Blog

Data Retention Under UK GDPR: How Long Can Organisations Keep Personal Data?

Under the UK GDPR, organisations should not keep personal data for longer than necessary. Retention periods should be based on the purpose of the processing, legal requirements, business need, and the accountability principle.

Estimated reading time: 6 minutesTopic: GovernanceRelated terms: Personal data and UK GDPR
Quick answer

What data retention means in practice

Under the UK GDPR, organisations should only keep personal data for as long as they need it for a clear purpose. There is no single retention period that applies to every organisation or every record. The right period depends on why the data is held, legal or regulatory requirements, operational need, and whether keeping it can still be justified under the accountability principle.

Should be

Limited to what is necessary for a clear purpose

Should involve

Documented retention periods and review points

Should allow

Secure deletion, anonymisation, or archive decisions

Section one

Why data retention matters under UK GDPR

The UK GDPR does not usually tell organisations exactly how many months or years to keep each type of record. Instead, organisations need to decide and document retention periods that are reasonable for the purpose. Keeping data indefinitely because it might be useful one day is unlikely to be enough.

Purpose

Retention starts with why the data is held

A retention period should connect back to the reason the data was collected or used. Customer records, staff records, marketing lists, and complaint files may all need different periods.

Evidence

Businesses need to justify the period

A retention schedule helps show that the organisation has thought about necessity, legal duties, limitation periods, operational need, and privacy risk.

Review

Retention should not be set and forgotten

Retention periods should be reviewed when systems, services, laws, or business processes change, especially where large volumes of personal data are involved.

Retention decisions also connect to transparency, because people should usually be told how long their data will be kept or how that period will be decided.

Section two

How to decide how long to keep personal data

A sensible retention period is usually based on a mixture of legal requirements, business need, limitation periods, sector expectations, and the risk to individuals. The key is to make a reasoned decision rather than keeping everything by default.

Business need

Organisations may need data to deliver services, manage accounts, handle disputes, evidence decisions, support audits, or maintain operational records.

Limitation periods

If data may be needed to bring or defend a legal claim, the relevant limitation period can influence how long certain records are retained.

Privacy risk

The more sensitive, detailed, or high-risk the data is, the stronger the reason should be for keeping it and the more carefully access should be controlled.

Section three

Retention periods should be practical and documented

A retention period is only useful if people inside the organisation can actually follow it. That usually means having a retention schedule, clear ownership, review dates, and a process for secure deletion or anonymisation.

Retention schedule

Sets out what is kept and for how long

Retention schedule may be appropriate where people can genuinely choose whether the processing happens, understand the choice clearly, and withdraw later without unfair consequences.

Deletion or anonymisation

Shows what happens when the period ends

At the end of a retention period, data should usually be deleted, anonymised, or moved into a restricted archive if there is a clear reason to preserve it.

Systems need extra care

For marketing, organisations often need to consider both UK GDPR and PECR. Retention schedule may be required for some electronic marketing, cookies, or similar technologies even where a different lawful basis is used for related processing. See Direct Marketing and GDPR for the wider overlap.

Section five

Examples of data retention in practice

Retention schedule is context-specific. The same design may be acceptable in one setting and unsuitable in another, depending on the level of choice, the clarity of the request, and the impact on the person.

Customer records

Retention schedule may be needed for certain email, SMS, or electronic marketing activity, particularly where PECR requires it.

Job applicant data

Recruitment data should not normally be kept indefinitely. Organisations should decide how long to keep unsuccessful applicant data and explain this clearly.

Marketing lists

Marketing contact records should be reviewed regularly, especially where people unsubscribe, stop engaging, or where consent or preference records become outdated.

Complaint and dispute files

Retention schedule may be suitable where people choose whether to receive optional updates, newsletters, event invitations, or promotional communications.

Why this distinction matters

If personal data is kept too long, the organisation increases storage, security, access, breach, and subject access risk. Good retention reduces clutter and supports stronger governance.

```html
Grounded in

What this article is grounded in

This article is based on ICO guidance on storage limitation, retention, deletion, and accountability under the UK GDPR, together with the UK GDPR provisions that require organisations to keep personal data only for as long as necessary. It also connects to wider duties around accountability, privacy notices, lawful basis, and individual rights such as subject access requests.

Related concepts

Explore connected topics

Next step

Keep building your understanding

Use the glossary for key terms, or download the checklist if you want a practical starting point for reviewing retention periods, deletion routines, privacy notice wording, old records, supplier files, marketing data, and internal retention schedules.

```
Future Implementation Support Waitlist