose and reviewed, and that offline storage is not erasure; the guidance is UK-specific and sets no universal period.
Prism contact — checked 2026-09-21. The inquiry asks for the website, products and question, excluding payment card details, passwords and customer records; follow-up is by email and the request is not an appointment, purchase or processing application.