– Trevor Daughney, director information intelligence group at Symantec Corp., says:
As organizations are constantly trying to steer clear of litigation, their fears of not having the right information saved when a lawsuit arises have lead them to keep more information than is necessary. In fact, while most organizations think they are saving themselves time and money by keeping everything, negative consequences can result from preserving more electronically stored information (ESI) than necessary. According to Symantec’s recent Information Retention and eDiscovery Survey, 54 percent of respondents noted that when they preserved too much ESI, it increased their costs associated with collection, analysis and review in times of litigation. In addition, they experienced a 47 percent increase in time spent to collect, analyze and review ESI.
In the same Symantec survey in 2011, organizations believed that while some data should be deleted, it is often kept indefinitely. In a year, there hasn’t been much of a change – in 2012, 81 percent of survey respondents believe that a proper information retention plan allows organizations to delete information on an ongoing basis. Even though this is the belief, 42 percent of respondents noted that their backups are indefinitely retained by their organization. This is not only going against their information retention beliefs, but it is also creating a vast sprawl of information that will have to be sifted through in times of litigation. This stat didn’t change much from the 2011 survey where 79 percent believed that organizations should delete information regularly, and 40 percent of backups were retained indefinitely by organizations.
Keeping backups indefinitely can also lead to inefficient backups. This year’s survey has shown us that not only are organizations keeping information longer than is needed, they are keeping the data within backups rather than in archives for legal holds, which can lead to costly and time-consuming discovery. Symantec has found that this method continues – 85 percent of organizations routinely perform legal holds in their backups, which are not designed to be accessed in the same way as an archive. Thirty-eight percent of data that organizations back up is not needed or shouldn’t be kept in backup. In fact, respondents say that a third of backup data (34 percent) shouldn’t be kept and is unnecessary due to litigation risk.
Based on the 2012 results, Symantec has found that there has been no improvement in the gap between retention beliefs and practices, resulting in ESI requests failing a third of the time. So what can organizations keep in mind when pulling together a retention policy and sticking to it? Here are some recommendations:
1. Adopt a defensible deletion mindset
2. Err on the side of fewer retention policies
3. Automate privacy, retention and compliance policies
4. Implement a solution that allows you to automatically override expiry policies with legal holds
Used to monitor number of Google Analytics server requests when using Google Tag Manager
1 minute
_ga_
ID used to identify users
2 years
_gid
ID used to identify users for 24 hours after last activity
24 hours
_gali
Used by Google Analytics to determine which links on a page are being clicked
30 seconds
__utmx
Used to determine whether a user is included in an A / B or Multivariate test.
18 months
_ga
ID used to identify users
2 years
__utmv
Contains custom information set by the web developer via the _setCustomVar method in Google Analytics. This cookie is updated every time new data is sent to the Google Analytics server.
2 years after last activity
__utmc
Used only with old Urchin versions of Google Analytics and not with GA.js. Was used to distinguish between new sessions and visits at the end of a session.
End of session (browser)
__utmz
Contains information about the traffic source or campaign that directed user to the website. The cookie is set when the GA.js javascript is loaded and updated when data is sent to the Google Anaytics server
6 months after last activity
__utmt
Used to monitor number of Google Analytics server requests
10 minutes
__utmb
Used to distinguish new sessions and visits. This cookie is set when the GA.js javascript library is loaded and there is no existing __utmb cookie. The cookie is updated every time data is sent to the Google Analytics server.
30 minutes after last activity
__utma
ID used to identify users and sessions
2 years after last activity
_gac_
Contains information related to marketing campaigns of the user. These are shared with Google AdWords / Google Ads when the Google Ads and Google Analytics accounts are linked together.
90 days
Vimeo is a video hosting platform for high-quality content, ideal for creators and businesses to showcase their work.
This cookie is used to play YouTube videos embedded on the website.
2 years
VISITOR_PRIVACY_METADATA
Youtube visitor privacy metadata cookie
180 days
YSC
Registers a unique ID to keep statistics of what videos from YouTube the user has seen.
Session
DEVICE_INFO
Used to detect if the visitor has accepted the marketing category in the cookie banner. This cookie is necessary for GDPR-compliance of the website.
179 days
PREF
This cookie stores your preferences and other information, in particular preferred language, how many search results you wish to be shown on your page, and whether or not you wish to have Google’s SafeSearch filter turned on.
10 years from set/ update
GPS
Registers a unique ID on mobile devices to enable tracking based on geographical GPS location.
1 day
VISITOR_INFO1_LIVE
Tries to estimate the users' bandwidth on pages with integrated YouTube videos. Also used for marketing