Free guide · Francisco Arrieta · 6 min

Work out which of your data outlives its own encryption

Sort what you hold by how long it has to stay private, then trace one item to every copy of it you forgot about

Pick the most confidential thing you hold. Without going to look, how many copies of it exist? Most people say one or two. Most people are out by a factor of five.

The reason this matters more than it used to is that confidentiality now has a clock on it. Anything encrypted and copied today can be stored by whoever copied it, and read later when the method protecting it stops being hard. So the question isn’t whether a document is protected. It’s how long it has to stay protected, and how many places you’d have to protect.

Those two numbers are the whole exercise. One of them is written in a contract you’ve already signed. The other one, almost nobody knows.

This is the counting half. Guide 23 is the doing half, encrypting the things that need to survive. Do this one first, because it tells you what to point that one at.

Before you start

Half an hour, a text file, and honesty. No tools.

The output is a number and a short list. If you end up with a spreadsheet and a colour scheme, you’ve done a different exercise and got the comfortable version of this instead of the useful one.


Step 1

Pick one document, the worst one

Not a category. One file.

The one where, if it turned up somewhere public in 2040, you’d have a genuine problem: a legal one, a client one, or a personal one for somebody who trusted you with it. Client records, a due diligence pack, medical or legal material you’re holding for someone, the schedule with the numbers in it.

One document. The instinct is to do all of them and the result of that instinct is that nobody does any of them.


Step 2

Find the date it stops mattering

This isn’t a judgement call. It’s usually written down.

Open the agreement that covers it. Confidentiality clauses have durations: a number of years after termination, or the life of the relationship, or perpetual for anything defined as a trade secret. Find that clause and write down what it actually says.

Three things you might find, and they’re different:

A number of years.
Fine. That’s your horizon, and it’s probably longer than you assumed.
Perpetual.
Common for trade secrets, and it means there’s no date at which this becomes safe to leak.
Nothing.
No clause, or you can’t find the agreement. That’s its own answer and it’s worth knowing before somebody else asks.

Step 3

Trace every copy, and be thorough about it

This is the work, and it’s the part that makes the guide worth doing.

Go and find every place that document exists. Not where it should be. Where it is.

  • The email it arrived in, and the one you forwarded
  • Your backup, and the backup’s older versions
  • The shared drive, and anybody’s personal folder it got dragged into
  • The laptop it was opened on, including the one you replaced
  • The chat thread where somebody asked for it
  • The phone with the mail app on it
  • Anything you pasted it into: a document tool, a note, an AI assistant

That last one catches people. A confidential document pasted into a chat window to be summarized is a copy, sitting on somebody else’s system, under their retention policy rather than yours.

Write down every location. Don’t tidy the list.


Step 4

Write the number down

Count them.

The number is the thing to sit with, because it’s your actual exposure. Whatever you do about encryption afterwards applies to the copies you know about, and this is now the list of copies you know about.

Compare it to the guess you made before step 1. That gap is why this exercise exists. It isn’t a failure of tidiness. Documents copy themselves as a side effect of ordinary work, and nobody is tracking it because tracking it isn’t anybody’s job.


Step 5

Decide what stays

Now the boundary, and it’s one decision per location.

For each copy: does this need to exist? Most don’t. A forwarded email from two years ago and a version on a laptop you don’t use are not serving anyone.

Keep the copies with a reason. Delete the rest. The ones that stay are what you’ll encrypt properly, and a short list is the difference between doing that and not.

Note the horizon from step 2 next to the survivors, so the next person to look at this knows what they’re holding and until when.


Step 6

Check that one deletion actually happened

Don’t finish on the assumption. Pick one thing you just deleted and go and see whether it’s gone.

Look in the email trash, which usually keeps things for thirty days. Look at your backup, which almost certainly still has it, because that’s precisely what a backup is for. Look in the shared drive’s version history or its own trash.

You will usually find at least one of them still there. That’s not a mistake you made. Deletion in most systems means removed from view and scheduled, and the schedule is theirs, not yours. Knowing which of your systems work that way is worth more than the deletion itself.


A boundary worth knowing about

This is a snapshot, and it starts going stale the moment you finish.

The same document gets emailed again next quarter, and the count is wrong again. That’s not an argument against doing it. It’s an argument for doing it on one document at a time, occasionally, rather than trying to build a permanent inventory that nobody maintains and everybody trusts.

The other edge: copies you find are the copies you can reach. A file sent to a client three years ago is on their systems now, under their retention and their security. You can note that it exists. You can’t do anything else about it, and pretending otherwise is the part of this exercise that would make it dishonest.


If you have staff

Do it once, together, on a real document. The number at the end does more than a policy will. People who have watched a single contract turn up in nine places stop asking why the rules exist.

Then make one rule, not a framework. Something like: confidential client material lives in one named place, and if you need it somewhere else you link rather than copy. One rule people follow beats a policy people acknowledge.


The short version

  1. Pick one document, the worst one. Not a category
  2. Read its confidentiality clause and write down the actual duration, including perpetual
  3. Find every copy: email, backups, drives, old laptops, chat, phones, anything you pasted it into
  4. Count them, and compare it to the number you’d have guessed
  5. Delete the copies with no reason to exist, and note the horizon next to the ones that stay
  6. Check one deletion actually happened. Check the backup and the email trash

Sources

Written August 2026. This one is method rather than tooling, so there is little to date. The clause in your own agreement is the only reference that matters, and it is the one nobody reads.

Prints to PDF from your browser — colours and all.