Compliance, Standards and Contracts
What Is a Data Retention Policy and How Long to Keep Data?
If you have ever asked how long your business is allowed to keep customer records, invoices or old job applications, the honest answer is that UK GDPR does not tell you. It gives you a principle and hands you the job of turning it into numbers. A data retention policy is how you do that: a written schedule that says, for every kind of personal data you hold, how long you keep it, why, and what happens when that time is up. Get it right and you satisfy the law, shrink your breach exposure, and give an insurer or an auditor a clean answer. Get it wrong, usually by keeping everything forever, and you are storing risk you gain nothing from.
What is a data retention policy?
A data retention policy is a documented set of rules deciding how long each category of data is kept and how it is disposed of at the end of that period. For personal data it is a legal requirement in practice, because the UK GDPR “storage limitation” principle in Article 5(1)(e) says personal data must be “kept in a form which permits identification of data subjects for no longer than is necessary.” It does not say how long “necessary” is. That is yours to decide and, crucially, to justify.
A usable policy lists each data category (customer accounts, payroll, CCTV, marketing consents, recruitment records), the retention period for each, the reason for that period, and the method and owner of disposal. It reads as a table, not an essay. This sits alongside the wider duties covered in our guide to the 8 principles of data protection and the Data Protection Act 2018 and UK GDPR.
Why there is no single legal answer
Because the law sets a principle rather than a period, two identical-looking businesses can lawfully keep the same data for different lengths of time if their purposes differ. The test is always the same three questions: do you still need this data for the purpose you collected it, does another law require you to keep it, and can you defend the period you chose? The Information Commissioner’s Office sets this out plainly in its guidance on storage limitation.
Keeping data “just in case” is not a purpose. Neither is “we might want it one day.” If you cannot state why you still hold something, storage limitation says you should not be holding it.
How long to keep common records in the UK
Some retention periods are effectively fixed for you by other legislation. These are the ones most UK small businesses need to pin down:
- Tax and VAT records: at least six years for limited companies, per HMRC. Self-employed records should be kept five years after the 31 January submission deadline of the relevant tax year.
- Payroll and PAYE records: HMRC requires at least three years from the end of the tax year; many firms keep six to match other tax records.
- Statutory maternity, paternity and sick pay records: three years after the end of the tax year they relate to.
- Workplace accident and injury records: three years under RIDDOR, though records involving young people or certain hazards are kept far longer.
- Anti-money laundering records (for regulated firms): five years after the end of a business relationship or a transaction.
- Financial services records (FCA-regulated): commonly five years, and longer for pensions and some investment products.
- Recruitment records for unsuccessful candidates: typically six to twelve months, enough to defend a discrimination claim, then deleted.
- CCTV footage: usually kept around 30 days unless it is needed for a specific incident.
Where no law sets a period, you choose one that matches your genuine need and write down the reasoning. A retention schedule that shows this thinking is exactly the kind of evidence an insurer values, and it is a natural output of a proper GDPR audit.
Writing and running the policy
Start by mapping what personal data you actually hold and where it lives, then assign each category a period and a justification. Set a review cadence, usually annual, and give someone ownership of the deletions so they actually happen. The hardest part is not writing the policy but enforcing disposal: build the deletion step into your systems so old data is purged automatically rather than left to a memory that fails. Remember that backups count too; a record you “deleted” that still sits in a nightly backup is still being retained.
The regulator can act when data is kept too long, and enforcement has teeth: the maximum UK GDPR fine is up to £17.5 million or 4% of global annual turnover, whichever is higher. For who can take action and when you must report a problem, see who enforces GDPR in the UK. A retention policy will not make headlines, but it is one of the cheapest, most defensible controls a small business can put in place.
Frequently asked questions
What is a data retention policy? It is a written schedule setting out how long your business keeps each category of personal data, the reason for each period, and how the data is securely destroyed afterwards. It turns the UK GDPR storage limitation principle into concrete, defensible rules.
How long can you legally keep personal data under UK GDPR? There is no fixed limit. UK GDPR says you may keep personal data only for as long as it is necessary for the purpose you collected it, and you must be able to justify the period. Some records, such as tax and payroll, have minimum periods set by other laws.
How long should a small business keep tax records? HMRC requires limited companies to keep tax and VAT records for at least six years. Self-employed people should keep records for five years after the 31 January submission deadline for the relevant tax year.
Do I have to have a written data retention policy? UK GDPR does not name the document, but you must be able to demonstrate how long you keep data and why, so a written retention policy or schedule is the practical way to meet the accountability principle and satisfy auditors and insurers.
What happens to data in backups when I delete it? Data held in backups still counts as retained. A sound policy sets retention and deletion rules that cover backups too, either by ageing them out on a schedule or by documenting why a short-lived backup copy is acceptable until it rotates.