This is a ready-to-use legal hold notice, paired with a register that tracks every hold placed across the organization from issuance to release. A legal hold suspends the normal retention schedule for specific records because of actual or anticipated litigation, investigation, audit, or regulatory action; while it is in force, those records cannot be destroyed no matter what the routine schedule says. Decommissioning projects and routine retention cleanups are exactly where a hold gets missed, because both are actively looking for data to dispose of. Replace every <<FILL: ...>> placeholder with your own specifics, set your document numbers, and route both the notice and the register through your normal document control. A worked filled specimen follows. Verify each cited regulation against the current source before you rely on it; the legal standard for what triggers a hold obligation is a legal determination, not a quality one, and this template supports that determination rather than making it.
Document control header
| Field | Entry |
|---|---|
| Document title | Legal Hold Notice and Register |
| Document number | <<FILL: LOG-ID, e.g. LOG-LGL-018>> |
| Version | <<FILL: version, e.g. 1.0>> |
| Effective date | <<FILL: effective date>> |
| Register owner | <<FILL: role, e.g. Legal / Regulatory Affairs>> |
| Applies to | <<FILL: sites / business units in scope>> |
Part 1: Legal Hold Notice
Issue one notice per hold event. The notice is the instruction sent to every custodian (system owner, IT, records management, archivist) who controls records within scope. It is a short, unambiguous directive, not a summary of the underlying matter.
Field table (notice)
| Field | Format | Required | Who completes it | When |
|---|---|---|---|---|
| Hold reference number | Short code | Yes | Legal | At issuance |
| Matter description | Text, only as detailed as needed to scope the hold; privileged detail stays with Legal | Yes | Legal | At issuance |
| Scope: record types, systems, date ranges, or custodians covered | Text, as specific as possible | Yes | Legal, with system owner input | At issuance |
| Instruction | Text: suspend all deletion, disposition, and routine retention-driven destruction for the scope above | Yes | Legal | At issuance |
| Custodians notified | Names / roles | Yes | Legal | At issuance |
| Acknowledgment | Name, signature, date, per custodian | Yes | Each custodian | Within a defined response window |
| Interaction with automated jobs | Text: which automated retention or cleanup jobs must be suspended or filtered to exclude the scope | Yes | System owner / IT | Within a defined response window |
Notice instructions
- Legal issues the notice as soon as litigation, investigation, audit, or regulatory action is reasonably anticipated, not only once it is filed or confirmed. Waiting for certainty is the most common way a hold is issued too late.
- Scope the notice as precisely as the matter allows. An overbroad hold (“everything, indefinitely”) is nearly as damaging as a missed one: it silently grows the retained estate, adds cost, and trains custodians to treat holds as noise.
- Send the notice to every custodian who could reasonably control in-scope records, including system owners of any automated retention or archival job that could otherwise sweep the data up.
- Require acknowledgment from every custodian within a defined window (a common practice is 5 business days). An unacknowledged notice is a gap, not a formality; follow up until every custodian has confirmed.
- Where a custodian’s system runs automated retention cleanup, confirm in the acknowledgment that the job has been suspended for the in-scope data or reconfigured to exclude it, not merely that the notice was read.
- Log the notice in Part 2, the register, the same day it is issued.
The notice (template)
| Field | Entry |
|---|---|
| Hold reference number | <<FILL>> |
| Date issued | <<FILL>> |
| Issued by (Legal) | <<FILL>> |
| Matter description (scope-appropriate detail only) | <<FILL>> |
| Record types / systems / date ranges covered | <<FILL>> |
| Instruction | Suspend all deletion, disposition, and retention-driven destruction for the scope above until this hold is released in writing by Legal. |
| Custodians notified | <<FILL: names / roles>> |
| Acknowledgment due by | <<FILL: date>> |
| Custodian acknowledgments (name, signature, date, automated-job status) | <<FILL, one row per custodian>> |
Part 2: Legal Hold Register
The register is the single place every disposition decision, and every decommissioning project, checks before destroying anything. It is the aggregate record of every hold ever placed, whether active or released.
Field table (register)
| Column | What goes in it | Format |
|---|---|---|
| Hold reference number | Links to the notice | Short code |
| Matter (scope-appropriate description) | Enough to identify the hold without privileged detail | Text |
| Scope | Record types / systems / date ranges / custodians | Text |
| Date issued | When the hold began | Date |
| Status | Active, Released, or Partially released | Text |
| Date released (if applicable) | When Legal released the hold | Date |
| Released by | Name | Text |
| Post-release disposition | Whether routine retention now applies, and from what date | Text |
| Notes | Any partial release, scope amendment, or escalation | Text |
Register (blank)
| Hold reference number | Matter | Scope | Date issued | Status | Date released | Released by | Post-release disposition |
|---|---|---|---|---|---|---|---|
<<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
How the register is used
- Before any disposition decision, whether a routine retention cleanup or a decommissioning project’s destroy step, the responsible function queries this register for every record type and system in scope.
- Any active hold covering the scope stops destruction for the covered portion; unheld record types in the same scope may proceed under their normal schedule.
- When Legal releases a hold, the release is recorded here with the date and the person who released it, before any deferred destruction resumes.
- On release, the record types formerly under hold are re-evaluated against the routine retention schedule; a lapsed clock during the hold period does not retroactively make the records eligible the instant the hold lifts unless the schedule itself is re-checked.
- The register is reconciled on a defined cadence against open litigation, investigation, and regulatory matters tracked by Legal, to catch a hold that should have been issued but was not yet formalized.
Retention
Retain this register, and every notice it references, as a controlled record indefinitely, or per <<FILL: records retention policy reference>>. A released hold’s history is itself evidence of why a later destruction was lawful; do not purge released entries.
Acceptance criteria
The legal hold process is working when every notice was issued with a defined scope and a required acknowledgment, every custodian’s automated retention jobs were confirmed suspended or filtered for the in-scope data, the register reflects the true current status of every hold ever placed, no destruction (routine or decommissioning) proceeds without a register check, and every release is dated, attributed, and followed by an explicit re-evaluation against the retention schedule before disposition resumes.
References
Federal Rules of Civil Procedure, Rule 37(e) (failure to preserve electronically stored information; the basis in US civil litigation for the consequences of a missed hold). 21 CFR 211.180 and 211.194 (routine records retention, which a hold suspends rather than replaces). EU GMP Annex 11 and EU GMP Chapter 4 (electronic records and documentation retention). MHRA GxP Data Integrity Guidance and Definitions (March 2018).
Confirm the current version of each reference before issue, and confirm with Legal what jurisdiction-specific preservation obligations apply beyond the GxP retention framework; this template supports the operational mechanics of a hold, not the legal standard for when one must be issued.
Filled specimen
The following shows a notice and its register entry for an example hold placed during a product complaint investigation that later intersected with a planned system decommissioning. Company, system, and numbers are illustrative.
Notice (specimen)
| Field | Entry |
|---|---|
| Hold reference number | HOLD-2027-004 |
| Date issued | 02 February 2027 |
| Issued by | M. Okafor, Legal |
| Matter description | Product complaint investigation with potential regulatory reporting implications, batch family DS-26-1xx |
| Record types / systems / date ranges covered | Batch disposition records, deviation records, and associated audit trails for batches DS-26-101 through DS-26-140, in both the active MES and the legacy CDS archive |
| Custodians notified | QA batch release, MES system owner, legacy CDS archive owner, decommissioning project lead |
| Acknowledgment due by | 09 February 2027 |
| Custodian acknowledgments | QA batch release: acknowledged, no automated job affected, 04 Feb 2027. MES owner: acknowledged, retention-cleanup job filter updated to exclude DS-26-101 to 140, 05 Feb 2027. Legacy CDS archive owner: acknowledged, archive records flagged in the archive index, 06 Feb 2027. Decommissioning lead: acknowledged, the in-flight decommissioning project’s destroy step for this archive segment suspended, 06 Feb 2027 |
Register entry (specimen)
| Hold reference number | Matter | Scope | Date issued | Status | Date released | Released by | Post-release disposition |
|---|---|---|---|---|---|---|---|
| HOLD-2027-004 | Product complaint investigation, batch family DS-26-1xx | Batch disposition, deviation, and audit trail records, batches DS-26-101 to 140, MES and legacy CDS archive | 02 Feb 2027 | Released | 30 Sep 2027 | M. Okafor, Legal | Records re-evaluated against schedule RT-002 (laboratory raw data, expiry plus 1 year); retention had not yet lapsed independent of the hold, so no destruction proceeded on release; archive retained under normal schedule |
The decommissioning project in this example had the affected archive segment scheduled for a destroy step; because the archive owner checked this register first, that segment was excluded and the rest of the archive’s dispositions proceeded unaffected. The hold’s release did not itself trigger destruction, because the underlying retention clock had not separately lapsed, which is exactly the check the post-release disposition column exists to force.
Common inspection findings this register prevents
- A decommissioning or routine cleanup destroyed records that were under an active hold nobody checked.
- A hold was issued verbally or by email with no formal notice, no defined scope, and no acknowledgment trail.
- An automated retention-cleanup job continued running against held data because the system owner was never asked to suspend or filter it.
- A hold’s release was undocumented, so years later nobody can show when or why the hold stopped applying.
- Records were destroyed immediately on a hold’s release without re-checking whether the routine retention clock had actually lapsed by then.
- No central register exists, so a decommissioning project has no single place to check before disposing of anything.
How to adapt this register
- Set your document number, owner, and effective date in the header.
- Confirm with Legal the acknowledgment window and escalation path for a custodian who does not respond.
- Wire every decommissioning plan, destruction certificate, and routine retention cleanup procedure to require a register check as a hard gate, not a recommended step.
- If your organization uses a legal matter management system, treat this register as the operational mirror focused on record-level scope and custodian acknowledgment, cross-referenced by matter number rather than duplicating privileged case detail.
- Reconcile the register against open matters on a defined cadence, and confirm every “Released” row shows a documented post-release re-evaluation before assuming normal disposition resumed.