5.3.6. Retention Policies, Retention Labels, and Retention Label Policies
💡 First Principle: Retention controls answer "how long should this content be kept, and what happens to it afterward" — completely separate from sensitivity labels' "who can access this and how is it protected" — and Purview offers two mechanisms to apply this: broad retention policies applied to entire locations, and granular retention labels applied to individual items, each governed by its own label policy for where it's available.
| Mechanism | Applies To | Granularity |
|---|---|---|
| Retention policy | Entire location (a mailbox, a whole SharePoint site) | Coarse — same rule for everything in scope |
| Retention label | Individual items a user (or auto-classification) applies it to | Fine — different items in the same location can have different retention |
| Retention label policy | Controls where labels are published/available | Governs label distribution, not retention duration itself |
A retention policy might say "keep everything in this SharePoint site for 5 years." A retention label lets one specific document within that same site be flagged for 10-year retention instead, overriding the broader policy for that item alone — retention labels generally take precedence over retention policies when both apply to the same content.
⚠️ Exam Trap: Sensitivity labels (5.3.3) and retention labels solve different problems even though both are called "labels" in Purview — sensitivity labels protect content; retention labels govern how long it's kept. A document can carry both simultaneously.
Reflection Question: A SharePoint site has a blanket 5-year retention policy, but one specific contract needs to be kept for 10 years due to a legal requirement. Which mechanism handles that exception, and why wouldn't the broader retention policy alone be sufficient?