IT Security
Written by Joanne Hughes, Policy & Compliance SpecialistLast reviewed

Why Your Business Needs a Data Storage and Retention Policy

A data storage and retention policy sets out what data your business holds, where it is stored, how long each category is kept and how it is destroyed at the end of its life. The legal anchor is the storage limitation principle in Article 5(1)(e) of the UK GDPR, which requires personal data to be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which it is processed.

The UK GDPR itself sets no fixed retention periods. Those come from other legislation, and they pull in different directions. HMRC requires PAYE payroll records to be kept for three years from the end of the tax year, minimum wage records must be kept for six years, and health records for staff exposed to hazardous substances must survive for forty years.

A written policy reconciles these obligations into a single retention schedule that staff can follow. Without one, most businesses default to keeping everything indefinitely, which breaches the storage limitation principle, inflates storage costs and widens the impact of any data breach.

The rules have also moved recently. The Data (Use and Access) Act 2025 amended UK data protection law in stages, and from 19 June 2026 every controller must operate a formal process for handling data protection complaints, including complaints about how long personal data is kept and how securely it is stored.

Statutory Retention Periods at a Glance

The periods below are set by statute or by HMRC requirements and have been checked against government sources. They are minimums: a business can hold records for longer where it can justify the extra period, but personal data with no statutory period must still be justified against the storage limitation principle.

Record typeMinimum retention periodSource
PAYE payroll records3 years from the end of the tax year they relate toHMRC (gov.uk)
National minimum wage records6 years (for records made from 1 April 2021)National Minimum Wage Regulations 2015, regulation 59
Working time records2 years from the date they were madeWorking Time Regulations 1998, regulation 9
Accident book entries3 years from the date of the entrySocial Security (Claims and Payments) Regulations 1979, regulation 25
COSHH health records40 years from the date of the last entryCOSHH Regulations 2002, regulation 11
VAT recordsAt least 6 yearsHMRC (gov.uk)
Company and accounting records6 years from the end of the financial year they relate toHMRC (gov.uk)

The accident book requirement applies to employers with ten or more people at the same premises, and to mines, quarries and factories of any size. The forty year rule for COSHH health records applies wherever employees are under health surveillance because of exposure to hazardous substances.

What a Data Storage and Retention Policy Covers

The policy is the master document for the whole data lifecycle. A well drafted version answers four questions for every category of data the business holds: where is it stored, who owns it, how long is it kept, and how is it destroyed.

The core components are:

  • A retention schedule by data type. Each category of record is listed with its retention period and the reason for it, whether statutory, contractual or a documented business justification.
  • Approved storage locations. The policy names the systems where each data type may live, covering servers, cloud platforms, paper archives and portable media, so data does not accumulate in personal drives and inboxes.
  • Ownership and review. A named owner is responsible for each schedule entry, and the whole document is reviewed on a fixed cycle so periods stay aligned with the law.
  • Disposal procedures. The policy states how data is deleted or destroyed when its period expires, and what evidence of destruction is kept.
  • Backup arrangements. Backup frequency, locations, encryption and recovery testing are defined so that resilience does not quietly become indefinite retention.

Storage and retention rules also depend on controlling who can reach the data in the first place. That side of the framework is covered in our guide to access control policies aligned to ISO 27001 and Cyber Essentials.

The Storage Limitation Principle in Practice

The ICO has been consistent that keeping personal data indefinitely just in case is not compliant with Article 5(1)(e). A business must be able to point to a purpose for every category of personal data it still holds, and to a defined period or review point at which that data is erased or anonymised.

Anonymisation is a genuine alternative to deletion. Once data no longer permits identification of individuals, the storage limitation principle no longer bites, which is useful for management information and long term trend analysis.

There are limited exceptions. Personal data may be kept for longer periods where it is processed solely for archiving in the public interest, for scientific or historical research or for statistical purposes, with appropriate safeguards. Very few commercial businesses can rely on these exceptions for routine records.

Disposal and Secure Deletion

Retention schedules only work if something actually happens when a period expires. Pressing delete or reformatting a drive does not destroy data; it can often be recovered with commercially available tools.

A retention policy therefore specifies approved destruction methods: overwriting with certified software, degaussing of magnetic media, physical destruction through a certified provider with a certificate of destruction, or cryptographic erasure of encrypted volumes. Paper records need an equivalent route, usually cross-cut shredding or a confidential waste contractor.

End of life hardware is a common gap. Laptops, phones and servers leave the business through resale, recycling or the bin, and each route needs a documented wiping or destruction step. Our hardware destruction, retention and backups policies service covers this part of the lifecycle in detail.

Backups Are Not an Archive

Backups exist so the business can restore systems after an incident. Article 32(1)(c) of the UK GDPR requires the ability to restore availability and access to personal data in a timely manner after a physical or technical incident, so a backup regime is itself a compliance measure.

The problem comes when backups double as an unofficial archive. If deleted records persist in backup sets for years, the business is still storing that personal data, and it remains discoverable in disputes and access requests.

The policy should state backup frequency and rotation periods, require backup media to be encrypted to the same standard as live data, and explain how deletion from live systems flows through to backup copies as sets expire. Recovery testing on a fixed cycle proves the arrangement works before it is needed.

How Retention Interacts with Subject Access Requests

Under Article 15 of the UK GDPR, an individual can request a copy of the personal data you hold about them, and you normally have one calendar month to respond. You can only meet that deadline if you know what you hold and where it is, which is exactly what the retention schedule records.

Over-retention makes every request slower and riskier. Each obsolete mailbox, legacy system and forgotten archive is another place you are expected to search, and another source of material you must review and disclose.

The courts have confirmed that searches cannot be artificially narrowed. In Ashley v HMRC [2025] EWHC 134 (KB), decided in January 2025, the High Court rejected HMRC's decision to confine its search to the single directorate that handled the request, holding that practical difficulty in searching across departments did not justify the limitation. Controllers are expected to design their systems around their obligations, not the other way round.

The Data (Use and Access) Act 2025 has since written the reasonable and proportionate search standard into law, and allows the response clock to be paused while a controller seeks information needed to identify the requester or clarify the request. Our Data (Use and Access) Act 2025 employer guide covers these changes in full.

The Data (Use and Access) Act 2025 and Your Policy

The most immediate DUAA change is the complaints duty. Since 19 June 2026, every controller must operate a process through which individuals can complain about the handling of their personal data, must acknowledge each complaint within 30 days and must respond without undue delay. There is no exemption for small businesses, and the ICO has published guidance on handling data protection complaints.

Retention is a natural source of complaints. A former employee who finds their file still circulating years after departure, or a customer whose deletion request went nowhere, now has a formal route to challenge you directly before escalating to the ICO.

A documented storage and retention policy gives you the evidence to answer those complaints: what you held, why you held it, and when it was destroyed. It sits alongside your data protection and confidentiality policy as part of one accountability framework.

Common Failure Points

  • Keeping everything indefinitely. The default in most businesses is never to delete. That breaches the storage limitation principle and turns every breach, dispute and access request into a bigger problem than it needed to be.
  • A schedule nobody executes. A retention schedule with no named owners and no deletion triggers is shelfware. The ICO expects procedures that actually review, erase or anonymise data when periods expire.
  • Backups outside the policy. Records deleted from live systems but kept in backup sets for years are still stored personal data, and still disclosable.
  • Unmanaged hardware disposal. Devices leaving the business without certified wiping or destruction have caused real breaches. Deleting files or formatting a drive is not secure disposal.
  • A policy that contradicts the privacy notice. If your privacy notice promises deletion after two years and your systems keep data for seven, you have documented your own infringement.
  • DSAR searches limited to one team. After Ashley v HMRC, confining a search to the department that received the request is not a defensible position.

Enforcement and Risk

Breaches of the data protection principles, including storage limitation, sit in the higher tier of ICO fines: up to £17.5 million or 4 per cent of total annual worldwide turnover, whichever is higher. The ICO can also issue enforcement notices requiring data to be erased and processing practices to change.

Fines at that scale are reserved for serious cases, but the everyday risks bite sooner. Over-retained data enlarges the reportable impact of any breach, missed statutory periods weaken your position in tax inquiries and tribunal claims, and a failed DSAR or complaint response is a standing invitation for ICO scrutiny.

Data Retention Policy and Procedure Writers

Policy Pros writes bespoke data storage policies and retention schedules for UK organisations, tailored to your systems, sector and the statutory periods that apply to your records. Each policy covers approved storage locations, retention by data type, secure disposal and the backup arrangements that keep the schedule honest.

We also write the surrounding framework, including data protection and confidentiality policies and hardware destruction, retention and backups policies, so retention, security and disposal work as one system rather than three documents that disagree with each other.

If your business has no retention schedule, or one that predates the Data (Use and Access) Act 2025, contact us for a fixed quote.

Frequently Asked Questions

What is a data storage policy?

A data storage policy sets the rules for how a business stores electronic and physical data across its lifecycle, from creation to secure disposal. It defines approved storage locations, retention periods for each data type, encryption and backup standards, and destruction procedures. It is a core accountability document under the UK GDPR and the Data Protection Act 2018.

What is the difference between a data storage policy and a data retention policy?

In practice they are two views of the same framework and are often combined in one document. The storage side covers where data lives and how it is protected, including approved systems, encryption and backups. The retention side covers how long each category is kept and how it is deleted or destroyed when its period expires.

How long can a business keep personal data under UK GDPR?

The UK GDPR sets no fixed periods. Article 5(1)(e) requires personal data to be kept no longer than necessary for the purposes it was collected for, so each business must set and justify its own retention periods. Statutory minimums apply to specific records, such as three years for PAYE payroll records, six years for VAT records and forty years for COSHH health records.

What does data storage protection mean?

Data storage protection is the set of safeguards applied to stored data: encryption at rest and in transit, access controls, physical security for servers and archives, encrypted backups and secure disposal of media. Article 5(1)(f) of the UK GDPR requires appropriate security for personal data, and Article 32 requires technical and organisational measures proportionate to the risk.

How long should a business keep employee records after someone leaves?

Different records carry different periods. PAYE payroll records must be kept for three years from the end of the tax year, minimum wage records for six years, and COSHH health records for forty years from the last entry. Many employers keep general personnel files for six years after employment ends to cover the limitation period for contractual claims, but that choice should be recorded and justified in the retention schedule.

Does the Data (Use and Access) Act 2025 change data retention rules?

It does not change retention periods, but it raises the cost of getting retention wrong. From 19 June 2026 every controller must operate a data protection complaints process, acknowledging complaints within 30 days, and retention disputes are a common complaint subject. The Act also confirms that subject access searches must be reasonable and proportionate, which is far easier to demonstrate when a retention schedule is in place.

Share:
Trustpilot Reviews - 5 Stars