A Custodian of Records is the designated individual or entity legally responsible for maintaining, securing, and disclosing an organization’s official records. This role exists to ensure transparency, accountability, and compliance with federal, state, and local laws governing records retention, privacy, and public access.
Organizations appoint a Custodian of Records to prevent data breaches, legal liabilities, and operational disruptions. Failure to comply with records management laws can result in fines, lawsuits, or criminal charges.
Statutory & Regulatory Framework
Federal Laws & Agencies
- Freedom of Information Act (FOIA) – 5 U.S.C. § 552
- Governs public access to federal agency records.
- Requires custodians to respond to requests within 20 business days (with limited extensions).
- Exemptions apply for classified, personal, or proprietary data.
- Federal Records Act (FRA) – 44 U.S.C. §§ 3101-3107
- Mandates federal agencies to preserve records with historical or operational value.
- The National Archives and Records Administration (NARA) oversees compliance.
- Health Insurance Portability and Accountability Act (HIPAA) – 45 CFR Parts 160 & 164
- Applies to healthcare providers, insurers, and business associates.
- Requires custodians to safeguard protected health information (PHI) and respond to patient access requests within 30 days.
- Sarbanes-Oxley Act (SOX) – 15 U.S.C. § 7201
- Public companies must retain financial records for 7 years.
- Custodians face criminal penalties (up to 20 years imprisonment) for destruction or falsification.
- Family Educational Rights and Privacy Act (FERPA) – 20 U.S.C. § 1232g
- Governs access to student education records.
- Schools must respond to requests within 45 days.
State & Local Variations
- California: Public Records Act (CPRA) – Gov. Code §§ 6250-6270
- Requires custodians to respond to requests within 10 days (with possible 14-day extensions).
- Penalties for non-compliance: $1,000–$5,000 per violation.
- Texas: Public Information Act (PIA) – Gov. Code §§ 552.001-552.353
- Custodians must release records promptly (no strict deadline, but delays can trigger legal action).
- The Texas Attorney General reviews disputes.
- New York: Freedom of Information Law (FOIL) – Public Officers Law §§ 84-90
- Agencies must respond within 5 business days (either granting access or explaining denials).
- Fees: $0.25 per page for copies.
Industry-Specific Regulations
| Industry | Governing Law | Key Compliance Requirement |
|---|---|---|
| Healthcare | HIPAA (45 CFR Part 164) | Encrypt PHI, audit access logs, respond to requests in 30 days. |
| Finance | SOX (15 U.S.C. § 7201) | Retain financial records for 7 years, implement internal controls. |
| Education | FERPA (20 U.S.C. § 1232g) | Protect student records, allow parental access. |
| Government | FOIA (5 U.S.C. § 552) | Disclose public records within 20 business days. |
Step-by-Step Process & Requirements
1. Designation & Training
- Who can be a Custodian of Records?
- A senior employee (e.g., Records Manager, Compliance Officer, or General Counsel).
- In small organizations, the owner or office manager may assume the role.
- Training Requirements
- Complete annual compliance training on:
- Records retention schedules (e.g., NARA’s General Records Schedules).
- Data privacy laws (HIPAA, GDPR, CCPA).
- FOIA/state public records request procedures.
- Certifications (recommended):
- Certified Records Manager (CRM) – Institute of Certified Records Managers (ICRM).
- Certified Information Privacy Professional (CIPP) – International Association of Privacy Professionals (IAPP).
2. Records Inventory & Classification
- Conduct a Records Audit
- Identify all active, inactive, and archival records.
- Classify records by:
- Type (financial, personnel, contracts, emails).
- Retention period (e.g., tax records: 7 years, employee files: 3 years post-termination).
- Sensitivity (public, confidential, restricted).
- Tools for Inventory Management
- Software: M-Files, Laserfiche, or SharePoint.
- Spreadsheets: Track retention periods, storage locations, and destruction dates.
3. Develop a Records Retention Policy
- Key Components of a Policy
- Legal citations (e.g., "Tax records retained per IRS 26 U.S.C. § 6001").
- Retention schedule (e.g., "Employee applications: 1 year post-hire").
- Destruction procedures (e.g., shredding, digital wiping).
- Disaster recovery plan (e.g., offsite backups, cloud storage).
- Sample Retention Schedule
| Record Type | Retention Period | Legal Authority |
|---|---|---|
| Tax returns | 7 years | IRS 26 U.S.C. § 6501 |
| Employee personnel files | 3 years post-termination | EEOC 29 CFR § 1602.14 |
| Contracts | 6 years post-expiration | UCC § 2-725 |
| Emails (business-related) | 3–7 years | Varies by state (e.g., CA: 2 years) |
4. Secure Storage & Access Controls
- Physical Records
- Store in locked cabinets or secure offsite facilities (e.g., Iron Mountain).
- Limit access to authorized personnel only.
- Digital Records
- Use encryption (AES-256 for sensitive data).
- Implement role-based access controls (RBAC).
- Enable audit logs to track who accesses records.
- Cloud Storage Compliance
- Ensure providers comply with FedRAMP (for federal data) or HIPAA (for healthcare).
- Recommended providers: AWS GovCloud, Microsoft Azure Government, Google Cloud for Healthcare.
5. Responding to Records Requests
- Public Records Requests (FOIA/State Laws)
- Acknowledge receipt within the statutory deadline (e.g., 5 days in NY, 10 days in CA).
- Review for exemptions (e.g., personal data, trade secrets, ongoing investigations).
- Redact sensitive information (e.g., Social Security numbers, medical details).
- Provide records in the requested format (paper, digital, or inspection).
- Document the response (date, requester, records released, exemptions applied).
- Internal Requests (Employees, Auditors)
- Follow the same process but prioritize business needs.
- Charge reasonable fees (e.g., $0.10–$0.25 per page for copies).
6. Records Destruction & Disposition
- When to Destroy Records
- Only after the retention period expires.
- Exception: If a litigation hold is in place (e.g., pending lawsuit or audit).
- Approved Destruction Methods
- Paper: Cross-cut shredding (NAID AAA certified).
- Digital: NIST SP 800-88 compliant wiping (e.g., Blancco, DBAN).
- Hard Drives: Physical destruction (degaussing or crushing).
- Certificate of Destruction
- Obtain a signed certificate from the vendor confirming:
- Date of destruction.
- Method used.
- Witnesses (if applicable).
Common Pitfalls, Exceptions, & Penalties
Top Compliance Mistakes
- Failing to Respond to Requests on Time
- Consequence: Lawsuits, fines, or court orders compelling disclosure.
- Example: A California agency was fined $5,000 for missing a CPRA deadline.
- Improper Redaction of Sensitive Data
- Consequence: Data breaches, identity theft, or HIPAA violations.
- Best Practice: Use automated redaction tools (e.g., Adobe Acrobat Pro, CaseGuard).
- Destroying Records Under Litigation Hold
- Consequence: Spoliation sanctions (e.g., adverse jury instructions, fines, or default judgments).
- Example: In Zubulake v. UBS Warburg, the court imposed $29 million in sanctions for destroyed emails.
- Inconsistent Retention Policies
- Consequence: Difficulty defending against lawsuits or audits.
- Solution: Align policies with NARA’s General Records Schedules or industry standards.
- Ignoring State-Specific Laws
- Consequence: Fines for non-compliance with local public records acts.
- Example: Florida’s Sunshine Law imposes $500 fines per violation for delayed responses.
Exceptions & Exemptions
| Law | Exemption | Example |
|---|---|---|
| FOIA (5 U.S.C. § 552) | National security (b)(1) | Classified military documents. |
| HIPAA (45 CFR § 164) | Psychotherapy notes (b)(3) | Therapist’s personal notes. |
| FERPA (20 U.S.C. § 1232g) | Law enforcement records (b)(1) | Campus police incident reports. |
| CPRA (CA Gov. Code § 6254) | Personnel files (c) | Employee performance reviews. |
Penalties for Non-Compliance
| Violation | Federal Penalty | State Penalty (Example: CA) |
|---|---|---|
| Unauthorized disclosure (HIPAA) | $100–$50,000 per violation (max $1.5M/year) | $2,500–$25,000 per violation (CCPA) |
| Records destruction (SOX) | Up to 20 years imprisonment | Up to 3 years imprisonment |
| FOIA non-compliance | Court-ordered disclosure + attorney fees | $1,000–$5,000 per violation (CPRA) |
| FERPA violation | Loss of federal funding | State fines up to $10,000 |
Frequently Asked Questions (FAQs)
Who can be designated as a Custodian of Records?
Any senior employee with authority over records management, such as:- Records Manager
- Compliance Officer
- General Counsel
- Office Manager (in small businesses)
- IT Director (for digital records)
Exception: In government agencies, the agency head may delegate the role but remains ultimately responsible.
What happens if a Custodian of Records ignores a FOIA request?
The requester can:- File a complaint with the agency’s FOIA Public Liaison.
- Appeal to the agency head (if denied).
- Sue in federal court (5 U.S.C. § 552(a)(4)(B)).
- Courts can order disclosure and award attorney fees.
- Example: In Citizens for Responsibility and Ethics in Washington v. DOJ, the court ordered the DOJ to release records after a 3-year delay.
How long does a Custodian of Records need to keep emails?
- Federal: 3 years (NARA General Records Schedule 23).
- State:
- California: 2 years (CA Gov. Code § 14614).
- New York: 1 year (unless part of a business transaction).
- Industry-Specific:
- Healthcare (HIPAA): 6 years (45 CFR § 164.316).
- Finance (SOX): 7 years (17 CFR § 210.2-06).
Best Practice: Implement an automated email archiving system (e.g., Mimecast, Proofpoint).
Can a Custodian of Records charge fees for records requests?
Yes, but fees must be reasonable and pre-approved by the governing law:- FOIA: $0.10–$0.25 per page (5 U.S.C. § 552(a)(4)(A)).
- HIPAA: Actual cost of labor + supplies (45 CFR § 164.524(c)(4)).
- CPRA (CA): $0.10 per page (Gov. Code § 6253(b)).
Prohibited Fees:
- Search fees for public records (unless the request is voluminous).
- Fees for electronic records (if the requester provides their own storage device).
What is a litigation hold, and how does it affect records retention?
A litigation hold (or legal hold) is a court order requiring an organization to preserve all relevant records when litigation is reasonably anticipated.Steps to Comply:
- Issue a hold notice to all employees with relevant records.
- Suspend automatic deletion (e.g., email retention policies).
- Document compliance (e.g., hold logs, employee acknowledgments).
- Monitor until the hold is lifted by legal counsel.
Consequence of Non-Compliance: Spoliation sanctions, including:
- Adverse jury instructions.
- Monetary fines.
- Default judgment.
How can a Custodian of Records ensure compliance with data privacy laws like GDPR or CCPA?
- Map Data Flows
- Identify what personal data is collected, stored, and shared.
- Implement Access Controls
- Restrict access to need-to-know personnel.
- Enable Data Subject Rights (DSR) Requests
- GDPR: Respond within 30 days (Art. 12).
- CCPA: Respond within 45 days (Cal. Civ. Code § 1798.130).
- Conduct Regular Audits
- Test data breach response plans.
- Review third-party vendor compliance (e.g., cloud providers).
- Train Employees
- Annual training on GDPR/CCPA requirements and phishing risks.
Penalties:
- GDPR: Up to €20 million or 4% of global revenue (whichever is higher).
- CCPA: $2,500–$7,500 per intentional violation.
Practical Next Steps & Checklist
Immediate Action Plan
- ✅Designate a Custodian of Records (if not already done).
- ✅Conduct a records inventory (identify all active/inactive records).
- ✅Develop a records retention policy (align with legal requirements).
- ✅Implement secure storage (physical + digital).
- ✅Train staff on FOIA/public records laws and data privacy.
- ✅Set up a request response system (track deadlines, exemptions, fees).
- ✅Schedule annual audits (test compliance with retention/destruction policies).
Official Resources & Contact Information
| Agency | Website | Phone Number |
|---|---|---|
| NARA (Federal Records) | www.archives.gov | (866) 272-6272 |
| HHS (HIPAA Compliance) | www.hhs.gov/hipaa | (800) 368-1019 |
| DOJ (FOIA Guidance) | www.justice.gov/oip | (202) 514-3642 |
| California CPRA | www.oag.ca.gov/cpra | (916) 210-6000 |
| Texas PIA | www.texasattorneygeneral.gov | (512) 463-2100 |
Recommended Tools & Software
- Records Management: M-Files, Laserfiche, SharePoint.
- Email Archiving: Mimecast, Proofpoint, Barracuda.
- Redaction: Adobe Acrobat Pro, CaseGuard.
- Destruction: Iron Mountain (physical), Blancco (digital).
Disclaimer: This article is for informational and educational purposes only. It does not constitute formal legal advice and does not establish an attorney-client relationship. Consult a licensed attorney for specific compliance guidance.
Key Statutory Takeaways
- Contemporaneous written records are crucial for establishing statutory liability.
- Filing deadlines (statute of limitations) apply strictly from the date of infraction.
- Administrative remedies (EEOC/FEPA) must precede federal civil filings.
Robert Vance, Esq.
Verified AuthorCorporate Governance Partner
Admitted to the Delaware and New York Bars. Advises boards of directors, private equity funds, and emerging technology ventures on corporate compliance.
