Data Retention: How Long Should You Really Keep Personal Data?

10th August 2026

Of all the questions we get from clients, this is amongst the ones that come up most often: ‘How long do we have to keep this data?’ Sadly, there is no single correct answer. There is a principle, a way of thinking about it, and a few practical anchors. For example,  Article 5(1)(e) of the UK GDPR, the storage limitation principle, says ’personal data must be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed’. The ICO’s guidance on storage limitation does not dictate periods, but it does say you must justify why you are still holding data.

Why ‘just in case’ is the wrong answer

In nearly every audit we run, we find a number of ‘just in case’ records. From old CVs from candidates never hired, customer records from contracts that ended five years ago, meeting recordings nobody can remember the purpose of, when we ask why are you storing this we get ‘oh, just in case’, or ‘We might need it one day!’ – these are not justified lawful bases.

When the ICO fined Capita £14 million in October 2025, 6.6 million people were affected: the fine was predominately for security failings, but the volume of data held shaped both the impact and the penalty. The more data a controller holds the more individuals will be affected and the higher the volume the more resources must be expended in maintaining data accuracy and security. 

DPOs are always acutely aware that a Subject Access Request could land at any time, and this will compound the problem if poor data retention practices are in place. The bottom line is, if you still hold it, you have to search for it, find it, read it and redact and disclose it. The more you hold, the more harm a breach can cause.

Building a retention schedule

A good retention schedule should set out all your significant processing activities in a clear and practical way. For each activity, think about the type of personal data you hold, why you are using it, how long you need to keep it, when the retention period starts, and whether any exceptions apply. Keep it simple: four columns are usually enough:

  the processing activity or legal/business reason,,

  the data category,

  the retention period, and

  the disposal method.

Make sure every relevant department is identified, including IT, HR, Finance, Marketing, and other central operations.

Of course, having a policy is only the starting point. The real test is whether it works in practice. Your retention schedule should be reviewed at least once a year and checked regularly to make sure it is being followed. It should also line up with your Record of Processing Activities (RoPA) and your Privacy Notice or Privacy Policy, so everything stays consistent and up to date.

Sometimes the law will help by setting out how long certain records should be kept, for example, in areas such as tax, employment, or children’s services. There may also be guidance from regulators or industry bodies. Where there is no clear rule, you will need to justify the retention period based on the purpose of the processing and the potential benefit or harm to both the individual and the organisation. As a general rule, the more sensitive the data, the stronger the case for keeping it only for as long as strictly necessary. And of course remember, if you can anonymise the data, GDPR no longer applies and you can keep indefinitely.

Common retention periods

Specific periods vary by sector, but treat these as starting points:

  • Employee records. You must keep payroll and PAYE records for a minimum of 3 years from the end of the tax year they relate to. However, under the Limitation Act 1980, retaining them for 6 years is the general standard to defend against potential employment or legal claims. Personnel records are usually kept for this same period after an individual leaves employment.
  • Unsuccessful job applications. Six months is the common default, long enough to cover discrimination claim timescales. If you want to keep longer, just ask the candidate for permission.
  • Financial records. HMRC requires most financial records to be kept for six years.
  • Customer records. Driven by the contract and any tax obligations. Six years from the end of the relationship is a common anchor.
  • CCTV footage. Typically 30 days unless investigating a specific incident.
  • Meeting recordings and AI transcripts. Delete once the agreed minutes or summary is signed off. The raw recording is no longer ‘necessary’ if the summary serves the purpose.
  • Marketing: If you are actively engaging with a contact, in other words you are sending newsletters and they are opening them, it is reasonable to assume ongoing consent or lack of objection. If however an individual stops engaging, then good practice is for the consent or legitimate interests to expire after 24 months. If you want to continue processing data after that time you will need to justify why the processing is lawful or that you have renewed consent. 

How Griffin House Consultancy Can Help

Retention is often overlooked until it becomes a problem, and one of the most common areas where SMEs lose marks in an ICO audit; thankfully it is one of the easiest to put right with a bit of effort and structure. We help organisations build sector-specific retention schedules, integrate them with RoPAs and privacy notices, and run training so the schedule actually gets followed. Get in touch with us at Griffin House Consultancy, or call us on 01673 885533, and one of our team will be happy to talk it through.

 

Author: Mike Martin LLM

Mike is an information rights law specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details