How Long Must a UK Business Keep Data?

A UK business must keep most financial and employment records for six years, and must delete personal data once it has no reason to hold it. There is no single retention period in UK law. Instead, there are statutory minimums for specific records, regulatory rules for some sectors, and the UK GDPR rule that everything else is deleted when its purpose ends.

The number that matters most this year is six years for holiday records. Since 6 April 2026, the Employment Rights Act 2025 has required every employer to keep records proving each team member received their annual leave and holiday pay. Employment law firm Lewis Silkin notes that failing to keep those records is now a criminal offence, punishable by a potentially unlimited fine. If your holiday tracking lives in a spreadsheet that someone deletes when they tidy Drive, you have a problem.

The video above walks through the reasoning. This article is the written version you can work from. It is built around one job: producing the one-page retention schedule a customer can ask for and you can send.

Why is there no single legal retention period in the UK?

UK law does not set a delete-by date because the UK GDPR is based on purpose, not time. The storage limitation principle says you may keep personal data only for as long as you need it for the purpose for which you collected it. The ICO's guidance on storage limitation says the period "is up to you". It adds that you "must be able to justify why you need to keep personal data" in identifiable form.

That puts the work on you rather than the regulator. The ICO never has to prove a file should have gone. You have to show why it stayed. The higher-tier penalty is £17.5 million or 4 per cent of worldwide turnover. A fifteen-person firm will not see that number, but an enforcement notice, or a breach involving ten years of old client files, is expensive enough.

The other side of the coin is that several laws set a floor. Delete accounting records at year four, and HMRC can fine you and disqualify a director. So the answer to "how long?" has three parts. Some records have a minimum period set by law or a regulator. Some have a period you choose and write down. Everything else has no reason to exist and should be removed.

What is the minimum retention period for each type of business record?

The table below lists the records nearly every UK employer holds, with the shortest period the law allows and the source of the rule. These are floors. Where two rules cover the same record, the longer period applies.

UK Statutory Record Retention Periods
RecordHow long to keep itWhere the rule comes from
Company and accounting recordsSix years from the end of the financial year they relate to. Longer if a transaction spans accounting periods, equipment lasts beyond six years, you filed late, or HMRC opened a compliance check.HMRC. Up to £3,000 fine and director disqualification for poor records.
Board minutes and resolutionsTen years.Companies Act 2006.
Register of membersFor the life of the company.Companies Act 2006.
PAYE recordsThree years from the end of the tax year.HMRC. Penalty of up to £3,000.
National Minimum Wage recordsSix years.National Minimum Wage Regulations.
Right to Work checksThe full length of employment, then two years after the person leaves.Home Office. £45,000 per worker for a first breach, up to £60,000 for a repeat.
Pension auto-enrolment recordsSix years.The Pensions Regulator.
Pension opt-out noticesFour years, in original format. A scan counts.The Pensions Regulator.
Annual leave and holiday pay records (new)Six years from the date created, whether the team member still works for you or not. Applies from 6 April 2026.Employment Rights Act 2025. Failure to keep records is a criminal offence.

Three points from the table trip people up in practice. The first is that HMRC's six years for accounting records runs from the end of the financial year, not from the date of the invoice. GOV.UK's guidance for limited companies lists cases where it stretches further, such as a late return or an open compliance check. The second is that PAYE records only need three years, but National Minimum Wage records for the same person need six, so payroll is a six-year record in practice. The third is Right to Work. The Home Office civil penalty for employing an illegal worker is £45,000 per worker, and £60,000 for a repeat, and the check is your only defence. Keep it for the whole employment and two years afterwards.

Which regulated sectors have extra data retention rules?

Accountancy, legal, property, and financial services firms have retention rules layered on top of the statutory list, and some of those rules require deletion as well as retention. If a regulator covers you, its periods replace the general ones wherever they are longer, and its deletion deadlines are binding.

Retention Periods for Regulated UK Businesses
RecordHow long to keep itWhere the rule comes from
Customer due diligence records (accountants, solicitors, estate and letting agents, tax advisers)Five years from the date the transaction completes or the relationship ends. Ten years in some cases. Must then be deleted.Money Laundering Regulations 2017, Regulation 40.
Pension transfer, conversion, opt-out, and free-standing AVC suitability recordsIndefinitely.FCA Handbook.
Life policies, personal and stakeholder pensions, and DC occupational schemesFive years.FCA Handbook.
MiFID systems and controls recordsFive years.FCA Handbook.
Most other FCA recordsThree years.FCA Handbook.
Health and care recordsFollow your sector records management code.Your sector regulator and records management code.

The Money Laundering Regulations are the ones most small firms miss. Customer due diligence records and proof-of-address documents you collected when you onboarded a client. They must be kept for five years after the relationship ends, or ten in some cases. Regulation 40 then requires you to delete them. A letting agent with a client ID from 2015 still sitting in a shared drive is breaking the rule in the other direction.

FCA firms have a longer retention period, ranging from indefinite retention for pension transfer suitability records to 3 years for most day-to-day records. Health and care providers work according to their own records management code. In all of these cases, the regulator's number beats anything an IT provider tells you.

How do you decide what to keep when no law tells you?

Keep a record when you can write one sentence naming the specific risk it protects you against. Contracts and the correspondence that shows what was agreed are the clearest cases. In England and Wales, a claim on a simple contract can be brought within six years, and within twelve years for a deed. Keeping the contract file for six years after the relationship ends is therefore a reason the ICO will accept.

The same logic covers accident books, insurance claims, complaints, and disciplinary records. Each one has a scenario where someone comes back later with a different account of events, and the record settles it.

Where the logic fails is the blanket version. "We might need it one day" covers the signed contract. It does not cover a former client's entire Drive folder, including their staff list, their bank details from an old invoice, and the photos from a site visit. A useful check is to try writing the sentence without the word "just". If the only sentence available is "we keep it just in case", the record has no purpose, and under storage limitation, a record with no purpose has to go.

What does a one-page data retention schedule look like?

A retention schedule is a short table that lists each category of data you hold, how long you keep it, why, and where it is stored. It is the document that a new customer's procurement team requests. The ICO says a small organisation doing low-risk processing "may not need" a formal policy. A single page still answers both the customer's and the ICO's questions. Take a twelve-person marketing agency in Birmingham as a working example. Its schedule fits in eight lines.

Example Retention Schedule for a Twelve-Person Marketing Agency
DataHow longReason
Client contracts and statements of workSix years after the engagement endsLimitation period for a contract claim in England and Wales.
Invoices and bank recordsSix years from the financial year endHMRC accounting records rule.
Payroll and holiday recordsSix yearsHMRC, National Minimum Wage, and the Employment Rights Act 2025.
Right to Work checksEmployment plus two yearsHome Office civil penalty defence.
Unsuccessful candidate CVsSix months after the role closesTime limit for a discrimination claim at an employment tribunal.
Client project filesTwelve months after the project closesHandover and revision requests. Then returned or deleted.
Leavers' mailboxesNinety daysTime to move anything the business needs, then deleted.
Prospect and enquiry dataTwo years from last contactNo purpose beyond that without renewed contact.

None of those periods is imposed by the ICO. Most are chosen. What makes the page defensible is that every line has a reason written next to it, and the reasons are specific.

How do you automate data retention in Google Workspace?

Retention only works when the system deletes on schedule, because nobody will search for a five-year-old client file on the right day. In Google Workspace, the tool is Google Vault, which lets you set a rule for each data type and time period, then remove the data when the period ends. Google's own documentation on how Vault retention works covers Gmail, Drive, Chat, Groups, Calendar, Google Voice, Sites, and the Gemini app.

Each line of the schedule becomes a rule. Leavers' mailboxes get a ninety-day rule. A Drive label for closed client projects is subject to a 12-month rule. Payroll records in a specific shared drive are subject to a six-year rule. Vault also does the reverse: a legal hold freezes data while a dispute is ongoing, even if a rule would otherwise delete it. We have used it to protect a client from a £250K claim, and our earlier guide covers how to set up Vault to retain business data.

Vault is not a backup. It will not bring back a file a team member deleted by mistake. That is a separate job, covered in our post on backup strategy for startups, scale-ups, and SMBs. Microsoft 365 has an equivalent in its compliance tools. Google Workspace is what Kimbley IT, a Birmingham managed IT services provider, specialises in, so we will leave Microsoft advice to people who do that daily.

Steps to set your business data retention periods

  1. List every category of data you hold. Finance, payroll, HR, client files, prospects, email, chat, and any ID documents. Ten to fifteen lines is normal for a small business.

  2. Fill in the legal floors first. Use the statutory table above, then your regulator's periods if you have one. Where two rules apply, take the longer.

  3. Choose a period for everything else and write the reason. One sentence per line, without the word "just". If you cannot write it, the period is zero.

  4. Clear the backlog in a single session. Ex-client folders, suspended mailboxes, old candidate CVs, and unused marketing lists. Delete what fails step three.

  5. Turn each line into an automatic rule. In Google Workspace, that means a Vault retention rule per category. Ask whoever runs your IT to show you the rules running, rather than telling you they exist.

  6. Keep the page. Send it when a customer asks, and review it once a year or when a law changes.

Frequently asked questions

The periods in this article were checked in September 2026 and apply to most UK businesses. Your business may hold records this guide does not cover, and the law changes, so confirm the periods before you rely on them. Retention is only one part of data protection, not the whole. How the data is secured and who can reach it matter as much, which is why a customer who asks about retention usually asks about Cyber Essentials next.

If you want help putting this into practice

The next step is to book a video call with Kimbley IT using the form below.

Kimbley IT can draft your retention schedule with you and set up the matching rules in Google Vault.

James Kimbley

<strong>Founder, Entrepreneur & Investor at Kimbley IT Limited</strong>

<br><br>

My team organises your business IT with Google Workspace, AI, Cyber Security & Support in One Package, trusted by 65+ UK businesses. Kimbley IT is a Google Cloud Partner, and Google Workspace is at the heart of everything we do. We recommend it because we've spent nearly 20 years helping UK businesses get the most from it and not because anyone asked us to.

<br><br>

Connect with me:

<a href="https://www.linkedin.com/in/jameskimbley/">LinkedIn</a> •

<a href="https://www.threads.com/@james.kimbley">Threads</a> •

<a href="https://www.kimbley.com/blog?author=50c5e9d6e4b033df8f3030ec">View All Posts</a>

www.kimbley.com
Next
Next

What Is the Average IT Support Response Time?