HR data retention schedule template

Very few HR retention periods are actually fixed in law. This separates the ones that are - with sources - from the many you have to set yourself, and shows how to justify those defensibly.

By · Template · Compliance · Checked 15 August 2026 · 7 min read

In short

Most "standard HR retention periods" circulating online are conventions, not law. The storage limitation principle requires that personal data is kept "no longer than is necessary for the purposes for which it is processed" (Art 5(1)(e) UK GDPR) - and Art 5(2) makes you responsible for demonstrating that. So the schedule below marks which periods are genuinely fixed and which are your decision, because a schedule that cannot distinguish them cannot be defended.

Download the schedule PDF · 3 pages · edit the [bracketed] parts

Periods that are actually fixed

RecordKeep forSource
Right to work check evidenceDuration of employment + 2 years, with the check date recordedgov.uk
PAYE and payroll records3 years from the end of the tax year they relate togov.uk - HMRC may estimate liability and charge a penalty of up to £3,000 if records are not kept
Auto-enrolment: names, addresses, ages, earnings, contribution dates, scheme reference6 yearsgov.uk
Auto-enrolment: requests to leave the scheme4 yearsgov.uk (note the different period)
Working time opt-out agreementsAn up-to-date record of who has opted outreg 4 WTR 1998 - "up to date" rather than a fixed period

Periods you have to set yourself

For everything below there is no single statutory period. Set one, write down the reason, and apply it. The reason is the part that matters - it is what Art 5(2) accountability actually looks like.

RecordA common periodThe justification to write down
Unsuccessful applicants: CVs, scorecards, notes[6-12] monthsCovers the window for a discrimination claim and any question about the decision
Personnel file after leaving[6] yearsAligns with the limitation period for a contract claim
Disciplinary and grievance records[6] years from conclusion, or shorter for expired warningsContract-claim period; expired warnings should be removed from active use on their stated expiry
Sickness absence records[3-6] yearsOccupational health and disability-adjustment history may be needed for later decisions
Occupational health reports[As advised by the OH provider]Special category data - keep the minimum that supports the adjustment decision
Training and certification recordsEmployment + [2] years, or the certificate's validityEvidence of competence and of the reasonable steps duty
Policy acknowledgements[6] yearsEvidence that a policy was issued and read - directly relevant to the harassment preventative duty
References given and received[1-6] yearsShorter for references you gave; longer where they informed a hiring decision
CCTV and access logs[30] daysRarely needed beyond an immediate incident
Exit interviews[2] yearsUseful in aggregate; the individual record ages quickly

The policy wrapper

1. Purpose

This schedule sets out how long [Company name] keeps personal data about workers, applicants and former workers, and why. It gives effect to the storage limitation principle in Article 5(1)(e) of the UK GDPR. [Role] owns it and reviews it every [12] months.

2. Trigger points

Retention periods run from the trigger stated for each record - normally the end of employment, the end of a tax year, or the conclusion of a case. Where a record has more than one trigger, the later applies. Where litigation is anticipated or under way, deletion of relevant records is suspended until the matter concludes.

3. What happens at the end

Records are securely deleted or destroyed at the end of the period. [Where we retain anonymised or aggregate information for reporting, it contains nothing that identifies an individual and falls outside this schedule.] Deletion runs [quarterly] and is recorded, because an undocumented deletion is indistinguishable from never having looked.

4. Special category data

Health information, and data revealing racial or ethnic origin, religious belief, trade union membership or sexual orientation, is kept only as long as the specific purpose requires and is held with access restricted to [roles]. Where a shorter period is workable for this data than for the rest of the file, we apply the shorter one.

5. Telling people

The periods in this schedule, or the criteria used to set them, are published in our worker privacy notice and are what we give in response to a subject access request. If a period changes, the notice changes with it.

Using it

  • Do not copy the second table without changing the brackets. Those are common periods, not correct ones - the number is only defensible once you have written why it fits what you do.
  • Actually run the deletion. A schedule that is never executed is worse than none: it documents precisely how long you said you would keep things, next to data you still hold.
  • Watch the two auto-enrolment rows. Six years for most records but four for requests to leave the scheme is an easy detail to flatten into a single number, and it is wrong in one direction or the other.
  • Publish the criteria. A subject access request requires you to state the storage period or the criteria for determining it - see the DSAR guide. This schedule is the answer to that question.

This is a starting point for a general UK employer and is not legal advice. Regulated sectors, pension scheme trustees and anyone holding data for safeguarding purposes have their own requirements that sit on top of this.

More to download: All 30 templates · 66 guides explaining the rules · 24 calculators

Privacy built in, not bolted on

CoDash stores anonymous feedback with no author column at all, keeps individual moods away from managers by design, and enforces k-anonymity in code - so the things that should never be retrievable never were.