Crown Relocations is NZ’s leading moving company.

ROT and compliance breaches that didn’t have to happen

This is the second of two articles on ROT. In part one, we showed how ROT quietly sabotages sustainability targets

In Part Two we focus on the compliance costs. Both articles are steppingstones toward our guide, From ROT to ROI, which reframes ROT not just as a liability, but as an opportunity for measurable business value.

In 2020, Morgan Stanley made headlines for all the wrong reasons. The bank had failed to properly wipe decadesold customer data from decommissioned servers and storage devices. 

After a data breach, regulators fined the company tens of millions of dollars, not counting the damage to the bank’s reputation. It wasn’t just the breach itself, it was the fact that much of the exposed data was obsolete, data that should have been deleted years earlier.

Redundant, obsolete, and trivial data lingers in forgotten corners of systems until it becomes a liability. In the first article of this series, we explored how ROT undermines sustainability goals, driving up storage costs, energy use, and carbon footprints. But sustainability is only part of the story. This second piece looks at the compliance dimension, how ROT can put you at what is now very serious risk: fines, lawsuits, and lasting harm to the reputation of your brand. 

We’ve written a comprehensive guide: From ROT to ROI, to help with this: a practical roadmap for transforming data clutter into measurable savings.

What sort of ROT is especially dangerous?

From the above example, it might seem like every piece of data is a potential risk factor. Luckily, not all of this is equally dangerous. The most dangerous categories are:

  1. Personal identifiable information (PII)
    Probably the best known (and most dangerous). Old customer records in CRMs or elsewhere, addresses, phone numbers, and ID details. These often stick around long after they should have been deleted. It’s worth noting that PII data is where regulations like GDPR carry the most severe penalties for breaches.
  2. Financial records
    This refers to things like outdated payment card details, bank account numbers, or transaction histories. These are easy to forget about or store past reasonable use. If exposed, they can lead to both regulatory breach cases (and fraud). 
  3. Health data
    Some of the most personal data, and most likely to trigger popular anger/reputational damage. Patient files, diagnostic results, and insurance information are tightly regulated under laws like HIPAA. Retaining them beyond mandated retention periods is a direct compliance breach.
  4. Employment and HR files
    Old payroll records, disciplinary notes, or background checks often sit in forgotten folders. These contain sensitive personal data that must be destroyed once legal retention windows close.
  5. Email and messaging archives
    Large volumes of email are kept “just in case,” but they often include sensitive attachments, contracts, or personal data. Regulators increasingly view uncontrolled email archives as a risk.
  6. Legacy system backups
    Think physical media in this case: Old server images, tape backups, or cloud snapshots frequently contain entire datasets that should no longer exist. They are easy to overlook but can be devastating if compromised.

Summarising the takeaways

  • Redundant, obsolete, and trivial data actively raise compliance risks in an increasingly severe regulatory environment. 
  • The most dangerous ROT is personal, financial, health, and employment data.
  • ROT complicates audits, inflates the scale of breaches, and erodes trust. Sometimes the reputational damage is worse than the fine. 
  • Managing ROT is not just about being more efficient and saving money,  but also about risk. 

Even if your organisation hasn’t faced a breach, how much forgotten data is sitting in your systems right now, and what would it cost you if it were exposed tomorrow?

From ROT to ROI

Our full guide, From ROT to ROI, shows how to move beyond firefighting and turn data clutter into measurable savings. A roadmap for reducing risk, cutting costs, and strengthening compliance. Download it today

Share
Related Posts
Good for Business | Crown Relocations NZ

Good for Business

Crown Worldwide NZ Ltd’s partnership with The Salvation Army has become a lasting example of

Time Out Sydney | Crown Relocations NZ

Time Out Sydney

The bright lights and popularity of Australia’s biggest and oldest city call many New Zealanders

Hanlie Mostert - Operations Manager | Crown Relocations

Stronger Together

In celebration of International Women’s Day, we put the spotlight on our Crown Relocations Auckland

Renovating your home | Blog | Crown Relocations NZ

Renovating your Home

Have you been binge-watching ‘The Block’ for the past few seasons? Is your MySky constantly

Why Nelson Should be Your Next Home | Crown Relocations NZ Blog

Retiring to Nelson

When putting together a plan for retirement, there’s more to consider than just your finance.

Crown Worldwide NZ Ltd working with The Salvation Army

The Salvation Army

It’s a privilege to support NZ’S true heroes. It’s no surprise that nearly every New

Construction of the sustainable designed Crown Worldwide Group NZ warehouse

Going Green: Sustainable Design to Protect What Matters to You

Are you concerned about how climate events might affect the safety of your stored valuables? Is your business looking to partner with a moving and storage business that shares your sustainability values? Or maybe you’re simply wondering what happens to your goods during power outages or extreme weather?

Recent Posts
Share

Hi there, you’ve reached us outside of business hours. Please leave your name and number and we’ll be in touch with you soon.

  • This field is for validation purposes and should be left unchanged.

Hi there, you’ve reached us outside of business hours. Please leave your name and number and we’ll be in touch with you soon.

  • This field is for validation purposes and should be left unchanged.