A general contractor in Ohio switches safety platforms in January. The old subscription ends on the 31st; the new system starts clean, with current-year data only. In March, a compliance officer opens a programmed inspection and asks for the 300 Logs covering the last five years, as the recordkeeping rule entitles them to do. Three of those years live in the old vendor's database, behind a login that stopped working with the last invoice. The safety manager is now negotiating with a support queue while a four-business-hour clock runs.
Nothing in that scene involves a violation of the software contract. The vendor did what the contract said. The problem is that two clocks were never compared: the retention clock OSHA puts on the employer, and the deletion clock the vendor puts on a closed account.
At a glance: the 300 Log, the privacy case list, the 300A and the 301 forms must be kept five years following the end of the calendar year they cover (29 CFR 1904.33(a)), and the stored 300 Logs must still be updated during that period (1904.33(b)(1)). Copies go to a government representative within four business hours (1904.40(a)) and to a current or former employee by the end of the next business day (1904.35(b)(2)(iii)). The chemical inventory and other exposure records run 30 years (1910.1020(d)(1)(ii)). Canceling a safety software subscription does not shorten any OSHA retention period: the employer stays responsible for five years of injury logs and thirty years of exposure records, whatever happens to the vendor account they were stored in.
The five-year rule outlives the subscription
The retention duty is written without any reference to where the records live. 29 CFR 1904.33(a) says it in one sentence:
"You must save the OSHA 300 Log, the privacy case list (if one exists), the annual summary, and the OSHA 301 Incident Report forms for five (5) years following the end of the calendar year that these records cover."
Two details in that sentence do the damage in a software transition. First, the anchor is the end of the calendar year, not the date of the entry: a case logged in January 2021 is held until the end of 2026, not January 2026. Second, the list has four items, and one of them, the privacy case list, is the one exit projects forget most often, because it is stored separately from the log by design under 1904.29(b)(6). If your export contains the 300 but not the confidential name list that decodes its "privacy concern case" lines, you have kept half a record.
The full schedule for every record type, with citations, is in our retention chart. The short version that matters here: no line of it mentions your vendor.
Stored logs still have to be updated
The five-year period is not cold storage. 1904.33(b)(1) asks the question directly and answers it:
"Do I have to update the OSHA 300 Log during the five-year storage period? Yes, during the storage period, you must update your stored OSHA 300 Logs to include newly discovered recordable injuries or illnesses and to show any changes that have occurred in the classification of previously recorded injuries and illnesses."
That sentence is the strongest argument against treating an exit export as an archive problem. A stack of frozen PDFs proves the logs existed on the day you left; it cannot absorb the hearing-loss case a physician confirms eleven months later, or a reclassification after a workers' compensation determination. Whatever you export has to remain editable as a log, or you need a plan for re-entering five years of history into the new system.
The narrower good news sits in the next two paragraphs of the same section: the annual summary and the 301 incident reports are exempt from updating under 1904.33(b)(2) and (b)(3). Those can be frozen safely.
Two deadlines that do not wait for a support ticket
The access rules are where a closed account turns from an inconvenience into exposure.
When an authorized government representative asks for your part 1904 records, 1904.40(a) requires copies "within four (4) business hours." We walked through what that deadline looks like inside a real inspection in the four-business-hour article; the point here is narrower. The rule sets the deadline and lists who can invoke it, including OSHA compliance officers and NIOSH representatives under 1904.40(b)(1). It does not carve out an exception for records held by a third party you no longer pay.
Employees have their own clock. Under 1904.35(b)(2)(iii), when an employee, former employee, personal representative, or authorized employee representative asks for copies of your current or stored 300 Logs, you must provide them "by the end of the next business day." Read that against a software exit: the electrician who left in 2023 keeps a right of access to the 2022 log, and the deadline for honoring it is measured in one business day, whether or not the log sits in a database you can still open.
What OSHA actually says about records kept in software
Employers sometimes assume digital recordkeeping is a gray zone. It is not; it is expressly permitted, with one condition attached, and OSHA has answered the software question in writing twice.
The rule itself is 1904.29(b)(5): "May I keep my records on a computer? Yes, if the computer can produce equivalent forms when they are needed, as described under §§ 1904.35 and 1904.40, you may keep your records using the computer system." The condition is the whole point. Your right to keep records digitally is tied to the system's ability to hand over equivalent forms when 1904.35 or 1904.40 knocks. A system you can no longer log into produces nothing.
What counts as equivalent is defined next door, in 1904.29(b)(4): a form with "the same information," that is "as readable and understandable," completed "using the same instructions" as the OSHA form it replaces. OSHA confirmed in an April 29, 2025 letter of interpretation that software-generated documents mirroring the Form 300 and 300A can satisfy the regulation on exactly those terms. So an export in a sane tabular format that carries every 300 column can be a lawful continuation of your log; a screenshot gallery is not.
The agency also addressed access design in a July 27, 2018 letter to a company building recordkeeping software: a system holding these records "would need to be designed in a way so that certain individuals could only access the specific information they are entitled to view." Worth remembering when an export lands as one flat file: the 300 Log with names is not shareable the way the 300A summary is, and the privacy case list is confidential under 1904.29(b)(6).
The same 2018 letter buries one more myth. Asked whether recordkeeping software needs OSHA certification, the agency answered: "No. OSHA does not approve, endorse, recommend, or certify any product or process." A vendor selling "OSHA-approved" software is selling a phrase the agency has refused, in writing, to attach to anyone. What the same letter does ask of a software, and what it never asks (a password, an audit trail, a login screen), is the subject of our guide to what OSHA requires from recordkeeping software.
The vendor clock against the OSHA clock
No sales deck puts these two clocks side by side. Across mainstream SaaS, a canceled account's data typically survives 30 to 90 days past the end of the subscription, and then it is deleted; Microsoft, for instance, documents a 90-day retention window for a lapsed Microsoft 365 tenant before permanent deletion. Retention terms vary by vendor and by contract, which is precisely why yours deserve a read before the last invoice.
Put the numbers side by side:
| The clock | How long it runs | Who set it |
|---|---|---|
| Your 300 Log, privacy case list, 300A, 301 | 5 years past the calendar year covered, 1904.33(a) | OSHA, on the employer |
| Your chemical inventory and other exposure records | 30 years, 1910.1020(d)(1)(ii) | OSHA, on the employer |
| A canceled SaaS account's data | commonly 30 to 90 days, then deletion | the vendor's contract |
No regulation bridges that gap for you. OSHA's rules bind the employer; they say nothing about what a software vendor must retain, because the vendor was never the one holding the duty. The bridge is contractual, and the time to read it is before signing, with the one question a widely cited software buying guide recommends putting to every recordkeeping vendor: we cancel in year three; what exactly do we get, in what format? If the answer does not cover every year, every form type, and the confidential lists, the retention problem has a date on it already.
One more line item belongs in the comparison. The 30-year clock on exposure records covers the chemical inventory and, unless you use the substitution option in 1910.1020(d)(1)(ii)(B), reaches records most people file under "the SDS binder." Five subscriptions can come and go inside one exposure record's lifetime.
The exit checklist, in the order that survives an inspection
Run this before the termination date, while the account is still yours:
- Export every open year plus five. One 300 Log per establishment per calendar year, consistent with 1904.30 and 1904.33(a), not one merged file.
- Export the privacy case list separately and store it with restricted access. It decodes the "privacy concern case" entries on the log, 1904.29(b)(6), and it is the piece a bulk export most often drops.
- Take the 300A summaries and 301 forms as they are. They freeze legally, 1904.33(b)(2) and (b)(3).
- Check the export against 1904.29(b)(4) equivalence: same columns, same legibility, same instructions. A data dump missing the classification columns fails the test.
- Keep the 300 data editable somewhere, because 1904.33(b)(1) keeps applying to cases you have not discovered yet.
- Pull the 30-year records: chemical inventory, exposure measurements, and the SDS set if you rely on it as your exposure record.
- Read the vendor's post-cancellation clause and diary the deletion date. If the window is 90 days, your export deadline is not "sometime soon."
What OSHA does not require here
Sorting the obligations from the folklore, in both directions:
- No rule requires paper. Digital-only recordkeeping is lawful under 1904.29(b)(5), on the equivalent-forms condition.
- No rule requires, or offers, certified software. The 2018 interpretation letter closed that door.
- No rule obligates the vendor. Every retention duty in part 1904 and 1910.1020 addresses the employer. What the vendor keeps after cancellation is whatever the contract says, nothing more.
- No updating duty on stored 300As and 301s. Only the 300 Log carries the five-year updating obligation.
How HazComFast handles a cancellation
In the spirit of the checklist above, stated plainly and only as far as we have measured it:
- After a cancellation, the account switches to read-only for 90 days. Records stay visible; nothing new can be written.
- The records export keeps answering during that window. We verified this on a real canceled subscription: the export endpoint returned the organization's complete record set after the cancellation webhook landed, not an error page.
- Those 90 days are our policy, not an OSHA number. No regulation blesses any post-cancellation window; we state ours so you can plan an exit against it, which is exactly the reading of the contract this article tells you to do with any vendor, us included.
Plan the exit before you need one
The free record retention calculator works out the destruction-eligible date for each record type from the rules cited in this article, with no login.
The hub & related: OSHA recordkeeping — 300, 300A & 301 · How long to keep each OSHA record · The four-business-hour rule · 30-year retention under 1910.1020 · Forms 300/300A/301 guide
Sources & verification: retention and updating duties per 29 CFR 1904.33, access deadlines per 29 CFR 1904.35 and 29 CFR 1904.40, exposure record durations per 29 CFR 1910.1020, all verified against the CFR text on 2026-09-05; software and certification positions per OSHA letters of interpretation of July 27, 2018 and April 29, 2025, read the same day. HazComFast product behavior (90-day read-only window, post-cancellation export) measured on a real canceled subscription on 2026-09-04.
Frequently Asked Questions
How long do you have to keep OSHA 300 Logs after you stop using a safety software?
Five years following the end of the calendar year each log covers, under 29 CFR 1904.33(a). The duty sits on the employer, not on the software vendor: canceling a subscription changes nothing about the retention clock. If the vendor deletes your account data after its contractual window, the logs are gone but the obligation is not.
Is it legal to keep OSHA injury records only in software, with no paper copies?
Yes. 29 CFR 1904.29(b)(5) lets employers keep part 1904 records on a computer system, on one condition: the system must be able to produce equivalent forms when they are needed to comply with the access requirements. An equivalent form must carry the same information, be as readable, and follow the same instructions as the OSHA form it replaces, per 1904.29(b)(4).
What if OSHA asks for records that are stuck in a canceled subscription?
29 CFR 1904.40(a) gives you four business hours to provide copies to an authorized government representative. The rule states the deadline without listing exceptions for vendor availability, so the practical answer is to export everything before the account closes, not to plan on reopening it during an inspection.
Do you still have to update old 300 Logs after switching software?
Yes, for the 300 Log itself. 1904.33(b)(1) requires you to update stored 300 Logs during the five-year period to add newly discovered recordable cases and to reflect changes in classification. The annual summary and the 301 forms are exempt from that updating duty under 1904.33(b)(2) and (b)(3). A frozen PDF export preserves the log but cannot satisfy the updating duty by itself.
Does OSHA approve or certify safety software?
No. In a July 27, 2018 letter of interpretation, OSHA wrote that it does not approve, endorse, recommend, or certify any product or process, and that it will not certify software claiming to help employers meet recording and reporting requirements. Any vendor marketing built on the phrase “OSHA-approved” describes something that does not exist.
OSHA figures and citations here come from our regulatory source-of-truth modules, last checked against the eCFR, OSHA.gov, and the Federal Register on October 5, 2026. Last reviewed September 15, 2026.
About This Article
Published by: HazComFast
Published: September 5, 2026
Last Updated: September 15, 2026
- https://www.ecfr.gov/current/title-29/section-1904.33
- https://www.ecfr.gov/current/title-29/section-1904.35
- https://www.ecfr.gov/current/title-29/section-1904.40
- https://www.ecfr.gov/current/title-29/section-1910.1020
- https://www.osha.gov/laws-regs/standardinterpretations/2018-07-27
- https://www.osha.gov/laws-regs/standardinterpretations/2025-04-29
This content is for informational purposes only and does not constitute legal advice.
