All sample legal documents

Data Retention Policy

A completed UK data retention schedule for customer, workforce, financial, recruitment and security records, with deletion controls and accountability.

Jurisdiction: England and Wales - completed fictional worked example

Download Sample

An editable Microsoft Word version is available from the interactive page.

Important: This sample provides general legal information only and is not legal advice. Check the law, prescribed forms and signing requirements that apply to your exact jurisdiction and circumstances before use.

# DATA RETENTION POLICY

Date: 3 November 2031

Parties: Linden Vale Analytics Limited and all staff, contractors and processors

## 1. Purpose and parties

This policy is issued by Linden Vale Analytics Limited, company number 09147268, whose registered office is at 8 St Paul's Square, Leeds LS1 2ND. It applies from Monday 3 November 2031 to personal data and business records held digitally or on paper by employees, contractors, consultants and processors acting for Linden Vale. Eleanor Shaw, General Counsel, is the policy owner and Data Protection Lead.

## 2. Facts, scope and terms

Linden Vale keeps customer contracts and material correspondence for six years after expiry or termination, because contractual claims may be brought within the Limitation Act 1980 period. Invoices and accounting records are kept for six years after the end of the relevant financial year, unless a longer tax, audit, litigation or financing requirement is documented. The schedule is a maximum operational period, not permission to retain data without a purpose.

## 3. Process and responsibilities

Employee personnel and payroll files are kept for six years after employment ends, while health information is kept only for the period needed for the particular employment, insurance or legal purpose and is reviewed separately. Unsuccessful recruitment records are deleted six months after the recruitment decision, successful candidate records move to the personnel schedule, and marketing data is deleted or anonymised when consent is withdrawn or after two years without meaningful engagement.

## 4. Evidence, records and safeguards

Access-control logs are retained for twelve months, security incident files for six years after closure, and CCTV for 31 days unless an identified incident requires preservation. Board minutes are retained permanently as corporate records. A legal hold, regulator request, safeguarding concern or documented dispute suspends ordinary deletion only for relevant material; Eleanor must record its scope, owner and review date.

## 5. Review, escalation and outcome

At expiry, the responsible department lists the data category, person or account, volume, expiry date and applicable hold. Paper records are cross-cut shredded to at least DIN 66399 level P-4 by an approved confidential-waste contractor. Linden Vale securely deletes digital copies from active systems, instructs cloud processors to delete within 30 days, obtains written confirmation, and checks backups through the next scheduled overwrite rather than claiming immediate deletion where that is technically impossible.

## 6. Reservations and practical protections

Every destruction event is logged with the category, date, method, responsible person, processor certificate where applicable and any exception. Data Protection Lead Eleanor Shaw reviews the log monthly; department heads check their schedules quarterly; IT configures automatic deletion where reliable; and all staff complete annual training and report over-retention or a mistaken deletion immediately. A suspected personal-data breach is escalated to Eleanor without undue delay for an assessment of the UK GDPR Article 33 72-hour notification requirement.

## 7. England and Wales law and completion

This completed fictional policy does not create a universal statutory retention period or override a data-subject right, including a valid erasure request. Linden Vale records a lawful basis and purpose for each category, minimises access, securely stores records, and reviews this policy each 3 November and after a legal, regulatory, system or data-category change. It is governed by England and Wales law; Eleanor approved it on 3 November 2031 and the next scheduled review is 3 November 2032. Each department must report review results and exceptions to the Data Protection Lead and confirm that the schedule matches actual storage locations. Any decision to shorten or extend a period must record its purpose, necessity and lawful basis, and individual records must not be kept arbitrarily.

Create a version for your situation

Create a tailored Data Retention Policy