A well-designed data retention policy UK GDPR framework helps organisations decide how long personal information should remain in their systems and when it must be deleted or anonymised. Without clear rules, businesses may keep customer, employee and supplier records indefinitely, often because nobody is responsible for reviewing them.
UK GDPR does not provide one universal retention period for every type of information. Instead, organisations must decide what is necessary for each processing purpose, document their reasoning and apply the period consistently.
This means balancing two significant risks. Keeping information for too long can breach the storage limitation principle and increase exposure during a cyberattack or subject access request. Deleting it too early can prevent an organisation from meeting statutory obligations or defending a legal claim.
The Storage Limitation Principle Explained
The storage limitation principle is one of the seven core UK GDPR principles. Article 5(1)(e) requires personal data to be kept in an identifiable form for no longer than is necessary for the purposes for which it is processed.
The other principles cover:
- Lawfulness, fairness and transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Integrity and confidentiality
- Accountability
You can find a broader overview in our guide to the data protection principles explained.
Storage limitation does not mean that all personal data must be deleted quickly. It means an organisation must understand why it is keeping the information and be able to justify the period selected.
The Information Commissioner’s Office advises organisations to establish standard retention periods where possible, review the information they hold and delete or anonymise data when it is no longer needed. The ICO also warns against keeping information indefinitely because it might become useful in the future.
The UK GDPR works alongside the Data Protection Act 2018, which supplements the UK data protection framework and contains additional provisions concerning matters such as special category information, criminal offence data and exemptions.
Longer retention may sometimes be permitted when information is held solely for public-interest archiving, scientific or historical research, or statistical purposes. Appropriate safeguards are still required, and the information should not later be reused for an unrelated purpose affecting individuals.
Does UK GDPR Set Fixed Retention Periods?
There is no single table in UK GDPR stating that employee information must be kept for one period, customer records for another and CCTV footage for a third. The legislation deliberately takes a purpose-based approach.
The ICO confirms that UK GDPR does not set specific time limits for different categories of personal information. Controllers must establish and justify their own periods based on why the information is being processed.
However, this does not mean retention periods can be chosen arbitrarily. Businesses should consider:
- Legal record-keeping obligations
- Regulatory and sector-specific requirements
- Contractual responsibilities
- Limitation periods for legal claims
- The expectations and rights of individuals
- The operational need for the information
- The sensitivity and volume of the data
- Whether anonymised information would be sufficient
For example, HMRC requires limited companies to retain certain company and accounting records for six years from the end of the relevant financial year, with longer periods applying in some circumstances.
Employment law also provides useful reference points. Many employment tribunal claims must normally be initiated within three months minus one day, although some claims have longer time limits and Acas early conciliation can affect the deadline.
These legal periods are starting points, not automatic permission to retain an entire personnel file. Each category within the file should still have a documented purpose.
How to Decide How Long to Keep Data
When deciding how long to keep personal data UK organisations should begin with the purpose for which it was collected.
Use the following process for each category of information:
-
Define the processing purpose.
State exactly why the information is held. “For business purposes” is too broad. -
Identify applicable legal requirements.
Check tax, employment, health and safety, financial, professional and sector-specific rules. -
Consider potential legal claims.
Determine whether the record may reasonably be needed to establish, exercise or defend legal rights. -
Assess the privacy risk.
Sensitive, detailed or high-volume records may create greater harm if misused or breached. -
Check whether identifiable data is still necessary.
Consider anonymising the information when the business only needs statistics or trends. -
Set a trigger date.
The retention period might begin when a contract ends, an employee leaves, an account closes or a complaint is resolved. -
Document the justification.
Record the legal, regulatory or operational reason behind the chosen period. -
Schedule a review or deletion action.
Do not rely on employees remembering to remove records manually.
Businesses must also explain retention in their privacy information. Where an exact period cannot be provided, the privacy notice should describe the criteria used to determine it.
A DPO can advise on proposed periods, monitor compliance and help departments understand their obligations. However, the DPO is not personally responsible for the organisation’s compliance; accountability remains with the controller or processor.
Common UK Retention Periods by Data Type
The following examples are reference points rather than universal legal instructions. Organisations should verify the requirements applying to their legal structure, location, sector and processing purpose.
|
Data type |
Possible retention approach |
Important considerations |
|
Recruitment applications |
Keep for a short, defined period after the recruitment decision |
Consider potential employment claims, future-vacancy consent and whether identifiable information is still necessary |
|
Employee personnel files |
Employment period plus a justified post-employment period |
Different parts of the file may require different periods; avoid retaining every document for the longest possible period |
|
Payroll records |
Current and previous three tax years for standard payroll records |
HMRC guidance states that employers should keep payroll records for the current and previous three tax years |
|
National Minimum Wage records |
Six years |
HMRC states that evidence showing compliance with minimum wage requirements should be kept for six years |
|
Corporation Tax and supporting records |
Generally six years from the end of the relevant accounting period |
Longer retention may be required where returns are late or an HMRC compliance check is ongoing |
|
VAT records |
Commonly six years |
Special schemes, concessions or specific circumstances may produce different requirements |
|
Customer contracts |
Contract duration plus a period linked to possible claims |
In England and Wales, many contractual claims may be brought within six years; Scottish limitation periods can differ |
|
Customer service correspondence |
Based on the complaint, contract or service purpose |
Routine messages may not need to be retained as long as contractual or dispute records |
|
Marketing information |
Until consent is withdrawn, the purpose ends or the information becomes unnecessary |
A minimal suppression record may still be needed to ensure someone who has objected is not contacted again |
|
CCTV recordings |
The shortest period necessary for the security purpose |
There is no universal UK GDPR period; footage connected to an incident may need to be isolated and retained longer |
|
Website account information |
While the account remains active and for a justified period afterwards |
Inactive accounts should be reviewed rather than retained indefinitely |
|
Subject access request records |
A documented period after completion |
Retain enough evidence to demonstrate how the request was managed without keeping unnecessary duplicate data |
HMRC’s current guidance states that standard payroll records should generally be kept for the current and previous three tax years, while National Minimum Wage records should be retained for six years.
VAT records are also commonly subject to a six-year period, although special rules and shorter agreed periods may apply in particular circumstances.
Where one document serves several purposes, apply the longest justified requirement to that document. Do not automatically apply a six-year period to every item merely because some accounting records require it.
Building a Data Retention Schedule
A retention schedule turns a general policy into practical instructions. It lists the information an organisation holds, the reason for keeping it, the retention period and what should happen when that period ends.
A useful retention schedule template UK organisations can adapt should contain:
- Business function or department
- Record category
- Types of personal data included
- Categories of individuals
- Processing purpose
- Lawful basis
- Statutory or regulatory reference
- Retention trigger
- Retention period
- Final action, such as deletion, anonymisation or archival review
- System or storage location
- Responsible record owner
- Review and approval date
- Any legal-hold procedure
The schedule should connect to the organisation’s Record of Processing Activities. ICO audit guidance recommends recording the purpose, data categories, storage location and retention period for each processing activity in the RoPA.
Linking the schedule to the RoPA prevents contradictory documentation. For example, the privacy notice should not promise deletion after three years while the RoPA says six years and the IT system has no deletion rule at all.
Treat the RoPA and retention schedule as living documents. Update them when:
- A new system is introduced
- A supplier begins holding personal data
- A processing purpose changes
- New legislation or sector guidance applies
- A department changes its working practices
- An audit finds that deletion is not taking place
Retention controls should form part of your wider GDPR audit readiness guide. A strong GDPR audit UK process should compare written periods with what is actually stored in live systems, archives, email accounts, shared drives and backups.
For deeper guidance on accountability and records management, explore GDPR training for Data Protection Officers. Operational teams may also benefit from GDPR Essentials for UK Businesses and broader data protection compliance training.
Secure Deletion and Disposal
Deleting personal data GDPR compliance requires more than moving a document to a recycle bin or marking a customer account as inactive.
Electronic information should be removed using methods appropriate to the system, storage medium and sensitivity of the data. This may include:
- Permanent deletion from live systems
- Removal from archives and recycle bins
- Scheduled deletion from cloud services
- Secure media erasure before equipment is reused
- Destruction of encryption keys where appropriate
- Deletion instructions for processors and suppliers
- Anonymisation where statistics are still required
Backups require particular attention. Immediate removal from every backup may not always be technically possible, but deleted information should be placed beyond normal use and allowed to expire through a controlled backup cycle. Restoration procedures should prevent deleted data from quietly returning to live systems.
The ICO recommends deleting electronic records in line with the retention schedule, addressing archives, emails, recycle bins and backups, and using automatic purging where appropriate. It also expects physical records to be destroyed using secure methods such as cross-cut or micro-cut shredding.
Businesses using disposal contractors should conduct due diligence, use appropriate contracts and obtain evidence of destruction. Records awaiting disposal must remain protected from unauthorised access.
A deletion log can record what was destroyed, when, under which schedule rule and who authorised the action. The log should confirm disposal without recreating the deleted personal information.
Risks of Over-Retention
Keeping personal data for too long creates legal, operational and cybersecurity risks.
The main consequences include:
- Greater breach exposure: Attackers can access a larger volume of historical information.
- Higher subject access request burden: Old emails, archives and duplicate files may need to be searched and reviewed.
- Inaccurate decisions: Outdated information may be mistaken for current information.
- Unnecessary storage costs: Organisations pay to secure records that no longer serve a purpose.
- Right-to-erasure complaints: Individuals may challenge information that is no longer needed.
- Regulatory scrutiny: Indefinite retention may indicate weak accountability and governance.
The ICO specifically notes that excessive retention can increase storage and security costs and make subject access requests more difficult to manage.
Deleting records too soon also carries risk. A business may lose evidence needed for tax reporting, regulatory inspection, contractual disputes, employment claims or complaint handling.
The correct objective is not maximum deletion or maximum retention. It is defensible, purpose-based retention supported by evidence.
Training Staff on Retention Practices
Even a strong policy will fail if employees save information in unmanaged folders, personal inboxes or unofficial cloud services.
Training should explain:
- Which records are covered by the retention schedule
- Where official records must be stored
- Why local and duplicate copies should be avoided
- How retention triggers are calculated
- Who can approve an extension
- What to do when litigation or an investigation is expected
- How to report a failed deletion
- Which secure disposal method to use
- How subject access and erasure requests affect records
Record owners in HR, finance, IT, customer service and compliance need more detailed training than general employees. They should understand the retention categories they control and be able to identify records that require review.
The DPO can advise, monitor and support awareness activities, but department heads and system owners should remain responsible for implementing the schedule. ICO guidance includes staff awareness, training and internal audits among the activities used to demonstrate accountability.
Retention should also appear in the organisation’s GDPR documentation checklist and onboarding process. New employees need to know that keeping every email “just in case” is not an acceptable records-management strategy.
FAQs
Does UK GDPR say exactly how long I can keep data?
No. UK GDPR generally requires organisations to decide and justify retention periods based on their processing purposes, legal obligations and the rights of individuals. Some sector-specific laws establish fixed periods for particular records.
How long should I keep employee records after they leave?
There is no single period for an entire employee file. Review each record category separately, considering payroll requirements, employment claim limitation periods, contractual obligations and whether the information is still necessary.
What is a data retention schedule?
A data retention schedule lists the records an organisation holds, why they are needed, how long they should be retained and what happens at the end of the period. It should be linked to the RoPA, privacy notices, systems and departmental procedures.
What happens if I keep personal data too long?
The organisation may breach the storage limitation principle and increase the impact of a data breach, subject access request or regulatory investigation. Unnecessary information may also become inaccurate or be used unfairly.
How should personal data be securely deleted?
Electronic data should be permanently removed or placed beyond use through an appropriate, documented process, including controls for archives, backups and suppliers. Paper records should be securely destroyed so that the information cannot be reconstructed or recovered.
Build a compliant retention schedule. Get expert guidance on retention, documentation and accountability by exploring our GDPR Training for Data Protection Officers course.