SecurSentry
← All notes
UK GDPR

Data Retention for Small Businesses: How Long to Keep Personal Data

There is no magic number for how long you keep customer or staff data. Here is the rule that actually applies, what other laws force you to keep, and how to write a one-page policy that keeps it tidy.

The short version

If you have ever wondered how long you are actually allowed to keep a customer’s details, an old employee’s file, or that spreadsheet of leads from two years ago, you are not alone. It is one of the most common GDPR questions, and the honest answer surprises people: there is no single number. Writing a data retention policy is really just deciding, on purpose, how long each type of data earns its place, then clearing out the rest. This guide walks through the rule that applies, what other laws force you to keep, and how to write the policy in an afternoon.

The rule is a principle, not a number

UK GDPR does not tell you to keep data for three years, or seven, or any fixed period. It says you must not keep personal data for longer than you need it for the purpose you collected it.

This is the ‘storage limitation’ principle, set out in Article 5(1)(e) of the UK GDPR. Personal data must be kept “for no longer than is necessary for the purposes for which the personal data are processed”. That word necessary does the heavy lifting. Once data has done the job you collected it for, the clock is running on getting rid of it.

The ICO, the UK’s data protection regulator, is blunt on this point: UK GDPR does not dictate how long you should keep personal data. It is up to you to justify it, based on your purposes for processing. And it warns against the most common habit of all, which is keeping data indefinitely “just in case”, or where there is only a small possibility you will ever use it.

So the question is never “what’s the legal retention period?” It is “how long do I genuinely need this, and can I explain why?” Two businesses can hold the same kind of data for very different lengths of time, both correctly, because their purposes differ.

The default setting for data is delete, not keep. If you can’t say why you still hold something, that’s usually your answer.

Where the actual time periods come from

Some retention periods are effectively set for you by other laws, so the real skill is separating ‘must keep this long’ from ‘keep only while it’s useful’.

Although GDPR sets no numbers, plenty of other rules do. These are the firm anchors in your retention schedule, the rows where the period isn’t a judgement call.

The clearest example is tax. HMRC requires businesses to keep tax and accounting records for a set time. If you are self-employed, you must keep your records for at least five years after the 31 January submission deadline of the relevant tax year. If you run a limited company, you must keep accounting records for six years from the end of the company financial year they relate to. (Source: GOV.UK, HMRC record-keeping guidance.) Those records often contain personal data, such as names, addresses and payment details, so they sit at the overlap of “tax law says keep it” and “GDPR says don’t keep more than you need”.

Other examples follow the same logic. Employment and payroll records have their own minimums; some health and safety records must be kept for years after an incident. The pattern is always the same: a specific law sets a floor, and you keep the data at least that long.

Everything else is a judgement you make, anchored to purpose. How long after a customer goes quiet do you keep their account? How long do you hang on to an unsuccessful job applicant’s CV? There is no statute for those, so you decide a reasonable period, write down why, and stick to it.

KEEPING IT FOR TAX IS NOT THE SAME AS KEEPING IT FOR MARKETING

A record you must hold for HMRC doesn't entitle you to keep using that person's email for marketing. Once the original purpose ends, lock the data down to the narrow reason you're still allowed to keep it, and don't quietly repurpose it. This is one of the more common over-retention traps.

What a data retention policy actually is

A data retention policy is a simple table that says, for each type of data you hold: what it is, how long you keep it, why, and what happens at the end.

People imagine a long legal document. It isn’t. The useful version is a one-page schedule with four columns:

Here is the shape of a few rows, to make it concrete:

Data typeHow longWhyAt the end
Accounting and tax records6 years (Ltd) / 5+ years (self-employed)HMRC requirementSecure deletion
Customer account data2 years after last purchaseRepeat-business windowDelete or anonymise
Unsuccessful job applicants6 months after the decisionHandle queries or complaintsSecure deletion
Marketing email listUntil they unsubscribe, reviewed yearlyConsent-based, ongoingRemove on opt-out

That’s a working retention policy. You can build it in a spreadsheet. The point isn’t elegance. It’s that you’ve made a deliberate decision for each kind of data, instead of letting everything pile up by default.

Building this is far easier if you’ve already mapped what data you hold and why. That groundwork is exactly what a record of processing activities gives you, and a retention schedule is its natural next column.

Make it living, not a one-off

A retention policy only works if you actually act on it, so the real win is turning it into a recurring habit rather than a document you wrote once.

The most common failure isn’t a bad policy. It’s a good policy that nobody follows. Data quietly accumulates, the schedule says “delete after two years”, and three years later it’s all still there.

Two habits fix this. First, name someone responsible, usually you or your office manager in a small business, and put a recurring review in the diary. Once or twice a year is plenty for most. Second, when the review comes round, actually do the disposal: delete the records that have aged out, anonymise where it’s smarter to keep aggregate data without the personal bits, and note what you did. A short log of “reviewed July 2026, cleared X” is your evidence that the policy is real.

Disposal needs to be genuine. Dragging files to the recycle bin isn’t secure deletion, and an exported backup that still holds the data hasn’t been cleared. Think about every place a record lives, including your main system, email, accounting tool, shared drive and backups, and make sure “delete” means deleted everywhere it reasonably matters.

THE REVIEW IS A FREE TIDY-UP

Each retention review is also a chance to spot data you forgot you had and purposes you no longer pursue. It quietly strengthens your wider GDPR position while keeping your systems lighter and faster.

The honest pay-off: holding less is just safer

Every record you keep beyond its usefulness is risk you carry for no benefit, which is why over-retention is one of the most common and avoidable GDPR weak spots.

There’s a real, selfish upside to good retention, and it has nothing to do with ticking a compliance box.

If you suffer a data breach, the damage is set by what you were holding. A business that deletes old customer data on schedule simply has less to lose when something goes wrong. The breach is smaller, the people affected are fewer, and the conversation with the ICO is shorter. You can’t lose what you no longer hold.

The same logic applies to a subject access request. When someone asks for everything you hold about them, you have to find it, review it, and send it within a month. A business that keeps five clean years of relevant records handles that calmly. A business with a decade of unsorted email, duplicate spreadsheets, and forgotten exports faces a far bigger job. Holding less doesn’t just reduce risk. It reduces work.

Over-retention is so common precisely because doing nothing feels safe. Keeping everything feels cautious. In data protection terms it’s the opposite: it grows your exposure, your obligations, and your workload, all at once. A short, followed retention policy is one of the highest-value, lowest-effort things a small business can do.

SecurSentry is launching soon to help UK SMEs set sensible retention periods, document them, and build the review habit that keeps personal data tidy and defensible. Join the waitlist to be first to know when we open.


This article is general information, not legal or compliance advice. Retention periods set by other laws change over time and vary by sector, so for your specific obligations seek qualified guidance from a data protection professional or solicitor.

Frequently asked questions

How long can a small business keep personal data under GDPR?

There is no fixed period. UK GDPR's storage limitation principle says you can keep personal data only for as long as you genuinely need it for the purpose you collected it, then you must delete or anonymise it. You set your own retention periods and must be able to justify them. Some records, such as tax and accounting documents, have minimum periods set by other laws like HMRC's rules.

Does GDPR set a maximum retention period?

No. The ICO, the UK's data protection regulator, is clear that UK GDPR does not dictate specific retention periods. It is up to you to justify how long you keep each type of data, based on your purposes. You should not keep data indefinitely 'just in case' or where there is only a small chance you will use it.

How long does HMRC require me to keep records?

If you are self-employed, HMRC requires you to keep your records for at least five years after the 31 January submission deadline of the relevant tax year. Limited companies must keep accounting records for six years from the end of the company financial year they relate to. These are HMRC requirements that sit alongside, not instead of, your GDPR duties.

What should a data retention policy include?

A practical retention policy is a table listing each type of personal data you hold, how long you keep it, why (the purpose or the law that sets the period), and what happens at the end: secure deletion or anonymisation. It should also name who is responsible for reviewing it and how often, so it stays current rather than gathering dust.

Written by The SecurSentry Team

We write plain-English notes on security and compliance for small businesses — the things we wish someone had explained to us. Read more notes →

More from the blog

UK GDPR

Does a Small Business Need a Data Protection Officer (DPO)?

29 Jul 2026 · 9 min
UK GDPR

The Six Lawful Bases for Processing Personal Data, in Plain English

22 Jul 2026 · 9 min
UK GDPR

What a Record of Processing Activities (ROPA) Is, and How to Build One

19 Jul 2026 · 7 min

Be first to know when we launch.

Leave your email and we'll let you know the moment SecurSentry is ready. One email — no newsletters, no spam.

Just one email, at launch. We never share your data. Privacy policy.

You're on the list — we'll be in touch at launch.