HR data retention schedule template
Very few HR retention periods are actually fixed in law. This separates the ones that are - with sources - from the many you have to set yourself, and shows how to justify those defensibly.
Most "standard HR retention periods" circulating online are conventions, not law. The storage limitation principle requires that personal data is kept "no longer than is necessary for the purposes for which it is processed" (Art 5(1)(e) UK GDPR) - and Art 5(2) makes you responsible for demonstrating that. So the schedule below marks which periods are genuinely fixed and which are your decision, because a schedule that cannot distinguish them cannot be defended.
Download the schedule PDF · 3 pages · edit the [bracketed] parts
Periods that are actually fixed
| Record | Keep for | Source |
|---|---|---|
| Right to work check evidence | Duration of employment + 2 years, with the check date recorded | gov.uk |
| PAYE and payroll records | 3 years from the end of the tax year they relate to | gov.uk - HMRC may estimate liability and charge a penalty of up to £3,000 if records are not kept |
| Auto-enrolment: names, addresses, ages, earnings, contribution dates, scheme reference | 6 years | gov.uk |
| Auto-enrolment: requests to leave the scheme | 4 years | gov.uk (note the different period) |
| Working time opt-out agreements | An up-to-date record of who has opted out | reg 4 WTR 1998 - "up to date" rather than a fixed period |
Periods you have to set yourself
For everything below there is no single statutory period. Set one, write down the reason, and apply it. The reason is the part that matters - it is what Art 5(2) accountability actually looks like.
| Record | A common period | The justification to write down |
|---|---|---|
| Unsuccessful applicants: CVs, scorecards, notes | [6-12] months | Covers the window for a discrimination claim and any question about the decision |
| Personnel file after leaving | [6] years | Aligns with the limitation period for a contract claim |
| Disciplinary and grievance records | [6] years from conclusion, or shorter for expired warnings | Contract-claim period; expired warnings should be removed from active use on their stated expiry |
| Sickness absence records | [3-6] years | Occupational health and disability-adjustment history may be needed for later decisions |
| Occupational health reports | [As advised by the OH provider] | Special category data - keep the minimum that supports the adjustment decision |
| Training and certification records | Employment + [2] years, or the certificate's validity | Evidence of competence and of the reasonable steps duty |
| Policy acknowledgements | [6] years | Evidence that a policy was issued and read - directly relevant to the harassment preventative duty |
| References given and received | [1-6] years | Shorter for references you gave; longer where they informed a hiring decision |
| CCTV and access logs | [30] days | Rarely needed beyond an immediate incident |
| Exit interviews | [2] years | Useful in aggregate; the individual record ages quickly |
The policy wrapper
This schedule sets out how long [Company name] keeps personal data about workers, applicants and former workers, and why. It gives effect to the storage limitation principle in Article 5(1)(e) of the UK GDPR. [Role] owns it and reviews it every [12] months.
Retention periods run from the trigger stated for each record - normally the end of employment, the end of a tax year, or the conclusion of a case. Where a record has more than one trigger, the later applies. Where litigation is anticipated or under way, deletion of relevant records is suspended until the matter concludes.
Records are securely deleted or destroyed at the end of the period. [Where we retain anonymised or aggregate information for reporting, it contains nothing that identifies an individual and falls outside this schedule.] Deletion runs [quarterly] and is recorded, because an undocumented deletion is indistinguishable from never having looked.
Health information, and data revealing racial or ethnic origin, religious belief, trade union membership or sexual orientation, is kept only as long as the specific purpose requires and is held with access restricted to [roles]. Where a shorter period is workable for this data than for the rest of the file, we apply the shorter one.
The periods in this schedule, or the criteria used to set them, are published in our worker privacy notice and are what we give in response to a subject access request. If a period changes, the notice changes with it.
Using it
- Do not copy the second table without changing the brackets. Those are common periods, not correct ones - the number is only defensible once you have written why it fits what you do.
- Actually run the deletion. A schedule that is never executed is worse than none: it documents precisely how long you said you would keep things, next to data you still hold.
- Watch the two auto-enrolment rows. Six years for most records but four for requests to leave the scheme is an easy detail to flatten into a single number, and it is wrong in one direction or the other.
- Publish the criteria. A subject access request requires you to state the storage period or the criteria for determining it - see the DSAR guide. This schedule is the answer to that question.
This is a starting point for a general UK employer and is not legal advice. Regulated sectors, pension scheme trustees and anyone holding data for safeguarding purposes have their own requirements that sit on top of this.
More to download: All 30 templates · 66 guides explaining the rules · 24 calculators
Privacy built in, not bolted on
CoDash stores anonymous feedback with no author column at all, keeps individual moods away from managers by design, and enforces k-anonymity in code - so the things that should never be retrievable never were.