Learn when to let it go

Is your company holding onto data it shouldn't? Are you sure?

I've been warning against data hoarding since the early days of data science and Big Data.

Whenever I pointed out the risks of data hoarding – such as data leaks and data breaches – people waved me off, claiming that it was better to hold that data "just in case."

Fast-forward to 2026, and we see that Columbia University may have held social security numbers of people who have no affiliation with the institution. They'd apparently collected these SSNs ages ago and just … never got around to deleting them. Now they've suffered a data breach.

What can you learn from this? Treat Columbia's incident as a reminder:

1/ Review your data. All of it. Ask yourself how you'd feel about any of it getting out.

2/ If you don't have a data retention policy, it's time to establish one. Make sure it includes provisions for periodic reviews.