4.8Top Rated Service 2026verified by TrustindexTrustindex verifies that the company has a review score above 4.5, based on reviews collected on Google over the past 12 months, qualifying it to receive the Top Rated Certificate.
Under the UK GDPR, organisations should not keep personal data for longer than necessary. Retention periods should be based on the purpose of the processing, legal requirements, business need, and the accountability principle.
Under the UK GDPR, organisations should only keep personal data for as long as they need it for a clear purpose. There is no single retention period that applies to every organisation or every record. The right period depends on why the data is held, legal or regulatory requirements, operational need, and whether keeping it can still be justified under the accountability principle.
Should be
Limited to what is necessary for a clear purpose
Should involve
Documented retention periods and review points
Should allow
Secure deletion, anonymisation, or archive decisions
The UK GDPR does not usually tell organisations exactly how many months or years to keep each type of record. Instead, organisations need to decide and document retention periods that are reasonable for the purpose. Keeping data indefinitely because it might be useful one day is unlikely to be enough.
A retention period should connect back to the reason the data was collected or used. Customer records, staff records, marketing lists, and complaint files may all need different periods.
A retention schedule helps show that the organisation has thought about necessity, legal duties, limitation periods, operational need, and privacy risk.
Retention periods should be reviewed when systems, services, laws, or business processes change, especially where large volumes of personal data are involved.
Retention decisions also connect to transparency, because people should usually be told how long their data will be kept or how that period will be decided.
A sensible retention period is usually based on a mixture of legal requirements, business need, limitation periods, sector expectations, and the risk to individuals. The key is to make a reasoned decision rather than keeping everything by default.
Some records need to be kept for a minimum period because of tax, employment, financial, contractual, or regulatory requirements. Those duties should be identified before data is deleted.
Organisations may need data to deliver services, manage accounts, handle disputes, evidence decisions, support audits, or maintain operational records.
If data may be needed to bring or defend a legal claim, the relevant limitation period can influence how long certain records are retained.
The more sensitive, detailed, or high-risk the data is, the stronger the reason should be for keeping it and the more carefully access should be controlled.
A retention period is only useful if people inside the organisation can actually follow it. That usually means having a retention schedule, clear ownership, review dates, and a process for secure deletion or anonymisation.
Retention schedule may be appropriate where people can genuinely choose whether the processing happens, understand the choice clearly, and withdraw later without unfair consequences.
At the end of a retention period, data should usually be deleted, anonymised, or moved into a restricted archive if there is a clear reason to preserve it.
For marketing, organisations often need to consider both UK GDPR and PECR. Retention schedule may be required for some electronic marketing, cookies, or similar technologies even where a different lawful basis is used for related processing. See Direct Marketing and GDPR for the wider overlap.
Retention schedule mistakes usually happen when organisations treat consent as a formality rather than a meaningful choice. The most common problems are weak wording, bundled requests, poor records, and difficult withdrawal processes.
Retention schedule should not be hidden inside general terms, privacy wording, or a long form where the individual cannot make a clear separate choice.
Data is often copied into spreadsheets, inboxes, downloads, shared folders, and old systems. Those copies still count and should be covered by retention controls.
Retention schedule should be designed as an ongoing control mechanism, not a one-time legal shield. Organisations need clear wording, separate choices, reliable records, and simple withdrawal routes.
Retention schedule is context-specific. The same design may be acceptable in one setting and unsuitable in another, depending on the level of choice, the clarity of the request, and the impact on the person.
Retention schedule may be needed for certain email, SMS, or electronic marketing activity, particularly where PECR requires it.
Recruitment data should not normally be kept indefinitely. Organisations should decide how long to keep unsuccessful applicant data and explain this clearly.
Marketing contact records should be reviewed regularly, especially where people unsubscribe, stop engaging, or where consent or preference records become outdated.
Retention schedule may be suitable where people choose whether to receive optional updates, newsletters, event invitations, or promotional communications.
If personal data is kept too long, the organisation increases storage, security, access, breach, and subject access risk. Good retention reduces clutter and supports stronger governance.
This article is based on ICO guidance on storage limitation, retention, deletion, and accountability under the UK GDPR, together with the UK GDPR provisions that require organisations to keep personal data only for as long as necessary. It also connects to wider duties around accountability, privacy notices, lawful basis, and individual rights such as subject access requests.
Use the glossary for key terms, or download the checklist if you want a practical starting point for reviewing retention periods, deletion routines, privacy notice wording, old records, supplier files, marketing data, and internal retention schedules.
We use cookies and similar technologies to make our website work and to provide optional features such as live chat.
Some cookies are strictly necessary for the website to function. Optional cookies support tools such as live chat and will only be used if you choose to allow them.
We also use privacy-friendly, cookieless website analytics to understand aggregated website usage. This does not use cookies or track you across websites.
You can choose to accept all cookies, reject non-essential cookies, or manage your preferences.