Templates/Data Retention Policy
GDPR · Free template

Data Retention Policy template

A free, editable data retention policy with a sample retention schedule — how long to keep different types of personal data under UK GDPR, and how to justify each period.

This is a generic starting point, not legal advice. The retention periods below are indicative — your actual periods must reflect your own legal obligations, sector, and genuine business need, and you should be able to justify each one if challenged.

What a data retention policy needs to cover

The storage limitation principle doesn't give you a number to plug in — it requires you to reason about each category of data you hold and set a period you can defend. A usable policy documents that reasoning once, as a schedule, rather than making the decision fresh (or not at all) every time someone asks whether it's safe to delete something.

The template below includes a sample schedule covering the data categories most UK businesses hold — adjust every period against your own obligations before adopting it.

The template

Data Retention Policy — [Company Name]

1. Purpose

UK GDPR's storage limitation principle (Article 5(1)(e)) requires that personal data is kept "no longer than is necessary" for the purposes it was collected for. This policy sets out how [Company Name] decides retention periods, and the schedule we follow in practice.

Keeping data longer than necessary isn't just a compliance risk — every record retained is a record that can be lost in a breach. Minimising retention reduces both.

2. How we set a retention period

For each category of personal data we hold, we ask: is there a legal obligation to keep it for a set period (e.g. tax records)? Is there a realistic risk of a claim or dispute that requires it as evidence? Is it still needed for the purpose it was collected for?

Where no legal minimum applies, we set a period based on genuine business need and document our reasoning — "we might need it someday" is not an adequate justification on its own.

3. Retention schedule

The table below sets out our standard retention periods by data category. [This is a starting point — review and adjust every period against your own legal obligations and business context before adopting it.]

Data categoryRetention periodBasis
Customer contact & account records[6 years] after the relationship endsLimitation Act 1980 — contract claims window
Financial records & invoices6 yearsHMRC statutory requirement
Employee records (during employment)Duration of employment + [6 years]Employment tribunal claims window, tax records
Recruitment records (unsuccessful candidates)[6–12 months]Discrimination claims window (ACAS guidance)
CCTV footage[30 days]Proportionality — no longer than needed for security purpose
Marketing consent & preferencesUntil consent withdrawn, reviewed every [2 years]Consent must stay current and evidenced
Website analytics / cookies data[14–26 months]ICO guidance on analytics cookie lifespans
CV / job applicant data (successful hires)Transferred into employee recordNo longer "applicant" data once hired
Security & access logs[6–12 months]Incident investigation window, proportionate to risk
Complaints & incident records[6 years]Potential litigation, regulatory enquiry window

4. Deletion and disposal

When a retention period expires, data is [securely deleted / anonymised] according to our data disposal procedure. Physical records are shredded; digital records are deleted from live systems and backups within [90 days] of the retention period ending.

[Describe your specific deletion process — who is responsible, what tooling is used, and how deletion from backups is handled given backups are often retained on a rolling cycle independent of the live system.]

5. Legal holds

Where data is subject to an active legal claim, regulatory investigation, or litigation hold, normal retention periods are suspended for that data until the hold is lifted. [Name who has authority to place and release a legal hold.]

6. Review

This policy and its retention schedule are reviewed [annually] or when our data processing activities materially change. Last reviewed: [Date]. Next review due: [Date].

Common questions

Does UK GDPR set fixed retention periods?

No — the law deliberately doesn't specify exact periods for most data, because the right period depends on the purpose and context. Instead it requires you to justify whatever period you choose against the storage limitation principle, and be able to explain your reasoning if asked.

What happens if we keep data longer than we said we would in our privacy policy?

It's a compliance gap the ICO can act on, and in practice it's one of the most common findings in an audit — policies that state a period the organisation doesn't actually enforce. Your retention schedule and your actual deletion practice need to match what your privacy policy tells people.

Do backups need to follow the same retention periods as live systems?

In principle yes, but the ICO recognises that backups are often on a fixed rolling cycle (e.g. 30- or 90-day retention) for technical reasons. The common approach is to document that backups roll off automatically within a defined, proportionate window, and to exclude backup data from live search/use in the meantime.

How does this relate to our GDPR Privacy Policy?

Your Privacy Policy states, at a summary level, how long you keep people's data — this Data Retention Policy is the internal document with the actual detailed schedule and reasoning behind those statements. See our GDPR Privacy Policy template for a starting point on the customer-facing side.

Want a schedule built for your actual data?

Fortify's Policy Engine generates a Data Retention Policy tailored to your organisation and regulation scope, and keeps it current when guidance changes — so the schedule you publish is the one you actually follow.