The instinct to keep everything forever feels like thoroughness. Under the Data Privacy Act, it's a liability: personal data kept beyond its purpose is data you're responsible for without a reason.
A retention policy answers three questions: what do we keep, for how long, and who deletes it. The answers differ by record type, transaction logs outlive session data, official records outlive drafts.
The hard part is the deleting. Retention policies fail when they're documents instead of jobs. Automate the purge, log what was removed, and the policy becomes a system instead of a hope.