Document Compliance: What GDPR, HIPAA, SOX and CCPA Expect From Your Files
Every audit of your documents comes down to four questions: what you have, who can see it, how long you keep it, and whether you can prove what happened to it. Here is how to answer each one.
Ademero Team8 min read

Most document findings in an audit come down to four questions. What do you have? Who can see it? How long do you keep it? Can you prove what happened to it? This guide maps the major rules to those four questions, gives you a retention starting point, lists the mistakes auditors find most often, and ends with a checklist you can work through in a week.
What each regulation expects from your documents
The rules differ in who they cover, but they all ask for the same four things: know it, limit it, keep it for the right time, and prove it.
| Rule | Who it covers | What it means for your documents |
|---|---|---|
| GDPR | Anyone handling personal data of people in the EU | Know where personal data sits, keep it only as long as you need it, answer access and erasure requests, and record your processing. Fines reach 20 million euros or 4% of worldwide annual turnover, whichever is higher. |
| HIPAA | Healthcare providers, health plans, clearinghouses and their business associates | Limit access to protected health information to the minimum necessary, log who opens it, keep required HIPAA policies and documentation for six years, and sign a business associate agreement (BAA) with every vendor that handles it. |
| SOX | US public companies | Keep the records behind the financial statements and the evidence that your controls ran: approvals, sign-offs and reconciliations. Auditors must keep their audit workpapers for seven years. |
| CCPA and CPRA | Businesses over California's revenue or data thresholds | Know what personal information you hold, answer consumer requests to know and delete, and keep records of those requests for at least 24 months. |
| Industry rules | Banks, broker-dealers, schools, government contractors and others | GLBA, FINRA and SEC record-keeping rules, FERPA for student records, and state privacy and records laws add their own periods and formats on top. |
Deeper guides for the most common ones: HIPAA, SOX, FERPA. GDPR and CCPA requests and breach response are covered below.
Question 1: what do you have?
Every document needs a type and a few index fields from the moment it arrives. Everything else depends on it.
Retention, permissions and search all hang off the document type. An invoice, an I-9 and a patient intake form need different rules, so they cannot sit in the same unlabelled folder. Decide your document types first, then give each one the two to five fields people search by: vendor and invoice number, employee ID, patient account number, matter number.
The cheapest place to get this right is at capture. Software that splits a scanned stack into separate documents, recognizes each type and reads its key fields means nobody has to label files by hand later. See intelligent document capture explained, and for a worked example with mixed paperwork, HR onboarding document capture.
Question 2: who can see it?
Grant access by job and document type, require a second sign-in factor, and never share logins.
- Permissions by document type. Payroll staff see payroll records; AP sees invoices. View, edit, download and delete are separate rights.
- Access by field value. A branch manager sees only their branch, a case worker only their cases.
- Strong sign-in. Single sign-on through your directory, plus multi-factor authentication for everyone.
- A reason for sensitive access. For the most sensitive records, ask people to state why they are opening a file and keep the answer.
- Safe sharing. Never email regulated files as plain attachments; use encrypted, expiring shares.
- Private by default. New document types start with the narrowest access, and you widen it on purpose. Before launching anything new that handles personal data, run a privacy impact assessment.
Question 3: how long do you keep it?
Set a retention period per document type, destroy on schedule, and suspend destruction for anything under legal hold.
These common US periods are a starting point. Confirm the right periods for your organization, state and industry with your counsel.
| Record | Common retention | Driven by |
|---|---|---|
| Records supporting a tax return | 3 years in general, longer in some cases | IRS |
| AP invoices and supporting documents | Often 7 years | Tax and audit practice |
| Payroll records | At least 3 years | FLSA |
| Form I-9 | 3 years after hire or 1 year after employment ends, whichever is later | USCIS |
| HIPAA policies and required documentation | 6 years | HIPAA |
| Patient medical records | Set by state law, often longer | State law |
| Contracts | Life of the contract plus the limitation period | State law |
| Consumer privacy request records | At least 24 months | CCPA regulations |
For a longer list, see retention schedules by record type, and draft your own policy with the free retention policy generator.
A legal hold overrides the schedule. When litigation, an investigation or an audit is reasonably expected, the relevant documents must be kept until the hold is lifted, even if their retention period ends. Your system needs a way to mark documents as kept indefinitely and to show who placed and released the hold.
Question 4: can you prove what happened?
Keep an audit trail of who viewed, changed, approved, shared and deleted each document, and a version history for each file.
- Activity log: sign-ins, searches, views, downloads, edits, emails and deletions, with user and time.
- Version history: every change to the file or its fields, with earlier versions still available.
- Approval evidence: who approved, when, and with what note. For SOX, this is the proof that a control ran. Routing approvals through a workflow records it automatically; see document workflow automation.
- Disposal records: what was destroyed, under which schedule, and when.
- Long-term format: for records you must keep for years, PDF/A is the archival format. See searchable PDF vs PDF/A.
When personal data is exposed
Contain it, assess it with the audit trail, notify within the legal deadline, and fix the cause.
- Contain: remove the share, disable the account, recall what you can.
- Assess: use the activity log to see exactly which documents and whose data were exposed, and to whom.
- Notify: under GDPR, the supervisory authority generally must be told within 72 hours of becoming aware of a breach, and affected people without undue delay when the risk to them is high. HIPAA allows up to 60 days for individual notice. US state breach laws set their own deadlines.
- Fix and learn: correct the permission, process or habit that let it happen, and record what you did.
Write the breach plan now, name who does what, and rehearse it once a year. The first breach is the wrong time to find out who calls counsel.
The mistakes auditors find most often
- Keeping everything forever. Over-keeping is a risk too. GDPR treats personal data kept longer than needed as a violation, and everything you keep can be requested in discovery.
- Retention by folder, not by document type. Folders get reorganized and the rule breaks. Tie the rule to the type.
- Shared logins. A shared account makes the audit trail useless, because you cannot say who did what.
- Image-only scans. A scan without searchable text cannot be found by a privacy request or a discovery search. Make every scan searchable.
- Approvals in email. An approval buried in someone's inbox is hard to produce and easy to lose.
- Destroying held documents. Scheduled deletion that does not check for legal holds is one of the most expensive mistakes there is.
How to answer a privacy access or deletion request
- Log the request with its date. GDPR gives you one month in most cases; CCPA gives you 45 days.
- Search every repository by the person's name, email, customer or account number, across both the text of documents and their index fields.
- Collect what you hold, or for a deletion request, check each document against retention rules and legal holds first. Some records you must keep.
- Respond, and keep a record of the request and your answer.
This only works if documents are searchable and typed. Scattered shared drives and image-only scans turn a one-hour task into a week.
Audit-ready checklist
- List your document types and the rule that applies to each.
- Give every type its index fields and a retention period.
- Make all scanned documents searchable, and use PDF/A for long-term records.
- Set permissions by document type, turn on MFA and remove shared logins.
- Route approvals through a system that records them.
- Confirm you can place and release a legal hold, and that scheduled destruction respects it.
- Review who has access to each document type and the activity log, and record the review in your audit file.
- Sign BAAs or data processing agreements with every vendor that touches regulated documents.
- Train staff on spotting phishing, handling personal data and what to do the moment something goes wrong.
- Write and rehearse the breach plan.
- Review the whole list once a year, and whenever a rule changes.
Where Ademero fits
At the scanner: CapturePoint 6 splits a stack into documents, recognizes each type, reads the key fields and saves a searchable PDF or PDF/A with an automatic file name. Reading and extraction happen locally on your Windows PC, so documents with personal or health data are not sent to an outside service to be read. More in intelligent document processing explained.
In the library: Content Central runs on your own servers, with retention schedules per document type, legal holds, permissions down to field values, a required reason for access, version history, and an activity log of sign-ins, searches, views, downloads and deletions. It signs in with Active Directory or SAML single sign-on and supports authenticator-app MFA. It is built for HIPAA, and we sign BAAs. The retention setup guide in the help library shows how a schedule is configured.
