Data Retention Requirements After You Cancel

Payroll records kept somewhere other than the worksite have to be produced within 72 hours of federal notice. Not 72 hours plus however long a former vendor takes to answer a support ticket.

That number is not a rule of thumb. 29 CFR 516.7 requires an employer to keep records "safe and accessible at the place or places of employment, or at one or more established central recordkeeping offices where such records are customarily maintained." Where they sit in a central office rather than the workplace, "such records shall be made available within 72 hours following notice from the Administrator or a duly authorized and designated representative" (eCFR, read 19 August 2026).

A cancelled SaaS account is a central recordkeeping office that has stopped taking your calls.

The clock the cancellation does not touch

Retention periods attach to records. Not to subscriptions, not to the tool the records happened to be created in, and not to the calendar year you decided to switch.

The IRS page on how long to keep records lists the ordinary case as 3 years, then the exceptions that stretch it: 7 years "if you file a claim for a loss from worthless securities or bad debt deduction," 6 years "if you do not report income that you should report, and it is more than 25% of the gross income shown on your return," and indefinitely if you did not file a return at all. Employment tax records get their own line, "at least 4 years after the date that the tax becomes due or is paid, whichever is later" (IRS, page last reviewed 30 June 2026).

Employment law adds its own layers, on different clocks, counted from different events:

Source Period Counted from
29 CFR 516.5 3 years Last date of entry for payroll records; last effective date for the certificates, agreements and plans listed there
29 CFR 516.6 2 years Last date of entry for time and earning cards and for customer orders, invoices and billing records; last effective date for wage rate tables
29 CFR 1602.14 1 year Making of the record or the personnel action, whichever is later; one year from termination in an involuntary termination
29 CFR 1602.14 Until final disposition Where a charge or action has been filed under Title VII, the ADA or GINA, "all personnel records relevant to the charge or action"

Part 516 rides on the Fair Labor Standards Act and Part 1602 on Title VII, the ADA and GINA, so coverage decides which of them reaches a given employer. Where the second one does reach you, that last row ignores every plan you have made. A charge freezes the relevant personnel records until final disposition, which 1602.14 defines as the expiry of the window in which the aggrieved person could sue, or the end of the litigation if an action was brought. Neither the charge nor the regulation cares that your HR tool was decommissioned two quarters earlier.

Worth reading twice, from the IRS page: "When your records are no longer needed for tax purposes, do not discard them until you check to see if you have to keep them longer for other purposes." Insurers, lenders, franchisors and grant programmes keep their own clocks, and yours are written into agreements you signed rather than into any regulation. Which of these apply to your entity, your state and your industry is a question for your accountant or attorney. This page is only about the fact that the obligations outlive the cancellation, and about getting files out while that is still possible.

A report is not the record

Here is where most exit plans go wrong. They treat "we exported everything to CSV" as the end of the retention question, when an export is a rendering of the records rather than the records.

The IRS FAQ on electronic accounting software records is unusually direct about this. It says the IRS "will request electronic accounting software backup files using Form 4564, Information Document Request (IDR), early in the examination," and that it "will also request the administrator's username and password, as they are needed to read most data files." Asked why a backup file rather than exported reports, the same page answers: "The backup file is an exact copy of the original books of entry and allows the IRS to review and test the integrity of the original electronic records using the software program. This testing cannot adequately be performed on records that have already been converted into Excel spreadsheets."

On the tempting shortcut of rebuilding the old year inside the new system, it is blunter still. A file created by re-inputting transactions "does not satisfy the requirements or needs of the Internal Revenue Service. The new or modified company file is not a copy of the books and records of original entry" (IRS, page last reviewed 3 July 2026).

Two consequences for anyone mid-switch. Capture the native file as well as the readable export, because they answer different questions and only one of them stays obtainable after the account closes. And check the span: the same FAQ says examiners may request a backup covering "the month prior to and the month after the tax year under examination, thus a fourteen (14) month period." A December cutover that exported only the calendar year is short at both ends.

The governing principle sits on the IRS recordkeeping page in one sentence: "All requirements that apply to hard copy books and records also apply to electronic records" (IRS, page last reviewed 3 August 2026).

What the vendor keeps, and for how long, is not what you assume

Every plan that rests on "we can always log back in" comes apart on some phrase in a help article nobody read.

Xero's cancellation page states that a paid subscription carries a one-month cancellation notice period "during which you're still billed," that after the notice period "we'll archive your organization's data to comply with record-keeping requirements," and, removing the obvious workaround, "We don't have a read-only plan." Reaching an archived organisation means reactivating: "You can reactivate your subscription at any time within our data retention period," a period Xero says "varies depending on your region" rather than naming a number. Reactivating to look at one invoice puts you back in the queue on the way out, because "the one-month notice period still applies." One more line belongs on the wall of anyone running payroll: "To access data related to features such as projects, payroll or expenses, you need to purchase a subscription with that feature" (Xero Central, checked 19 August 2026).

Set that against the 72-hour rule at the top of this page. The arithmetic stops working.

The tighter clocks are the ones nobody budgets for at all:

  • A departing employee's mailbox. Google's admin documentation says data owned solely by the user and not transferred before deletion "is permanently deleted," with "some data" retained "for 20 days, during which time you can restore the deleted user," and Drive files "saved for 20 days but are only accessible if you restore the user" (Google Workspace Admin Help, checked 19 August 2026). Twenty days is shorter than most notice periods, and offboarding usually runs on a different calendar from the migration.
  • The file sync you were treating as the archive. Dropbox's retention article, updated 16 October 2025 and checked 19 August 2026, gives recovery periods by plan: 30 days on Basic, Plus and Family; 180 days on Professional, Standard, Essentials and team; 365 days on Advanced, Enterprise, Education and team Plus (Dropbox Help Center). Deleted is recoverable for a while, then it is not.

Message history on a free plan is the third of these, and it expires without anybody cancelling anything. Slack states that on the free version you are "limited to the most recent 90 days of message and file history" and that "all data in your workspace that's more than one year old will be deleted," a rolling deletion the same page dates from 26 August 2024 (Slack help centre, checked 19 August 2026). Which parts of that you can still get into a ZIP is the subject of what a Slack export actually contains. The short version: retention sets the ceiling before the export button does anything.

Building the list before the account closes

Work from obligations down to files, not from apps outward. An app-by-app sweep produces a folder of exports and no idea what is missing. An obligation-first sweep tells you when to stop.

  1. Write the obligation, then name the artifact. "Payroll records, 3 years, 29 CFR 516.5" becomes "pay runs 2023 to 2026 as PDF payslips, plus the payroll register CSV, plus the native backup." One line per obligation. A line you cannot name a file for is the finding.
  2. Sort by who holds it. Anything held by the vendor you are leaving goes to the top. Anything held by a bank, a payroll bureau or your accountant can usually be re-obtained later and can wait.
  3. Take a native format and a readable format. The backup file for the examiner, the PDF or CSV for whoever opens it in 2029. Neither substitutes for the other.
  4. Test the edges. Pull one record from your first month on the system and one from the last, and confirm both open. Truncated exports fail quietly, and they fail at the ends.
  5. Capture the things that are not records but explain them. Chart of accounts, tax rate settings, the user list with roles, the field mapping notes from the migration. Six months on, a ledger without its chart of accounts is a column of numbers.
  6. Only then touch billing, in the order set out in the 30-day switch runbook.

If an obligation cannot be met from files you already hold, the remaining lever is buying time rather than buying access back later. One seat on the cheapest tier for a few more months usually costs less than a reactivation plus a fresh notice period plus the feature-specific plan you will be told you need, and the seat maths behind that comparison is in why your SaaS bill is higher than the pricing page says. Decide it deliberately, with the list in front of you, rather than in the fortnight after somebody asks for a document.

Where the documentation stops

Three things this page could not settle against a primary source, and which should not be taken from it as settled:

Xero's actual retention period. The cancellation article points to a retention period that "varies depending on your region" without giving a figure, and links out to a policy page rather than stating one. Third-party posts confidently quote seven years. The vendor's own article does not, so neither will this one. If the number matters to your plan, get it in writing for your region before you rely on it.

Intuit's current wording. The QuickBooks Online help article on cancelling a subscription did not load on 19 August 2026 — three attempts across the day, the last of which returned ERR_HTTP2_PROTOCOL_ERROR rather than a page. Widely repeated summaries say read-only access for a year after cancelling. That may well be right. It is not stated as verified here, because the page could not be opened to check the wording.

Everything outside US federal rules. State retention schedules, industry-specific regimes, non-US requirements, and how any of it applies to your entity are past what a procedure page can answer. The claim here is narrower: the obligations do not pause because you changed vendors, and the window in which you can still satisfy them cheaply closes on the vendor's schedule rather than yours.


Verified against Xero, Google Workspace, Dropbox and Slack documentation on 19 August 2026, and against IRS and eCFR sources the same day. Regulation text came from the eCFR for 29 CFR Part 516 and 29 CFR Part 1602; IRS wording from How long should I keep records?, What kind of records should I keep? and the electronic accounting software records FAQ. The vendors named above appear because they publish their cancellation and retention terms in their own words, which is what makes those terms quotable — not because any one of them is better or worse to leave than the rest. Regulations get amended between issues, and a help article can be rewritten the week after it is quoted, so the sentence in quotation marks is the claim and the date beside it is its shelf life. Where one has drifted, the contact page reaches me, and the page gets re-read against the source and re-dated rather than quietly patched.

Frequently asked questions

How long do I have to keep business records after switching accounting software?

The switch is irrelevant to the clock. The IRS page on how long to keep records says to keep records for 3 years in the ordinary case, 6 years if you do not report income you should report and it is more than 25% of the gross income shown on the return, 7 years for a worthless securities or bad debt claim, indefinitely if no return was filed, and employment tax records for at least 4 years after the tax becomes due or is paid, whichever is later. Separately, 29 CFR 516.5 requires employers to preserve payroll records for at least 3 years. Those periods attach to the records, not to the software they happen to live in, and the IRS adds that when records are no longer needed for tax purposes you should check whether something else requires you to keep them longer. Retention rules for your state, entity type and industry are a question for your accountant or attorney, not for a vendor help page.

Does an Excel or CSV export count as keeping the records?

Sometimes, but not as a substitute for the original data file if your books were kept in accounting software. The IRS FAQ on electronic accounting software records says examiners request the software backup file using Form 4564, and explains why: the backup file is an exact copy of the original books of entry, and integrity testing cannot adequately be performed on records that have already been converted into Excel spreadsheets. The same page says a file re-created by re-inputting transactions does not satisfy the requirement, because it is not a copy of the books and records of original entry. Capture the native backup as well as the readable export, and do it while the subscription is live.

Can I just reactivate the old subscription if someone asks for the records?

Only if the vendor still holds the data, and only at the price and speed of a new subscription. Xero's cancellation article says data is archived after the one-month notice period, that there is no read-only plan, and that reactivating is the way to reach an archived organisation, with the one-month notice period applying again on the way back out. It also says features such as payroll are reachable only if you buy a subscription that includes that feature. Checked 19 August 2026. That is a purchase and a wait, set against 29 CFR 516.7, which requires records held at a central recordkeeping office to be made available within 72 hours of notice from the Administrator.

What about records that live in one employee's mailbox?

Those are the most fragile items on the list, and they vanish on a shorter clock than the subscription does. Google's admin documentation on deleting a user says data owned solely by the user and not transferred before the account is deleted is permanently deleted, with some data retained for 20 days during which the deleted user can be restored, and Drive files saved for that window but reachable only by restoring the user. Checked 19 August 2026. Signed contracts, supplier invoices and payroll approvals sitting in one person's mail are records for retention purposes even though nobody filed them anywhere.